HomeIntelligenceBrief
🔓 BREACH BRIEF🟠 High🔓 Breach

EU Commission AWS Account Compromised by TeamPCP, 92 GB of Sensitive Data Stolen

CERT‑EU says the hacking group TeamPCP used a stolen AWS API key to breach the European Commission’s cloud environment, exfiltrating 92 GB of internal files containing personal and email data. The incident highlights supply‑chain risks in cloud‑native tooling for public‑sector vendors.

🛡️ LiveThreat™ Intelligence · 📅 April 04, 2026· 📰 therecord.media
🟠
Severity
High
🔓
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
therecord.media

EU Commission AWS Account Compromised by TeamPCP, 92 GB of Sensitive Data Exfiltrated

What Happened — CERT‑EU confirmed that the hacking group TeamPCP accessed the European Commission’s Amazon Web Services (AWS) account using a stolen API key, downloading roughly 92 GB of compressed files that contain names, email addresses and outbound email content. The breach was first detected on 24 March after alerts of abnormal network traffic and potential API misuse.

Why It Matters for TPRM

  • Highlights the critical risk of supply‑chain‑compromised tooling (Trivy) that can expose privileged cloud credentials.
  • Demonstrates how a single API key can give attackers lateral movement across a public‑sector cloud estate.
  • Personal data of EU officials and agencies was exfiltrated, creating regulatory, privacy and reputational exposure for any downstream vendors.

Who Is Affected — Government & public‑sector bodies (European Commission, EU member‑state entities, internal client agencies).

Recommended Actions — Review cloud‑service contracts for API‑key management clauses, enforce least‑privilege IAM policies, conduct a supply‑chain software‑bill‑of‑materials audit, and implement continuous cloud‑traffic anomaly detection.

Technical Notes — Attack vector leveraged a compromised version of the open‑source container scanner Trivy, enabling the theft of a secret AWS API key (third‑party dependency compromise). Exfiltrated data included ~52 000 email‑related files (≈2.2 GB) and additional confidential documents. Source: The Record

📰 Original Source
https://therecord.media/european-commission-cyberattack-teampcp

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

🛡️

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.