TeamPCP Hacks European Commission via Poisoned Trivy, Steals 340GB Data
Image: The Record from Recorded Future News

TeamPCP Hacks European Commission via Poisoned Trivy, Steals 340GB Data

03 April, 2026.Technology and Science.8 sources

Key Takeaways

  • CERT-EU attributes breach to TeamPCP; supply-chain attack via poisoned Trivy updates.
  • Affected entities: 29–30 EU bodies; AWS cloud compromised in the breach.
  • Exfiltrated data volume reported between 92 GB and 340 GB.

Supply Chain Attack Breaches EU Cloud

The breach was first detected on March 24 but originated on March 19.

Image from BleepingComputer
BleepingComputerBleepingComputer

Approximately 340 gigabytes of data were exfiltrated, affecting 71 clients of the Europa web hosting service.

The commission's Cybersecurity Operations Center failed to detect the intrusion for five days.

ShinyHunters Leak Stolen Data

The extortion group ShinyHunters published the stolen dataset on their leak site.

This dual attribution is unusual and complicates response efforts.

Image from Clubic
ClubicClubic

At least 52,000 files containing sent email messages were included.

The leak contained personal data including names and email addresses.

Investigation Reveals Attack Techniques

The breach originated from a supply chain compromise of Trivy that was inadvertently downloaded by the Commission.

The attackers used TruffleHog to scan for additional secrets and created new access keys to evade detection.

This cascading failure underscores the complexities of securing modern digital environments.

More on Technology and Science