Skip to main content

Company intelligence

Europa cybersecurity incidents and threat signals

europa.eu

Europa logo

This company page brings together public reporting currently associated with Europa. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

3

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

1

High or critical

confidence classifications

July 22, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Europa. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Europa

Europa logoUse of stolen credentials or exploit
Medium

European Commission cloud hack exposes data of 30 EU entities

The European Commission's cloud environment was hacked by the TeamPCP threat group, exposing data from at least 29 other EU entities. The breach, which took place on March 19 and was discovered on March 24, involved the theft of approximately 340 GB of data, including names, email addresses, email content, usernames, and personal information. The incident was part of the Trivy supply chain attack.

Europa
Europa logoMisconfiguration or publishing error
High

European Commission's AWS Account Breached by ShinyHunters, Data Stolen

European Commission cloud breach: a supply-chain compromise In the interest of transparency, and in full agreement with the European Commission, CERT-EU is publishing this blog post to inform the wider community about a cybersecurity incident affecting the European Commission’s public website platform “europa.eu” hosted on Amazon Web Services (AWS) cloud infrastructure. CERT-EU was notified of this incident on 25 March 2026 by the European Commission, in accordance with Article 21 of Regulation (EU, Euratom) 2023/2841 (the “Cybersecurity Regulation”), which requires the Union institutions, bodies, offices and agencies (Union entities) to report significant incidents to CERT-EU without undue delay. CERT-EU has been providing support in accordance with Article 22 of the same Regulation. On March 27, the European Commission publicly disclosed the incident through a press release . On March 24, the European Commission’s Cybersecurity Operations Centre received alerts about potential misuse of Amazon APIs, potential account compromise, and an abnormal increase in network traffic. On March 25, CERT-EU was informed. We assess with high confidence that initial access was obtained through the Trivy supply-chain compromise, which was publicly attributed to a threat actor known as TeamPCP. A significant volume of data (about 91.7 GB compressed) was exfiltrated from the compromised AWS account, including personal data such as names, email addresses, and email content. On March 28, the data extortion group ShinyHunters made the stolen data publicly available on their dark web leak site. The compromised account is part of the technical infrastructure that drives multiple websites of the European Commission. Data pertaining to at least 29 other Union entities may be affected. We assess that the rise in supply-chain compromises poses a significant threat. We strongly encourage all organisations to implement the recommendations in this post. On March 25, CERT-EU received a notification from the European Commission that one of their AWS cloud accounts had been compromised. The first alerts, indicating potential misuse of Amazon APIs, potential account compromise, and an unusual volume of network traffic, had been detected by their Cybersecurity Operations Centre (CSOC) team the previous day. An investigation uncovered that a malicious actor acquired an Amazon Web Services (AWS) secret (an API key) on March 19 through the Trivy supply chain compromise. This key granted control over other AWS accounts affiliated with the European Commission. On the same day, the threat actor attempted to discover additional secrets by launching TruffleHog, a tool commonly used for scanning secrets and validating AWS credentials by calling the Security Token Service (STS). STS is an AWS service that generates short-lived security credentials for accessing AWS resources and verifying identities. The threat actor used the compromised AWS secret to create and attach a new access key to an existing user, aiming to evade detection. They then carried out reconnaissance activities. The European Commission swiftly revoked the compromised account’s rights to block any illegitimate access. All compromised access keys have been deactivated or deleted. The European Commission and CERT-EU have assessed with high confidence that the initial access vector was the Trivy supply-chain compromise, publicly attributed to TeamPCP by Aqua Security. The firm has provided comprehensive details on this compromise in its advisory . This assessment is based on three main factors: The timing of the Trivy supply-chain compromise coincides with the observed initial compromise on March 19. The specific resources being targeted: AWS credentials and cloud infrastructure. The European Commission was unwittingly using a compromised version of Trivy during the relevant timeframe, having received it through normal software update channels. According to Aqua Security, TeamPCP's tooling is designed to operate within CI/CD pipelines and exfiltrates harvested secrets via multiple channels, including typosquatted domains, GitHub repositories, and Cloudflare tunnels. The threat actor used the compromised AWS secret to exfiltrate data from the affected cloud environment. The exfiltrated data relates to websites hosted for up to 71 clients of the Europa web hosting service: 42 internal clients of the European Commission, and at least 29 other Union entities. On March 28, the data extortion group ShinyHunters published the exfiltrated dataset on their dark web leak site, claiming to have stolen “data dumps of mail servers, datavases [sic], confidential documents, contracts, and much more sensitive material”. The published dataset was approximately 91.7 GB compressed (340 GB uncompressed). Analysis of the published dataset has so far confirmed the presence of personal data, including lists of names, last names, usernames, and email addresses, predominantly from the European Commission’s websites but potentially pertaining to users across multiple Union entities.

Europa
Europa logo
Medium

European Commission's Mobile Device Management System Cyberattack

The European Commission's central infrastructure managing mobile devices identified traces of a cyberattack on January 30, 2026. The swift response ensured the incident was contained and the system cleaned within nine hours. While no mobile devices were compromised, hackers might have accessed personal information pertaining to some staff members, such as names and phone numbers. The Commission is conducting a thorough review to improve cybersecurity capabilities.

Europa

FAQ

Questions about Europa cybersecurity reporting

What does the Europa page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Europa.

Does every mention of Europa appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.