The "Shadow IT" Scandal at Europol: 2 Petabytes of Unregulated Data

A massive joint investigation by CORRECTIV, Computer Weekly, and Solomon has just pulled back the curtain on a secret, parallel IT infrastructure operating within Europol. What was intended as a forensic tool has evolved into a "shadow database" that bypassed standard EU data protection safeguards for years.

The "Shadow IT" Scandal at Europol: 2 Petabytes of Unregulated Data

A massive joint investigation by CORRECTIV, Computer Weekly, and Solomon has just pulled back the curtain on a secret, parallel IT infrastructure operating within Europol.

What was intended as a forensic tool has evolved into a "shadow database" that bypassed standard EU data protection safeguards for years.

The Scale of the Breach
The investigation focuses on the Computer Forensic Network (CFN) and a tool internally dubbed "Pressure Cooker." The numbers are staggering:
1- Massive Volume: By 2019, the CFN held 2,000 terabytes (2 PB) of data.
2- The Disparity: This is 420 times larger than Europol’s official criminal database.
3- Operational Monopoly: Analysts estimate that 99% of Europol’s operational data was stored in this unofficial system.

Why This Matters for Privacy & Security
This isn't just about technical bureaucracy; it’s about the fundamental rights of citizens and the integrity of law enforcement:
1- Targeting the Innocent: Because data wasn't categorized, the system held sensitive info on millions of people with no link to criminal activity.
2- Security Failures: Internal assessments revealed "baseline" failures, weak passwords, and a lack of audit logs, meaning there is no way to know who accessed or modified this data.
3- Regulatory Defiance: Despite orders from the European Data Protection Supervisor (EDPS) to delete data on innocent citizens in 2022, implementation has stalled.

The Justification vs. The Reality
Europol maintains that these systems are essential for modern counter-terrorism and the fight against organized crime. They deny the "shadow IT" label, claiming the environment was regulated and disclosed in 2019.
However, with 15 major security recommendations still unfulfilled as of early 2026, the gap between "essential processing" and "unregulated surveillance" has never looked wider.

⚖️ The Big Question:
Can we trust law enforcement agencies to self-regulate when the "emergency" measures of 2015 become the permanent (and secret) infrastructure of 2026?

DataPrivacyCyberSecurityEuropolEDPSGDPRDigitalRightsTechEthicsBreakingNews

What's Your Reaction?

like

dislike

love

funny

angry

sad

wow