
The European Union's cybersecurity agency has confirmed that a significant data breach at the EU's executive body was orchestrated by a cybercriminal group known as TeamPCP. In a detailed report released on Thursday, CERT-EU disclosed that approximately 92 gigabytes of compressed data were stolen from a compromised Amazon Web Services (AWS) account utilized by the European Commission. This data includes sensitive personal information such as names, email addresses, and email content. The breach impacted the cloud infrastructure of the Commission’s Europa.eu platform, which serves as a resource for member states to host various websites and publications related to EU institutions and agencies. CERT-EU warned that the data of at least 29 other EU entities might also be compromised, as well as internal data from numerous European Commission clients. Following the breach, the stolen data was publicly released by another hacking group known as ShinyHunters. The incident underscores a troubling trend where cybercriminals collaborate to maximize their extortion efforts. CERT-EU traced the breach back to March 19, when hackers obtained a secret API key linked to the European Commission's AWS account, a vulnerability that arose from the Commission inadvertently downloading a compromised version of the open-source security tool Trivy. As the analysis of the leaked data continues, it has been found that around 52,000 files include sent email messages. While most of these emails are automated and contain minimal content, those that bounced back due to errors may reveal original user-submitted information, raising concerns about personal data exposure. CERT-EU is already in communication with the organizations affected by this breach. Although the European Commission is currently closed for comments until next week, a spokesperson indicated that they will respond to inquiries when they reopen. Meanwhile, a member of ShinyHunters has not replied to requests for comments. In addition to the Trivy breach, TeamPCP has been associated with various ransomware attacks and crypto-mining campaigns, according to Aqua Security, which develops the Trivy tool. Recent reports from Palo Alto Networks Unit 42 highlight that these hackers have been executing a systematic campaign of supply chain attacks targeting other open-source security projects. By compromising developers with access to critical systems, they are able to hold organizations ransom, demanding payments for the restoration of access.
Corgi, the insurance technology startup backed by Y Combinator, has recently found itself at the center of a controversy...
TechCrunch | Jun 26, 2026, 22:10
Beginning July 1, streaming services operating in California will face new regulations prohibiting advertisements from b...
Ars Technica | Jun 26, 2026, 21:15
Tennis champion Novak Djokovic has been appointed as a global strategic advisor for General Atlantic, a prominent privat...
TechCrunch | Jun 26, 2026, 19:45
In a significant policy shift, the Trump administration has lifted restrictions on Anthropic's advanced cybersecurity mo...
TechCrunch | Jun 27, 2026, 01:20
In a bold move, South Korea has announced plans to train its entire military, which consists of nearly 500,000 personnel...
Ars Technica | Jun 26, 2026, 22:20