ADVERTISEMENT

European Commission breach linked to Trivy attack, 29 EU entities at risk

Last month’s European Commission cloud breach – and the later leak of 350 GB of stolen data by ShinyHunters – are now tied to the TeamPCP hacker group and the recent Trivy supply-chain attack, according to CERT-EU.

commission-data-breach

Image by Cybernews.

Stefanie Schappert
Stefanie Schappert Senior Journalist
April 3, 2026 Updated: April 7, 2026 4 min read
Key takeaways:
European Commission building
European Commission headquarters in Brussels, Belgium. JPix/NurPhoto via Getty Images

How TeamPCP got in

aws-uae-incident
Image by Cybernews.

Strong password generator

Upgrade the security of your online accounts.
Create strong passwords that are completely random and impossible to guess.
Generated unique password
Ad link_title
Convenient way to secure and use all your passwords. Now 72% OFF!

What data the hackers took

ADVERTISEMENT
Shiny Hunters European Commission cloud breach
Shiny Hunters claims to have published about 350 GB of uncompressed data on its victim blog on March 28, 2026. European Commission cloud breach ShinyHunters leak site. Image by Cybernews

What organizations should do

  • Update to a known-safe version as identified by Aqua Security.
  • Audit and rotate all AWS secrets and credentials that may have been exposed to Trivy during the compromise window.
  • Audit Trivy versions deployed across all environments, including CI/CD pipelines.
  • Pin all GitHub Actions to full SHA hashes rather than mutable tags.
  • Search CI/CD logs and environments for exfiltration artefacts associated with TeamPCP (e.g., connections to typosquatted domains, unexpected Cloudflare tunnel activity).
Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.

ADVERTISEMENT