Last Update: 08/01/2026 at 2:00 PM EST

European Institutions Face Cloud Extortion

Coverage from BleepingComputer, Safestate, and others

Articles

8

Active Days

82

The Topic

European Institutions Face Cloud Extortion topic image

European institutions are facing a series of cyber incidents involving cloud environments, hosted websites, employee data, and public leak threats. The European Commission confirmed that attackers accessed its AWS environment and exposed data associated with multiple Europa.eu clients, while CERT-EU attributed the intrusion to TeamPCP and linked the stolen credential to a Trivy supply-chain attack. ShinyHunters has separately claimed extensive theft from the Council of Europe, but that allegation remains under investigation and has not been independently verified.

First Article: 03/27/26

Latest Article: 06/16/26

History

07/23/20260 new articles

The story now places stronger emphasis on the Commission breach as a broader multi-institution exposure, with a higher affected-client count and a new supply-chain link to a Trivy-stolen AWS credential. It also adds a separate reported intrusion path involving Ivanti Endpoint Manager Mobile vulnerabilities, widening the technical scope beyond cloud credential theft alone.

07/23/20260 new articles

CERT-EU has now attributed the Commission breach more specifically to TeamPCP and tied it to a stolen management-level API key from a Trivy supply-chain attack, sharpening the technical understanding of how the intrusion occurred. The scope was also clarified upward, with tens of thousands of files confirmed exfiltrated and the Council of Europe claim still remaining unverified.

  • TeamPCP was attributed the Commission intrusion by CERT-EU.
  • The stolen API key came from a Trivy supply-chain attack.
  • Forty-two internal clients were potentially affected.
  • Tens of thousands of files were confirmed exfiltrated.
  • ShinyHunters published an alleged 90GB archive.
07/21/20262 new articles

The story has broadened from a single European Commission cloud breach into a wider set of EU-institution data-theft and extortion claims, including an unconfirmed Council of Europe incident. The Commission case is now more specific about TeamPCP’s AWS API-key compromise and the scale of exfiltrated data across multiple Union entities.

  • CERT-EU attributes the Commission breach to TeamPCP.
  • At least 29 other Union entities were reportedly affected.
  • ShinyHunters claimed a 90GB Commission dataset.
  • ShinyHunters claimed nearly 300GB from the Council of Europe.
  • The Council of Europe has not confirmed a breach.
05/13/20260 new articles

The story is now more explicitly framed as a confirmed cloud breach of Commission-hosted web infrastructure, with stronger attribution to a supply-chain-linked AWS credential compromise and clearer identification of the leak-site actor. The current version also adds regulatory notification and stresses that internal systems were not affected.

05/12/2026Topic Formed

The European Commission’s cloud breach remains the dominant event, with reporting converging on stolen AWS credentials, delayed detection, and large-scale exfiltration of EU-hosted data that was later published on the dark web. The incident is now framed less as a simple intrusion and more as a supply-chain-enabled exposure affecting multiple Commission and EU-affiliated web services.