A serious security breach in the European Commission's cloud environment highlights the growing risks facing the European institutions. The attack, attributed by CERT-EU to TeamPCP, led to a data leak affecting not only the Commission itself but also dozens of other European Union entities.

The incident was publicly disclosed in late March, but the initial intrusion occurred several days earlier, highlighting delays in detecting suspicious activity. The lack of timely alerts for malicious API use or abnormal network traffic raises questions about the effectiveness of monitoring mechanisms.
How the breach was carried out via AWS and API keys
The attack appears to have started with the use of a compromised API key in the Amazon Web Services environment, which granted extensive administrative privileges. This credential had previously been leaked through a supply chain attack related to the Trivy tool.
See also: Granola: Notes Leak – Change Privacy Settings
The attackers then leveraged the TruffleHog to discover additional secrets and credentials within the environment. By adding a new access key to an existing user, they were able to remain invisible for a longer period of time, performing identification and data extraction without triggering alarms.
The extent of the spill and the organisms affected
CERT-EU's analysis revealed that the breach affected up to 71 organisations related to the europa.eu web hosting service. These include 42 internal Commission services and at least 29 other European Union entities.
The leaked data includes personal information such as names, usernames and email addresses, as well as files related to emails. While a large portion of the emails are automated notifications, there are cases where user content, increasing the risk of exposing sensitive information.

Data publication and the role of ShinyHunters
The case took an even more serious turn when the ShinyHunters group published the stolen data on the dark web. The archive, which exceeds 90GB in compressed form, includes tens of thousands of files and communications, making the leak one of the largest to affect a European institution.
See also: Stryker returns to full operation after data-wiping attack
Making this data public increases the risk of further attacks, such as phishing or targeted fraud, as attackers can leverage the information for more convincing deception scenarios.
TeamPCP and supply chain attacks
TeamPCP has been linked to a series of attacks on software development platforms such as GitHub, PyPI, and NPM, as well as the distribution of malicious packages. In previous incidents, it has used information-stealing tools to gain access to cloud infrastructure and corporate systems.
Her activity highlights the growing importance of security in the software supply chain , as even trusted tools can serve as an entry point for large-scale attacks.

Impacts and need to strengthen cybersecurity
Although no lateral movement was detected in other systems and no services were disrupted, the incident highlights serious weaknesses in credential management and early threat detection. The European Commission has already informed the relevant data protection authorities and is working with the relevant bodies to mitigate the impact.
See also: Intesa Sanpaolo: Unauthorized access for 2 Years
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This incident, combined with previous breaches that have hit European systems, confirms that cyber threats are becoming increasingly complex. For organizations, the challenge is not only to protect infrastructure, but also to ensure that they can detect and respond to attacks in real time, before they develop into large-scale crises.
Source: www.bleepingcomputer.com
