History
07/23/20260 new articles
The story now places stronger emphasis on the Commission breach as a broader multi-institution exposure, with a higher affected-client count and a new supply-chain link to a Trivy-stolen AWS credential. It also adds a separate reported intrusion path involving Ivanti Endpoint Manager Mobile vulnerabilities, widening the technical scope beyond cloud credential theft alone.
07/23/20260 new articles
CERT-EU has now attributed the Commission breach more specifically to TeamPCP and tied it to a stolen management-level API key from a Trivy supply-chain attack, sharpening the technical understanding of how the intrusion occurred. The scope was also clarified upward, with tens of thousands of files confirmed exfiltrated and the Council of Europe claim still remaining unverified.
- TeamPCP was attributed the Commission intrusion by CERT-EU.
- The stolen API key came from a Trivy supply-chain attack.
- Forty-two internal clients were potentially affected.
- Tens of thousands of files were confirmed exfiltrated.
- ShinyHunters published an alleged 90GB archive.
07/21/20262 new articles
The story has broadened from a single European Commission cloud breach into a wider set of EU-institution data-theft and extortion claims, including an unconfirmed Council of Europe incident. The Commission case is now more specific about TeamPCP’s AWS API-key compromise and the scale of exfiltrated data across multiple Union entities.
- CERT-EU attributes the Commission breach to TeamPCP.
- At least 29 other Union entities were reportedly affected.
- ShinyHunters claimed a 90GB Commission dataset.
- ShinyHunters claimed nearly 300GB from the Council of Europe.
- The Council of Europe has not confirmed a breach.
05/13/20260 new articles
The story is now more explicitly framed as a confirmed cloud breach of Commission-hosted web infrastructure, with stronger attribution to a supply-chain-linked AWS credential compromise and clearer identification of the leak-site actor. The current version also adds regulatory notification and stresses that internal systems were not affected.
05/12/2026Topic Formed
The European Commission’s cloud breach remains the dominant event, with reporting converging on stolen AWS credentials, delayed detection, and large-scale exfiltration of EU-hosted data that was later published on the dark web. The incident is now framed less as a simple intrusion and more as a supply-chain-enabled exposure affecting multiple Commission and EU-affiliated web services.