Skip to content

European Commission

Disclosed Mar 27, 20266 months agoConfirmed

Official notice

European Commission cloud breach via Trivy-stolen AWS key hits 30 EU bodies

The European Commission confirmed data was taken from its Europa.eu web hosting cloud. CERT-EU said TeamPCP used an AWS secret stolen in the Trivy supply-chain attack to exfiltrate data affecting 71 clients including at least 29 other EU bodies, and ShinyHunters leaked about 90 GB.

What is known

People affectedNot stated in the sources we have
DisclosedMar 27, 2026
DiscoveredMar 2026
AttackSupply chain
Data exposedNames, Emails, Messages, Internal documents
SectorGovernment · BE
StatusConfirmed
Part ofTrivy (2026)

Sources

Source
CERT-EU: European Commission cloud breachcert.europa.eu · Official notice
CERT-EU: European Commission hack exposes data of 30 EU entitiesbleepingcomputer.com · News
European Commission confirms data breach after Europa.eu hackbleepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalMar 27

Same campaign

History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about European Commission

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.