Cyber attacks

Nikolaj Nielsen made this access to documents request to European Agency for the operational management of large-scale IT systems in the area of freedom, security and justice Automatic anti-spam measures are in place for this older request. Please let us know if a further response is expected or if you are having trouble responding.

Response to this request is long overdue. By law, under all circumstances, European Agency for the operational management of large-scale IT systems in the area of freedom, security and justice should have responded by now (details). You can complain by requesting an internal review.

Dear European Agency for the operational management of large-scale IT systems in the area of freedom, security and justice,

Under the right of access to documents in the EU treaties, as developed in Regulation 1049/2001, I am requesting documents which contain the following information:

documents held by the Agency concerning cyber‑attacks and attempted intrusions against large‑scale IT systems managed by eu‑LISA.

I respectfully request access to any document, irrespective of format (including, but not limited to, reports, incident notifications, technical assessments, risk analyses, briefings, correspondence, and minutes), produced or received by eu‑LISA between 1 January 2024 and the present date, that:

Refers to, analyses or records any actual or attempted cyber‑attack, hacking attempt, intrusion, or other form of unauthorised access targeting:

-the Schengen Information System (SIS),
- the Visa Information System (VIS),
- Eurodac,
- the Entry/Exit System (EES),

the European Travel Information and Authorisation System (ETIAS), and/or any other large‑scale IT system or central infrastructure operated by eu‑LISA.

Identifies, mentions or discusses as a (suspected or confirmed) source of such activity: the Russian Federation or actors linked to Russia, any other non‑EU state, any state‑sponsored group, or any non‑state actor (including organised crime groups or other advanced persistent threat actors).

Concerns the assessment of the threat landscape, vulnerabilities, or risk scenarios specifically in relation to state or non‑state actors attempting to compromise the confidentiality, integrity or availability of the systems listed above, including hack‑and‑leak scenarios, data‑exfiltration attempts, ransomware, distributed‑denial‑of‑service attacks, or other advanced persistent threats.

Records or reflects notifications or exchanges with:

EU Member States, the European Commission, the European Data Protection Supervisor (EDPS), or other EU agencies (e.g. Europol, Eurojust, Frontex) regarding security incidents or attempted intrusions affecting the large‑scale IT systems for which eu‑LISA provides technical and operational management, in line with the applicable incident‑notification rules.

If possible, I would prefer to receive the documents in electronic form, by email.

Should you consider that parts of the requested documents fall under any of the exceptions laid down in Regulation 1049/2001, I kindly request that you apply partial access and redact only the specific passages that are considered sensitive, granting access to the remainder of the documents.

In that case, I would also appreciate a justification for any redactions or refusals, including reference to the specific exception(s) relied upon.

If this request is considered too wide or insufficiently precise, I would be grateful for your assistance in refining it, as foreseen by Article 6(2) of Regulation 1049/2001.

Yours faithfully,
Nikolaj Nielsen

EUobserver
Résidence Palace, International Press Centre
Rue de la Loi / Wetstraat 155
1040 Brussels

EULISA PAD, European Agency for the operational management of large-scale IT systems in the area of freedom, security and justice

Dear Mr Nielsen,

Thank you for your email and for your interest in eu-LISA.

In your email dated 23 February 2026, you indicated your intention to submit an application for access to documents pursuant to Regulation (EC) No 1049/2001 regarding public access to European Parliament, Council and Commission documents (hereinafter “PAD Regulation").

Before we can proceed with the registration and processing of your request, please note that, in accordance with Article 2 of the PAD Regulation and Article 5(3) of eu-LISA Management Board Decision No 2022-090 laying down practical arrangements regarding public access to the documents held by the Agency (hereinafter “Decision No 2022-090”), initial applications must be accompanied by:

• a copy of a valid identity document; or
• proof of residence in a Member State of the European Union; or
• in the case of a legal person, proof of the registered office in a Member State, together with evidence demonstrating the link between the individual submitting the application and the legal person concerned.

Furthermore, pursuant to Article 6(1) of Decision No 2022-090, only applications that comply with the requirements set out in Article 5 thereof may be registered and processed by the Agency.

You are therefore kindly requested to submit, by email to [eu-LISA request email], an electronic copy of the relevant supporting document within three (3) working days, i.e. by 1 March 2026.

Should we not receive the requested documentation within this deadline, your application will not be registered and will be considered closed without further action.

Thank you for your cooperation.

Yours sincerely,

PAD Team
Legal Sector

Vesilennuki 5,
10415 Tallinn, Estonia
[email address]
www.eulisa.europa.eu

show quoted sections

Dear EULISA PAD,

I have sent you a copy of my ID.

Yours sincerely,

Nikolaj Nielsen