Cloud Account Takeover After Trivy Supply-Chain Compromise
A compromised update to the Aqua Security Trivy vulnerability scanner delivered an API key that allowed attackers to take over an EU European Commission AWS account. This access enabled the theft of over 300GB of data from cloud infrastructure supporting public websites for the European Commission and affiliated EU entities. The attackers used the stolen key to create new access keys, perform reconnaissance, and pivot to other AWS accounts, demonstrating that the blast radius extends beyond local Trivy installations to any cloud environment trusting these credentials.
The incident unfolded over five days, with the API key compromised on March 19 and data exfiltration confirmed on March 24. This delay shows that attackers can maintain a multi-day dwell time in cloud environments after supply-chain compromises, making simple patching insufficient to contain the breach. Environments using the compromised Trivy build should be treated as fully breached across cloud services, not just as a
7 sources · Apr 4
Community Assessment
Threat researchers at SANS ISC tracked TeamPCP supply-chain activity before publication, and later media tied CERT-EU’s attribution to TeamPCP with spillover data exposure across at least 30 EU entities, widening this beyond a single EC account breach.
Europe’s cyber agency blames hacking gangs for massive data breach and leak | TechCrunch
CERT-EU blamed the cybercrime group TeamPCP for the recent hack on the European Commission, and said the notorious ShinyHunters gang was responsible for leaking the stolen data online.