What's Inside the "European Commission" Ransomware Leak Claimed by ShinyHunters?
What the indexed data of the "European Commission" ransomware leak claimed by ShinyHunters contains: 14% of records hold an email, and 86% carry names and other PII.
Category: breach reports · Source: HIBR GET /api/fullmetadata/27648 plus 1,000-record samples per domain via /api/fullransom.
In March 2026 the ransomware group ShinyHunters listed a victim called "European Commission (*.europa.eu)" and advertised "350 GB+" of mail-server dumps, databases and contracts. That is the group's claim; we have no independent confirmation of it. What we can do is open the indexed data and see what is actually in it. The most-repeated email domain is not europa.eu. It is bytedance.com.
The short answer
- Of the indexed records, 14.0% contain an email address. The other 86.0% are not "empty": they carry other forms of personal data, such as names and further identifiers, rather than emails.
- Among those addresses, 70% carry the domain bytedance.com, while at least 5% belong to europa.eu subdomains.
- In a 1,000-record sample of the bytedance.com records, only 2 distinct addresses appear. The pattern looks like web-crawler traces in server logs, not millions of people.
- Our heuristic attribution score is 50/100 (medium): the content moderately supports the Commission link. It is not verification.
What we found inside the leak
Percentages below are always stated against the base named next to them. Sample results describe only that sample and are not extrapolated to the whole leak.
By file type (share of indexed records). 99.65% of records come from CSV files, 0.34% from JSON, 0.016% from legacy .doc files, and under 0.01% combined from PDF, XLS/XLSX, XML, database files and text. No .eml or .mbox mail archives are indexed. This matters: despite the "mail-server dumps" wording in the group's note, the content is overwhelmingly flattened tabular data, not mailboxes. The API counts records per type, not files.
By content (share of records). 14.0% of all records contain an email address. The remaining 86.0% contain no email, but that does not make them harmless: they hold other personal data, mainly names and other identifying details. Email is only the easiest PII to count, so 14.0% understates how much personal information the leak holds. We have not quantified each non-email PII type, so we give no percentages for them.
Inside the bytedance.com records (sample of 1,000 records spread across the leak). - 0.2% distinct addresses per record: just 2 distinct addresses across the whole sample. - 55.1% of records are web-access log lines (CloudFront-style fields: URI, status, referrer, host). - 6.1% are web-application-firewall (WAF) log entries, and 6.0% contain the string "Bytespider", the name of ByteDance's crawler. - The remaining records were not classified.
Inside the europa.eu records (sample of 1,000 records matched on europa.eu). - 31.7% distinct addresses per record, so far more varied than the bytedance.com sample. - 35.7% mention WAF logs, 8.5% mail-delivery (SMTP) metadata, 19.0% CloudFront-style access logs. - Within this sample, the subdomains most present are ec.europa.eu (27.2% of sample records), eppo.europa.eu (21.6%), srb.europa.eu (18.0%) and ema.europa.eu (18.0%). Because the sample was selected by domain, this is a mix of institutions in the sample, not a ranking of the leak.
Corporate vs. Personal email
HIBR splits addresses into two classes:
- Corporate: 87.6% of 46,594,408 addresses.
- Personal: 12.4% of the same base.
What each means. Personal = the address uses a known free-webmail provider from a fixed list (49 exact domains plus 9 wildcards, case-sensitive). Corporate = everything else. So "corporate" does not mean "belongs to the Commission": it means "not on the webmail list". Third-party companies, test domains and unlisted webmail all land here. We read this in the deployed code.
Top 5 Corporate domains (% within Corporate):
| Domain | % of Corporate |
|---|---|
| bytedance.com | 79.96% |
| ec.europa.eu | 4.61% |
| search.yandex.ru | 0.67% |
| srb.europa.eu | 0.40% |
| eeas.europa.eu | 0.39% |
Top 5 Personal domains (% within Personal):
| Domain | % of Personal |
|---|---|
| gmail.com | 51.62% |
| hotmail.com | 15.67% |
| yahoo.com | 11.16% |
| yahoo.fr | 2.70% |
| outlook.com | 2.00% |
The Corporate figure is therefore heavily inflated. Reclassifying the top-10 domains ourselves (victim domain, third party, webmail) against all addresses gives: bytedance.com 70.05%, webmail 12.4%, europa.eu subdomains at least 5.14% (a floor, because only the top 10 domains are published). The 5.14% is counted over email occurrences, not distinct people.
Countries · identity documents
Only 96 records are identity documents, a tiny part of the leak, so the percentages below rest on a small base. The API associates each document with a country through the country field attached to the identity-document record (we could not read the extraction logic itself).
| Country | % of identity documents |
|---|---|
| US | 64.58% |
| DE | 10.42% |
| FR | 6.25% |
| CA | 3.12% |
| ES, EU, FI, SE (tied) | 2.08% each |
That the United States leads in a leak about a European institution is curious, but with 96 documents we do not draw conclusions from it.
Why the bytedance.com concentration is interesting
Fact: bytedance.com is the most frequent domain; our samples show very few distinct addresses and many log-style records. Hypothesis: the Bytespider crawler includes a contact address in its User-Agent, so every crawled request logged by the Commission's web infrastructure repeats the same address. A handful of addresses repeated millions of times would explain the 70%. We confirmed this pattern only for the share of the sample that carried the Bytespider string (6.0%); for the rest of the bytedance.com records we have not established the cause. What it does not show: that ByteDance was involved in, or the entry point of, the intrusion. A domain appearing in data tells you nothing about how the attacker got in.
Personal addresses tell a different story. In a 1,000-record gmail.com sample, 61.0% of addresses are distinct and 68.7% of records carry SMTP delivery metadata. That is consistent with outbound transactional email logs listing recipients, rather than people's mailboxes. Again a hypothesis, drawn from a sample.
Does the content match the victim?
HIBR's attribution indicator scores 50/100 (medium). It is a heuristic estimate with published factors, not a calibrated probability or formal attribution. The main driver is that distinct europa.eu addresses make up 34.5% of distinct corporate addresses we could evaluate, and europa.eu is the most frequent distinct corporate domain. The largest third party (skole.hr) accounts for only 4.1% of distinct addresses once repetitive crawler-like artifacts are discounted. Indicators like AWS WAF rule names tagged "EC-GENERAL" are consistent with the Commission but are not part of the score. Read it as: the content points toward the Commission, and the group's label is plausible, not proven.
Why it matters
Email counts are only the visible part of the PII: most records hold names and other identifiers instead. Headline counts such as "46.6 million emails" invite alarm, but the composition changes the story: the data looks like infrastructure telemetry and transactional-mail metadata at least as much as personal correspondence. For anyone assessing exposure, the question is not "how many emails" but "how many distinct people, in what context".
You can check whether a domain of yours appears in indexed ransomware leaks at HaveIBeenRansom.
Darkeye Research Team
JuanmaTracking ransomware crews, breach disclosures and the tooling that matters — field notes from the Darkeye desk.
Intel briefing
Get breach reports before they trend
Ransomware intel and breach disclosures in your inbox. Signal only, no noise.
Read next //
What's Inside the "European Commission" Ransomware Leak Claimed by ShinyHunters?
What the indexed data of the "European Commission" ransomware leak claimed by ShinyHunters contains: 14% of records hold an email, and 70% of those carry bytedance.com.
Keep investigating //
Discussion (0)
Sign in to join the discussion
Share your take with the Darkeye community.
No comments yet. Be the first to weigh in.