Last Update: 08/01/2026 at 1:00 PM EST

European Institutions Face Cloud Extortion

Coverage from BleepingComputer, Safestate, and others

Articles

8

Active Days

82

The Topic

European Institutions Face Cloud Extortion topic image

European institutions are facing a series of cyber incidents involving cloud environments, hosted websites, employee data, and public leak threats. The European Commission confirmed that attackers accessed its AWS environment and exposed data associated with multiple Europa.eu clients, while CERT-EU attributed the intrusion to TeamPCP and linked the stolen credential to a Trivy supply-chain attack. ShinyHunters has separately claimed extensive theft from the Council of Europe, but that allegation remains under investigation and has not been independently verified.

First Article: 03/27/26

Latest Article: 06/16/26

Summary

  • The European Commission confirmed a breach affecting its AWS-hosted Europa.eu environment, while reporting no website disruption or detected lateral movement into other Commission AWS accounts.
  • CERT-EU attributed the Commission intrusion to TeamPCP and said attackers used a compromised AWS API key with management rights.
  • The compromised environment contained data associated with up to 71 Europa web-hosting clients, including at least 29 other Union entities.
  • A 90GB archive published by ShinyHunters reportedly contained tens of thousands of files with names, usernames, email addresses, and email content.
  • The Commission incident was reportedly connected to a credential stolen in a Trivy supply-chain attack; attackers also searched for additional secrets and created new access keys.
  • ShinyHunters claimed to have stolen nearly 300GB from the Council of Europe, including payroll and personnel records, but the organization has not confirmed a compromise.
  • Separate reporting also links recent European institutional breaches to exploitation of Ivanti Endpoint Manager Mobile vulnerabilities.

History

07/23/2026

The story now places stronger emphasis on the Commission breach as a broader multi-institution exposure, with a higher affected-client count and a new supply-chain link to a Trivy-stolen AWS credential. It also adds a separate reported intrusion path involving Ivanti Endpoint Manager Mobile vulnerabilities, widening the technical scope beyond cloud credential theft alone.

07/23/2026

CERT-EU has now attributed the Commission breach more specifically to TeamPCP and tied it to a stolen management-level API key from a Trivy supply-chain attack, sharpening the technical understanding of how the intrusion occurred. The scope was also clarified upward, with tens of thousands of files confirmed exfiltrated and the Council of Europe claim still remaining unverified.

Full History

Featured

Timeline: 82 Days

Mar 27Apr 10Apr 24May 15May 29Jun 12

Additional Articles

⭐⭐⭐⭐⭐

Safestate06-16-2026
The Council of Europe investigates ShinyHunters extortion claims alleging exposure of payroll and medical-related personnel data before a June 16, 2026 response deadline.
TechRepublic / Joseph Ofonagoro06-16-2026
ShinyHunters demanded action by June 16, 2026 by the Council of Europe after claiming exposure of payroll and medical employee records totaling 297GB.
OODA Loop04-17-2026
European Commission and CERT-EU reported 300GB of data stolen from an AWS environment after a Trivy supply chain API key compromise enabled exfiltration.

⭐⭐⭐

BleepingComputer / Sergiu Gatlan04-02-2026
CERT-EU attributed a March 10 European Commission AWS cloud breach to TeamPCP, reporting delayed detection and exposure of personal data later published on a ShinyHunters dark-web site.
TechCrunch / Zack Whittaker03-27-2026
European Commission officials confirmed a cloud infrastructure cyberattack on Europa.eu hosting, with containment steps taken after reported Amazon Web Services data theft.