A breach at the network infrastructure provider Eurofiber was reported in late 2025, exposing data relating to critical infrastructure across European networks.
Documentation Is The Recurring High-Value Asset
This desk filed at 25-0611 that stolen network diagrams behave differently from personal data: they do not decay, they convert a future intrusion from exploration into navigation, and possessing them generates no detection event.
An infrastructure operator’s records are the physical-layer version. Where fibre runs, which routes carry which customers, where the exchange points and the single points of failure sit. That is a map of dependency for organisations that are not the operator’s problem and were never asked.
It Falls Outside Almost Every Regime In The Corpus
Notification law follows personal data, per 25-0916 and 25-1204. Infrastructure documentation concerns cables and routes, so the disclosure obligation is thin and the litigation route at 25-1228 has no class.
The regime that would reach it is the critical-supplier designation proposed at 25-1124 — and this is exactly the case that file warned about. A wholesale infrastructure provider is invisible to the organisations depending on it, which is what makes criticality emergent and designation hard.
What We Are Not Asserting
Graded medium. We have not established the extent of the exposed documentation, which customers it covered, or whether any operational risk followed. Infrastructure breaches attract speculation about sabotage potential and this desk is not making that argument on this evidence.
Compiled from published research reporting, listed below. Scope of exposure is not established and no actor is named. Corrections: corrections@forensicpost.com.