European Institutions Face Cloud Extortion
Coverage from BleepingComputer, Safestate, and others
Articles
8
Active Days
82
The Topic

European institutions are facing a series of cyber incidents involving cloud environments, hosted websites, employee data, and public leak threats. The European Commission confirmed that attackers accessed its AWS environment and exposed data associated with multiple Europa.eu clients, while CERT-EU attributed the intrusion to TeamPCP and linked the stolen credential to a Trivy supply-chain attack. ShinyHunters has separately claimed extensive theft from the Council of Europe, but that allegation remains under investigation and has not been independently verified.
First Article: 03/27/26
Latest Article: 06/16/26
Summary
- The European Commission confirmed a breach affecting its AWS-hosted Europa.eu environment, while reporting no website disruption or detected lateral movement into other Commission AWS accounts.
- CERT-EU attributed the Commission intrusion to TeamPCP and said attackers used a compromised AWS API key with management rights.
- The compromised environment contained data associated with up to 71 Europa web-hosting clients, including at least 29 other Union entities.
- A 90GB archive published by ShinyHunters reportedly contained tens of thousands of files with names, usernames, email addresses, and email content.
- The Commission incident was reportedly connected to a credential stolen in a Trivy supply-chain attack; attackers also searched for additional secrets and created new access keys.
- ShinyHunters claimed to have stolen nearly 300GB from the Council of Europe, including payroll and personnel records, but the organization has not confirmed a compromise.
- Separate reporting also links recent European institutional breaches to exploitation of Ivanti Endpoint Manager Mobile vulnerabilities.
History
The story now places stronger emphasis on the Commission breach as a broader multi-institution exposure, with a higher affected-client count and a new supply-chain link to a Trivy-stolen AWS credential. It also adds a separate reported intrusion path involving Ivanti Endpoint Manager Mobile vulnerabilities, widening the technical scope beyond cloud credential theft alone.
CERT-EU has now attributed the Commission breach more specifically to TeamPCP and tied it to a stolen management-level API key from a Trivy supply-chain attack, sharpening the technical understanding of how the intrusion occurred. The scope was also clarified upward, with tens of thousands of files confirmed exfiltrated and the Council of Europe claim still remaining unverified.
