
The notorious SiegedSec hacker group has announced on Telegram that it infiltrated NATO’s internal systems and stole several gigabytes of confidential data.The threat group disclosed this week that it hacked into the internal systems of NATO and stole around 9GB of data, including around 3,000 confidential NATO documents.“The astonishing siegedsec hackers have struck NATO once more!!1!!! We tend to have fun breaching intergovernmental alliances between large nations :p” We bring to you over 3 thousand files totalling to over 9GB of uncompressed Data!” the hacker group posted on its Telegram channel on 1st October.SiegedSec added that it gained access to NATO’s Joint Advanced Distributed Learning, NATO Lessons Learned Portal, Logistics Network Portal, Communities of Interest Cooperation Portal, NATO investment Division Portal and NATO standardisation Office and stole thousands of confidential documents.Acknowledging the reports of a data breach, NATO officials said that the organisation is actively addressing the incident and has launched an internal investigation to understand the authenticity of SiegedSec‘s claims.In an official statement shared with the media, a NATO spokesperson said, “NATO is facing persistent cyber threats and takes cyber security seriously.“NATO cyber experts are actively addressing incidents affecting some unclassified NATO websites. Additional cyber security measures have been put in place. There has been no impact on NATO missions, operations and military deployments.”This is the second time in less than six months that the SiegedSec hacker group has claimed responsibility for infiltrating NATO’s internal network and stealing confidential documents. The group claimed a similar attack on NATO’s internal systems in July.According to cyber security firm CloudSEK, the documents stolen in July included 845 megabytes of compressed data with almost 8,000 rows of user-related sensitive data, unclassified documents, and user account access details including name, company or unit, working group, job title, business Email ID, home address and photo.Commenting on the news, Ryan McConechy, CTO at Barrier Networks, said, “NATO must investigate these claims as a priority to understand if the compromised files relate to a new data breach or if they are part of the incident that took place in July.“If the documents relate to a new breach, this would indicate that SiegedSec still has a gateway into NATO’s network that was not remediated in the last clean up. This gateway must be closed when NATO is investigating this breach and it must run assessments on its network to ensure all pathways are closed to adversaries, otherwise this won’t be the last time NATO features on a breach notification site.“As cybercrime continues to increase globally, it is vital government organisations take steps to improve their defences. Experiencing two breaches so close together is something that must be avoided, as it undermines the security of the organisation and gives attackers the impression that they have an easy target within their reach,” McConechy added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543