Skip to main content
Back to overview
Medium

Dutch civil servants from Authority for Consumers and Markets (ACM) affected by Microsoft data leak

Microsoft accused of leaking Dutch civil servants' names to U.S.

Key points

  • Names of Dutch civil servants from ACM leaked.
  • Involved in Digital Services Act (DSA) implementation.
  • Data shared by Microsoft with U.S. House of Representatives.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Error

Threat source not confirmed

03

Potential impact

Data Exposure

Impact remains under assessment

Published
May 22, 2026
Updated
Jul 22, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch process controls, misconfiguration and accidental disclosure paths.

Business impact

Potential business exposure
Impact area
Unknown
Likely asset
Server or cloud data store

Mentioned entities

AcmDutchAuthority for Consumers and MarketsACMMicrosoftU.SU.S. House of Representatives. TheFridayVrij Nederland. TheDigital Services Act

Quick context

Questions about this signal

What happened in this signal?

Microsoft accused of leaking Dutch civil servants' names to U.S. government Microsoft has reportedly shared the names of Dutch civil servants working for two regulatory agencies with the U.S. House of Representatives. The agencies involved include the Authority for Consumers and Markets (ACM) and the Dutch Data Protection Authority (AP), according to an article published on Friday by Vrij Nederland. The civil servants involved are working on implementing the Digital Services Act (DSA), the European law that forces online platforms to take stricter action against illegal content, online child sex abuse, and disinformation. The American government considers this law a form of censorship. Microsoft shared emails, minutes, and invitations sent by these civil servants without redacting their names in the documents. American tech companies are required to share data with the U.S. government due to the Cloud Act in force in that country. State Secretary Eric van der Burg of Interior is concerned that Microsoft simply shared civil servants’ names with the U.S. government. But he first wants to investigate how the names were shared and in what documents before drawing conclusions. State Secretary Willemijn Aerdts for Digital Economy and Sovereignty has spoken with the U.S. Ambassador Joe Popolo about the allegations. The D66 politician said this happened some time ago, and she raised the issue with Popolo during her introductory meeting with the ambassador. “I said how undesirable this is. If you have a problem, you fight it out with us or, if necessary, in Europe, but not against the backs of civil servants,” Aerdts told ANP before heading into the Council of Ministers meeting on Friday. There is a broad desire within the Netherlands to become less dependent on major American tech companies , specifically because of the Cloud Act. Both Aerdts and Van der Burg stressed that it will take time for the Netherlands to become digitally sovereign.

When was this signal reported?

Shadow Tier lists May 22, 2026 as the signal date.

Which organization is connected to this signal?

Acm is the organization connected to this public signal.

Explore Acm
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence