European Commission
Disclosed Mar 27, 20266 months agoConfirmed
European Commission cloud breach via Trivy-stolen AWS key hits 30 EU bodies
The European Commission confirmed data was taken from its Europa.eu web hosting cloud. CERT-EU said TeamPCP used an AWS secret stolen in the Trivy supply-chain attack to exfiltrate data affecting 71 clients including at least 29 other EU bodies, and ShinyHunters leaked about 90 GB.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Mar 27, 2026 |
| Discovered | Mar 2026 |
| Attack | Supply chain |
| Data exposed | Names, Emails, Messages, Internal documents |
| Sector | Government · BE |
| Status | Confirmed |
| Part of | Trivy (2026) |
Sources
| Source | |
|---|---|
| CERT-EU: European Commission cloud breachcert.europa.eu · Official notice | Official notice |
| CERT-EU: European Commission hack exposes data of 30 EU entitiesbleepingcomputer.com · News | News |
| European Commission confirms data breach after Europa.eu hackbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Mar 27 |
Same campaign
| Organization | Affected | ||||
|---|---|---|---|---|---|
| Apr 265 months ago | Supply chain | Tech | Confirmed | Unknown | |
| Mar 315 months ago | Supply chain | Tech | Unverified | Unknown | |
| Mar 246 months ago | Supply chain | AI | Unverified | Unknown | |
| Mar 216 months ago | Supply chain | Tech | Unverified | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.