Europe’s cyber agency blames hacking gangs for massive data breach and leak

Key summary
CERT-EU says the breach was carried out by the cybercriminal group TeamPCP.
Approximately 92 GB of compressed data were stolen from a compromised AWS account used by the European Commission; the Europa.eu cloud infrastructure was affected.
CERT-EU warned data of at least 29 other EU entities may be affected; the stolen material was later posted online by ShinyHunters.
The incident began on March 19 after attackers obtained a secret API key tied to the Commission’s AWS account; that key was acquired following an earlier hack targeting the Trivy tool and because the Commission downloaded a compromised Trivy copy.
The haul includes about 52,000 sent email files; bounced emails may contain original user-submitted content that could expose personal data, and CERT-EU is already contacting affected organizations.


