{"id":232414,"date":"2026-04-03T15:50:43","date_gmt":"2026-04-03T15:50:43","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/04\/03\/europes-cyber-agency-blames-hacking-gangs-for-massive-data-breach-and-leak-techcrunch\/"},"modified":"2026-04-03T15:50:43","modified_gmt":"2026-04-03T15:50:43","slug":"europes-cyber-agency-blames-hacking-gangs-for-massive-data-breach-and-leak-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/04\/03\/europes-cyber-agency-blames-hacking-gangs-for-massive-data-breach-and-leak-techcrunch\/","title":{"rendered":"Europe\u2019s cyber agency blames hacking gangs for massive data breach and leak | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">The European Union\u2019s cybersecurity agency said Thursday that <a href=\"https:\/\/techcrunch.com\/2026\/03\/27\/european-commission-confirms-cyberattack-after-hackers-claim-data-breach\/\" target=\"_blank\" rel=\"noopener\">a recent hack and data breach at the EU\u2019s executive body<\/a> was the work of a cybercriminal group known as TeamPCP.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In a <a href=\"https:\/\/cert.europa.eu\/blog\/european-commission-cloud-breach-trivy-supply-chain\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">new report<\/a>, CERT-EU also reported that the hackers stole around 92 gigabytes of compressed data from a compromised Amazon Web Services (AWS) account used by the bloc\u2019s executive, the European Commission, which included personal data containing names, email addresses, and the contents of emails.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The breach affected the cloud infrastructure of the Commission\u2019s Europa.eu platform, which member states use to host websites and publications of the bloc\u2019s institutions and agencies.<\/p>\n<p class=\"wp-block-paragraph\">CERT-EU wrote that the data of at least 29 other EU entities may be affected, and that dozens of internal European Commission clients could have had data stolen as well.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The stolen data was then posted online by another hacking group, the notorious ShinyHunters.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">While the size of the data breach is itself notable, the hack and subsequent leak of the European Commission\u2019s data by two separate hacking groups highlights a growing trend of cybercriminals working together to extort their victims.<\/p>\n<p class=\"wp-block-paragraph\">CERT-EU said that the breach originated on March 19 when hackers acquired a secret API key associated with the European Commission\u2019s AWS account, following an earlier hack targeting the <a href=\"https:\/\/unit42.paloaltonetworks.com\/teampcp-supply-chain-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">open source security tool Trivy<\/a>. The Commission inadvertently downloaded a copy of the compromised Trivy tool following the project\u2019s recent breach, allowing the hackers to steal its secret API key and use that access to pivot to obtain data stored in the Commission\u2019s AWS account.<\/p>\n<p class=\"wp-block-paragraph\">While the service said it\u2019s still analyzing the data published online, close to 52,000 files contain sent email messages. CERT-EU said the majority of these emails are automated with little to no content, but emails that bounced back with an error \u201cmay contain the original user-submitted content, posing a risk of personal data exposure.\u201d<\/p>\n<p class=\"wp-block-paragraph\">CERT-EU said it is already in contact with affected organizations.\u00a0<\/p>\n<div class=\"article-block block--callout block--right has-green-500-background-color\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\t\tDo you have more information about this breach? Or other cyberattacks? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or <a href=\"https:\/\/techcrunch.com\/2026\/04\/03\/europes-cyber-agency-blames-hacking-gangs-for-massive-data-breach-and-leak\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">email<\/a><a href=\"https:\/\/techcrunch.com\/2026\/04\/03\/europes-cyber-agency-blames-hacking-gangs-for-massive-data-breach-and-leak\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">.<\/a>\t\t<\/div>\n<p class=\"wp-block-paragraph\">A spokesperson for the European Commission told TechCrunch that the body is closed until next week, and would respond to a request for comment then.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">A member of ShinyHunters did not respond to requests for comment.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Besides the Trivy breach, TeamPCP has been linked to ransomware attacks and crypto-mining campaigns, <a href=\"https:\/\/www.aquasec.com\/blog\/trivy-supply-chain-attack-what-you-need-to-know\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">says Aqua Security<\/a>, which develops Trivy. The hackers have more recently been behind a systematic campaign of supply chain attacks compromising other open source security projects, <a href=\"https:\/\/unit42.paloaltonetworks.com\/teampcp-supply-chain-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">according to Palo Alto Networks Unit 42<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">By targeting developers with keys to access sensitive systems, the hackers \u201cthen have the ability to hold compromised organizations for ransom, demanding extortion payments,\u201d Unit 42 wrote.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/04\/03\/europes-cyber-agency-blames-hacking-gangs-for-massive-data-breach-and-leak\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The European Union\u2019s cybersecurity agency said Thursday that a recent hack and data breach at the EU\u2019s executive body was the work of a cybercriminal group known as TeamPCP.\u00a0 In a new report, CERT-EU also reported that the hackers stole around 92 gigabytes of compressed data from a compromised Amazon Web Services (AWS) account used [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":232415,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-232414","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/232414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=232414"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/232414\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/232415"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=232414"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=232414"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=232414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}