Observed Signal · Apr 3, 2026 · Data Breach · Source: techcrunch · Impact: 3/5 · Sentiment: Negative

CERT-EU Blames TeamPCP for European Commission Data Breach

Executive Signal Summary

CERT-EU reported that a cybercriminal group known as TeamPCP breached an Amazon Web Services account used by the European Commission, stealing roughly 92 GB of compressed data from the Commission's Europa.eu cloud infrastructure. The stolen material — later posted online by the hacking group ShinyHunters — included names, email addresses and the contents of emails; CERT-EU said at least 29 other EU entities and dozens of internal Commission clients may be affected. The agency traced the intrusion to March 19 after attackers acquired a secret AWS API key following a supply-chain compromise of the open-source security tool Trivy. CERT-EU is contacting affected organizations and continues analyzing the published data.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A large-scale breach of the European Commission's cloud infrastructure exposes personal data across multiple EU entities and highlights supply‑chain risks in open-source security tools and cloud credential management—issues with cross-industry operational and regulatory implications.

SIGNAL RADAR

Track Palo Alto Networks Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • CERT-EU attributed a recent breach of the European Commission's AWS account to the cybercriminal group TeamPCP.
  • Attackers stole approximately 92 gigabytes of compressed data from the Commission's AWS account tied to the Europa.eu platform.
  • CERT-EU said data of at least 29 other EU entities and dozens of internal Commission clients may be impacted.
  • The breach began March 19 after hackers obtained a secret API key via a supply-chain compromise of the open-source tool Trivy; stolen data was later posted online by ShinyHunters.
  • Close to 52,000 files in the published dataset contain sent email messages; many are automated but some bounced/error emails may expose original user-submitted content.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Apr 3, 2026
Original Coverage Title: “Europe’s cyber agency blames hacking gangs for massive data breach and leak | TechCrunch”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

InfrastructureMar 27, 2026

European Commission Confirms Cloud Cyberattack

The European Commission confirmed a cyberattack that affected part of its cloud infrastructure hosting the Europa.eu web presence. A Commission spokesperson, Nika Blazevic, said the attack was discovered and contained, mitigation measures implemented, and that internal Commission systems were not affected; the investigation is ongoing. Security outlet Bleeping Computer reported the breach first, saying hackers claimed to have extracted hundreds of gigabytes — including multiple databases — from the Commission’s Amazon Web Services account and provided screenshots as proof. The Commission’s statement did not specify what types of data were taken.

Read assessment
Platform Security / Data BreachMay 20, 2026

Team‑PCP steals 3,800 internal GitHub repositories

The hacker group Team‑PCP accessed approximately 3,800 internal GitHub repositories between May 18 and May 19, 2026, and is attempting to sell the stolen data. GitHub confirmed the incident on X and said no customer data was affected. According to GitHub, attackers used a compromised employee device that had a malicious Visual Studio Code extension installed; the impacted endpoint was isolated and incident response measures were taken. Team‑PCP, previously linked to a March 2026 supply‑chain attack and said to collaborate with the Ransomware‑as‑a‑Service operator Vect, is offering the GitHub data for sale and reportedly coordinated with the LAPSUS$ group in later negotiations.

Read assessment
PrivacyAug 10, 2026

Ceva Logistics hack exposes customer data across Europe

Ceva Logistics, a France-headquartered global shipping and logistics company, suffered a cyber intrusion that has impacted at least eight European warehouses and resulted in the theft of customer personal information. The attack, which industry reporting says began on July 29, has caused shipping delays and order cancellations for multiple retailers and organizations that use Ceva for fulfillment. Affected parties named in reporting include Dutch retailers Bol and De Bijenkorf, football club Ajax, bank ING, eyeglass maker Ace & Tate, and game company Valve (which notified Steam hardware customers). Ceva confirmed the intrusion on Aug. 1, said it is investigating, restored some services, and is working with authorities; the Dutch data protection authority has received breach reports from 10 organizations.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.