Skip to main content
Back to overview
Medium

Microsoft Accused of Leaking Dutch Civil Servants' Data to US Government

Microsoft has been accused of leaking data belonging to Dutch civil servants, specifically those working for the Authority for Consumers and Markets (ACM) and the Dutch Data Protection Authority (AP), to the US House of…

Key points

  • The affected civil servants work for Dutch regulatory agencies involved in implementing EU digital regulations, such as the Digital Services Act (DSA).
  • Emails, minutes, and invitations were shared without redacting the names of the civil servants.
  • The incident raises concerns about data privacy and Europe's reliance on American technologies.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Explore attack patterns

Threat source not confirmed

03

Potential impact

Data Exposure

Impact remains under assessment

Published
May 28, 2026
Updated
Jun 30, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential business exposure
Impact area
Unknown

Mentioned entities

MicrosoftMicrosoft Accused of Leaking DutchCivil ServantsUS Government MicrosoftDutchAuthority for Consumers and MarketsACMUS House of Representatives. TheDigital Services ActDSA

Quick context

Questions about this signal

What happened in this signal?

Microsoft has been accused of leaking data belonging to Dutch civil servants, specifically those working for the Authority for Consumers and Markets (ACM) and the Dutch Data Protection Authority (AP), to the US House of Representatives. The leaked data includes emails, minutes, and invitations with unredacted names.

When was this signal reported?

Shadow Tier lists May 28, 2026 as the signal date.

Which organization is connected to this signal?

Microsoft is the organization connected to this public signal.

Explore Microsoft
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence