Observed Signal · Apr 3, 2026 · Data Breach · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
CERT-EU Blames TeamPCP for European Commission Data Breach
CERT-EU reported that a cybercriminal group known as TeamPCP breached an Amazon Web Services account used by the European Commission, stealing roughly 92 GB of compressed data from the Commission's Europa.eu cloud infrastructure. The stolen material — later posted online by the hacking group ShinyHunters — included names, email addresses and the contents of emails; CERT-EU said at least 29 other EU entities and dozens of internal Commission clients may be affected. The agency traced the intrusion to March 19 after attackers acquired a secret AWS API key following a supply-chain compromise of the open-source security tool Trivy. CERT-EU is contacting affected organizations and continues analyzing the published data.
A large-scale breach of the European Commission's cloud infrastructure exposes personal data across multiple EU entities and highlights supply‑chain risks in open-source security tools and cloud credential management—issues with cross-industry operational and regulatory implications.
Track Palo Alto Networks Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- CERT-EU attributed a recent breach of the European Commission's AWS account to the cybercriminal group TeamPCP.
- Attackers stole approximately 92 gigabytes of compressed data from the Commission's AWS account tied to the Europa.eu platform.
- CERT-EU said data of at least 29 other EU entities and dozens of internal Commission clients may be impacted.
- The breach began March 19 after hackers obtained a secret API key via a supply-chain compromise of the open-source tool Trivy; stolen data was later posted online by ShinyHunters.
- Close to 52,000 files in the published dataset contain sent email messages; many are automated but some bounced/error emails may expose original user-submitted content.
Connected Companies & Entities
2 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
European Commission Confirms Cloud Cyberattack
The European Commission confirmed a cyberattack that affected part of its cloud infrastructure hosting the Europa.eu web presence. A Commission spokesperson, Nika Blazevic, said the attack was discovered and contained, mitigation measures implemented, and that internal Commission systems were not affected; the investigation is ongoing. Security outlet Bleeping Computer reported the breach first, saying hackers claimed to have extracted hundreds of gigabytes — including multiple databases — from the Commission’s Amazon Web Services account and provided screenshots as proof. The Commission’s statement did not specify what types of data were taken.
Team‑PCP steals 3,800 internal GitHub repositories
The hacker group Team‑PCP accessed approximately 3,800 internal GitHub repositories between May 18 and May 19, 2026, and is attempting to sell the stolen data. GitHub confirmed the incident on X and said no customer data was affected. According to GitHub, attackers used a compromised employee device that had a malicious Visual Studio Code extension installed; the impacted endpoint was isolated and incident response measures were taken. Team‑PCP, previously linked to a March 2026 supply‑chain attack and said to collaborate with the Ransomware‑as‑a‑Service operator Vect, is offering the GitHub data for sale and reportedly coordinated with the LAPSUS$ group in later negotiations.
Ceva Logistics hack exposes customer data across Europe
Ceva Logistics, a France-headquartered global shipping and logistics company, suffered a cyber intrusion that has impacted at least eight European warehouses and resulted in the theft of customer personal information. The attack, which industry reporting says began on July 29, has caused shipping delays and order cancellations for multiple retailers and organizations that use Ceva for fulfillment. Affected parties named in reporting include Dutch retailers Bol and De Bijenkorf, football club Ajax, bank ING, eyeglass maker Ace & Tate, and game company Valve (which notified Steam hardware customers). Ceva confirmed the intrusion on Aug. 1, said it is investigating, restored some services, and is working with authorities; the Dutch data protection authority has received breach reports from 10 organizations.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
