HomeSecurityEuropean Commission Cloud Breach: 91GB of Data Leaked

European Commission Cloud Breach: 91GB of Data Leaked

The European Commission cloud breach didn’t start with a dramatic system attack or an obvious outage. It started quietly, with a trusted tool, an update routine, and a single compromised credential. Within days, that was enough to expose nearly 91.7 GB of data and implicate multiple EU entities in a widening cybersecurity incident.

See also: Vertex AI vulnerability exposes Google Cloud data and files

cloud

The European Commission's cloud breach, publicly disclosed on March 27, is now seen as a clear example of how supply chain attacks are reshaping risk in cloud environments. Not because defenses were absent, but because the entry point seemed legitimate.

Researchers from CERT-EU state with high certainty that the European Commission's cloud breach began with a breach in the supply chain involving Trivy, a widely used security scanning tool. The malicious version, attributed to a threat actor known as TeamPCP, was inadvertently deployed in the Commission's environment after being delivered through normal information channels.

On March 19, the attacker obtained an AWS secret, an API key — with administrative privileges. This unique key became the gateway to the Commission’s cloud. From there, the activity was intentional. The attacker attempted to reveal more credentials using TruffleHog, a tool designed to scan for secrets and validate access through the AWS Security Credential Service (STS). They also created a new access key associated with an existing user, an attempt to maintain access while avoiding detection.

The impact became clearer a few days later. A large amount of data — about 91.7 GB compressed, or about 340 GB uncompressed — was extracted from the compromised AWS account.

On March 28, the data extortion group ShinyHunters published the dataset on its dark web leak site. The group claimed that it included “data dumps from mail servers, databases, confidential documents, contracts, and much more sensitive material.”

Initial analysis confirms that the European Commission's cloud breach exposed personal data, including names, usernames and email addresses. The dataset also contains more than 51,000 files linked to outgoing email communications.

See also: Microsoft: Investments in Thailand for cloud and AI infrastructure

European Commission Cloud Breach: 91GB of Data Leaked

While most of these emails are automated notifications, some “bounce-back” messages may include original user-submitted content. This detail is important, as it increases the risk of inadvertent exposure of personal data in systems that rely on user interaction.

The timeline of the European Commission's cloud breach highlights how quickly such incidents can unfold:

  • March 19: AWS credential obtained via compromised Trivy tool
  • March 24: Alerts triggered due to unusual API activity and traffic spikes
  • March 25: CERT-EU was notified, access was secured and keys were revoked
  • March 27: Public disclosure by the European Commission
  • March 28: Data published by ShinyHunters

In less than ten days, the attack moved from initial access to public data exposure.

The European Commission acted quickly once the breach was discovered. The compromised AWS secret was secured, the newly generated access keys were deactivated, and all known exposed credentials were disabled or deleted.

The authorities also followed regulatory protocol by informing data protection authorities, including the European Data Protection Supervisor (EDPS), and notifying affected entities. Direct communication with affected customers began on March 31.

Importantly, the Commission has stated that its internal systems were not affected. However, the European Commission cloud breach remains under active investigation, particularly as analysis of the exposed databases continues.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The European Commission’s cloud breach is not just about one incident or one tool. It reflects a deeper issue: the increasing difficulty of verifying trust in modern software ecosystems. Cloud environments, automated workflows, and open source tools have made operations faster and more efficient. But they have also introduced new blind spots.

See also: European Commission investigates breach related to cloud infrastructure

European Commission Cloud Breach: 91GB of Data Leaked

The lesson here is uncomfortable but clear — the security controls worked, but they worked slowly. The detection came after access had already been established and the data had already been moved. And therein lies the real danger.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS