Breaches · 164 days ago
Cloud Account Takeover After Trivy Supply-Chain Compromise A compromised update to the Aqua Security Trivy vulnerability scanner delivered an API key that allowed attackers to take over an EU European Commission AWS account. This access enabled the theft of over 300GB of data from cloud infrastructure supporting public websites for the European Commission and affiliated EU entities. The attackers used the stolen key to create new access keys, perform reconnaissance, and pivot to other AWS accounts, demonstrating that the blast radius extends beyond local Trivy installations to any cloud environment trusting these credentials.
The incident unfolded over five days, with the API key compromised on March 19 and data exfiltration confirmed on March 24. This delay shows that attackers can maintain a multi-day dwell time in cloud environments after supply-chain compromises, making simple patching insufficient to contain the breach. Environments using the compromised Trivy build should be treated as fully breached across cloud services, not just as a
Timeline Sources 7 sources covering this story
SecurityWeek Apr 4
European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
Hackers stole over 300GB of data from the Commission’s AWS environment, including personal information.
The Record from Recorded Future Apr 3
EU cyber agency attributes major data breach to TeamPCP hacking group
The European Union’s cybersecurity agency said the hacking group TeamPCP was behind a massive recent data breach at the European Commission.
TechCrunch Security Apr 3
Europe’s cyber agency blames hacking gangs for massive data breach and leak | TechCrunch
CERT-EU blamed the cybercrime group TeamPCP for the recent hack on the European Commission, and said the notorious ShinyHunters gang was responsible for leaking the stolen data online.
SANS ISC Apr 3
TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments
TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, Author: Kenneth Hartman
CSO Online Apr 3
CERT-EU blames Trivy supply chain attack for Europa.eu data breach
Attackers exploited a vulnerability scanner to steal 350GB of data that they then leaked on the dark web.
Help Net Security Apr 3
Trivy supply chain attack enabled European Commission cloud breach - Help Net Security
ShinyHunters are behind the recent breach of the cloud infrastructure underpinning the websites of the European Commission, CERT-EU says.
BleepingComputer Apr 3
CERT-EU: European Commission hack exposes data of 30 EU entities
The European Union's Cybersecurity Service (CERT-EU) has attributed the European Commission cloud hack to the TeamPCP threat group, saying the resulting breach exposed the data of at least 29 other Union entities.
Entities Part of the PlainSec briefing for 2026-04-06
Editions
Breaches · 164 days ago
Cloud Account Takeover After Trivy Supply-Chain Compromise A compromised update to the Aqua Security Trivy vulnerability scanner delivered an API key that allowed attackers to take over an EU European Commission AWS account. This access enabled the theft of over 300GB of data from cloud infrastructure supporting public websites for the European Commission and affiliated EU entities. The attackers used the stolen key to create new access keys, perform reconnaissance, and pivot to other AWS accounts, demonstrating that the blast radius extends beyond local Trivy installations to any cloud environment trusting these credentials.
The incident unfolded over five days, with the API key compromised on March 19 and data exfiltration confirmed on March 24. This delay shows that attackers can maintain a multi-day dwell time in cloud environments after supply-chain compromises, making simple patching insufficient to contain the breach. Environments using the compromised Trivy build should be treated as fully breached across cloud services, not just as a
Timeline Sources 7 sources covering this story
SecurityWeek Apr 4
European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
Hackers stole over 300GB of data from the Commission’s AWS environment, including personal information.
The Record from Recorded Future Apr 3
EU cyber agency attributes major data breach to TeamPCP hacking group
The European Union’s cybersecurity agency said the hacking group TeamPCP was behind a massive recent data breach at the European Commission.
TechCrunch Security Apr 3
Europe’s cyber agency blames hacking gangs for massive data breach and leak | TechCrunch
CERT-EU blamed the cybercrime group TeamPCP for the recent hack on the European Commission, and said the notorious ShinyHunters gang was responsible for leaking the stolen data online.
SANS ISC Apr 3
TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments
TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, Author: Kenneth Hartman
CSO Online Apr 3
CERT-EU blames Trivy supply chain attack for Europa.eu data breach
Attackers exploited a vulnerability scanner to steal 350GB of data that they then leaked on the dark web.
Help Net Security Apr 3
Trivy supply chain attack enabled European Commission cloud breach - Help Net Security
ShinyHunters are behind the recent breach of the cloud infrastructure underpinning the websites of the European Commission, CERT-EU says.
BleepingComputer Apr 3
CERT-EU: European Commission hack exposes data of 30 EU entities
The European Union's Cybersecurity Service (CERT-EU) has attributed the European Commission cloud hack to the TeamPCP threat group, saying the resulting breach exposed the data of at least 29 other Union entities.
Entities Part of the PlainSec briefing for 2026-04-06
Editions