Cyber & Technology — 2026-04-04

European Commission AWS Breach Exposes 340 GB of Data from 30+ EU Entities via Trivy Supply Chain Attack

CERT-EU attributed a major breach of the European Commission's AWS infrastructure to the hacking group TeamPCP, which exploited a supply chain compromise in the open-source security tool Trivy to steal API keys on March 19. The attackers exfiltrated over 340 GB of uncompressed data including personal information, email contents, and internal documents from 71 clients on the Europa web hosting service. At least 29 other EU entities may be affected. The stolen data was subsequently leaked online by ShinyHunters.

Analysis
The Trivy supply chain vector is the critical detail: an open-source security tool used to protect infrastructure became the entry point for its compromise. The 71 clients affected via Europa web hosting suggests the breach may have exposed diplomatic communications and policy drafts across multiple EU institutions. The ShinyHunters secondary leak guarantees the data is now in wide circulation, limiting damage control options.
3 sources
  1. Europe's cyber agency blames hacking gangs for massive data breach and leak - TechCrunch
  2. EU cyber agency attributes major data breach to TeamPCP hacking group - The Record
  3. CERT-EU: European Commission hack exposes data of 30 EU entities - BleepingComputer

View in full brief →

UNCLASSIFIED // OPEN SOURCE