BotBeat
...
← Back

> ▌

Not ApplicableNot Applicable
POLICY & REGULATIONNot Applicable2026-04-04

European Commission Suffers Major Cloud Breach via Trivy Supply Chain Compromise

Key Takeaways

  • ▸Initial access was obtained through the Trivy supply-chain compromise attributed to TeamPCP, demonstrating the critical risk of compromised development tools in CI/CD pipelines
  • ▸The threat actor leveraged a single compromised AWS API key to escalate privileges, create backdoor access keys, and access multiple Commission accounts across 29+ Union entities
  • ▸91.7 GB of sensitive data including personal information was exfiltrated and subsequently published on dark web leak sites by ShinyHunters
Source:
Hacker Newshttps://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain↗

Summary

The European Commission experienced a significant cybersecurity incident affecting its public website platform europa.eu hosted on Amazon Web Services, with initial access gained through a supply-chain compromise of the Trivy vulnerability scanning tool attributed to threat actor TeamPCP. On March 24, the Commission's Cybersecurity Operations Centre detected suspicious activity including potential AWS API misuse and account compromise, leading to formal notification of CERT-EU on March 25. An investigation revealed that a malicious actor obtained an AWS API key through the Trivy compromise on March 19, which they used to create additional access keys and conduct reconnaissance across multiple Commission accounts. Approximately 91.7 GB of compressed data was exfiltrated, including personal information such as names, email addresses, and email content from at least 29 Union entities, before being publicly released by data extortion group ShinyHunters on March 28.

  • CERT-EU emphasizes that supply-chain compromises pose a significant and rising threat, urging organizations to implement enhanced security recommendations
CybersecurityPrivacy & Data

More from Not Applicable

Not ApplicableNot Applicable
POLICY & REGULATION

White House Warns of 'Industrial-Scale' AI Technology Theft Efforts from China

2026-04-23
Not ApplicableNot Applicable
RESEARCH

Study Reveals Sex-Based Differences in Brain Gene Expression Linked to Psychiatric and Neurological Disorder Risk

2026-04-23
Not ApplicableNot Applicable
RESEARCH

Research Shows AI Assistance Reduces Persistence and Impairs Independent Performance

2026-04-23

Comments

Suggested

AnthropicAnthropic
POLICY & REGULATION

Advanced AI Models Bring Government to 'Reflection Point,' CIA Official Says

2026-05-20
AnthropicAnthropic
RESEARCH

Anthropic Claude Code Sandbox Bypass: Second Vulnerability Exposes Critical Data Exfiltration Risk

2026-05-20
ChromaChroma
UPDATE

Critical Authentication Bypass Vulnerability in ChromaDB Allows Remote Code Execution

2026-05-20
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us