Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationdata-exfiltration-methodgovernment-diplomatic-threatcloud-misconfiguration

European Commission Probes Breach of Amazon Cloud Environment

Updated 2mo agoFirst seen Mar 27, 202633 sources

The European Commission is investigating a breach after a threat actor gained unauthorized access to its Amazon cloud infrastructure and at least one account used to manage that environment. According to reports, the intrusion was detected quickly by the Commission’s cybersecurity incident response team, but the actor claims to have exfiltrated more than 350 GB of data, including multiple databases. Screenshots shared with reporters allegedly show access to European Commission employee information and an email server used by staff.

The actor reportedly said they do not intend to extort the Commission and instead plan to leak the stolen data later. The incident adds to a recent string of security problems at European institutions: the Commission had already disclosed a separate breach tied to a compromised mobile device management platform, apparently linked to exploitation of Ivanti Endpoint Manager Mobile code-injection vulnerabilities that affected other organizations in the region as well.

Share:
European Commission Probes Breach of Amazon Cloud Environment
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Apr 3, 20263mo ago

CERT-EU attributes Commission AWS breach to TeamPCP

CERT-EU said the European Commission's AWS cloud breach was carried out by TeamPCP, which used a compromised AWS API key stolen in the Trivy supply-chain attack to access the environment on March 10. CERT-EU also said the incident potentially exposed data from 42 internal Commission clients and at least 29 other EU entities using the europa.eu hosting service.

CERT-EU: European Commission hack exposes data of 30 EU entities
Mar 30, 20263mo ago

ShinyHunters posts European Commission data on leak site

After claiming the Europa.eu breach, ShinyHunters added the European Commission to its leak site and released an archive of more than 90 GB of allegedly stolen files. The group said the material included mail server dumps, databases, confidential documents, and contracts.

European Commission confirms data breach after Europa.eu hack
Mar 28, 20263mo ago

European Commission says website data may have been taken

The European Commission said early findings from its investigation indicate some data may have been exfiltrated from the cloud infrastructure hosting Europa.eu websites. It also said potentially affected EU entities are being notified while the investigation continues.

ShinyHunters claims the hack of the European Commission
Mar 27, 20263mo ago

European Commission confirms cloud cyberattack affecting Europa web platform

The European Commission publicly confirmed a cyberattack affecting part of its cloud infrastructure, specifically systems hosting its Europa.eu web presence. It said internal systems were not affected, that containment and risk mitigation measures were taken immediately, and that the investigation was ongoing.

European Commission confirms cyberattack after hackers claim data breach | TechCrunch

European Commission launches investigation into Amazon cloud breach

The European Commission's cybersecurity incident response team detected the Amazon cloud intrusion quickly and began investigating the breach. The threat actor said they did not plan to extort the Commission and instead intended to leak the allegedly stolen data later.

Threat actor gains access to European Commission Amazon cloud environment

A threat actor obtained unauthorized access to the European Commission's Amazon cloud infrastructure and at least one account used to manage that environment. The actor later claimed to have stolen more than 350 GB of data, including databases, employee information, and access to a staff email server.

Mar 24, 20263mo ago

European Commission discovers cyberattack on Europa web platform

The European Commission said it discovered a cyberattack on 24 March affecting the cloud infrastructure hosting its Europa.eu web presence. It took immediate containment and mitigation measures, kept the websites available, and initially found no impact on internal systems.

Commission responds to cyber-attack on its Europa web platform
Feb 1, 20265mo ago

European Commission discloses earlier Ivanti-linked breach

In February, the European Commission disclosed a separate breach tied to the January 30 compromise of its mobile device management platform. Reporting indicated the incident was part of wider exploitation affecting other European institutions.

Jan 30, 20265mo ago

European Commission discovers compromise in mobile device management platform

The European Commission discovered a compromise affecting a mobile device management platform on January 30. This incident was later linked to broader attacks on European institutions exploiting code-injection vulnerabilities in Ivanti Endpoint Manager Mobile.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

66 LINKEDOpen in app
Threat actors
2 linked
Malware
1 linked
Affected products
9 linked
Amazon Web ServicesTrivyNextcloudGithubAws CloudtrailDockerNpmGoogleLitellm
Organizations
54 linked
Amazon Web ServicesAqua SecurityTicketmasterBanco SantanderAstraZenecaAyloBleepingComputerGoogleGitHubSalesforceTikTokXSoundcloudSecurity AffairsCanada GooseOkcupidTinderLinkedinTechCrunchOktaIvantiDockerMicrosoft CorporationMatch.comHingeMeeticMatch GroupPanera BreadBettermentThe RegisterPalo Alto NetworksAT&TSnowflakeCybernewsCloudflareSwimlaneBroadcomVercelWizHackread.comChanelPornhubFuture plcMercorMcGraw-HillSilicon RepublicAllianz LifeOdidoFigureCarGurusTelnyxInfinite CampusEuropa web hosting serviceRituals
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.