The EU’s cybersecurity agency said on Thursday that a recent hack and data leak at the EU was done by a cybercriminal group called TeamPCP.
In a new report, CERT-EU said that hackers exfiltrated about 92 gigabytes of data from an Amazon Web Services (AWS) account linked to the European Commission. This data had personal information like names, email addresses, and email content.
By infosecbulletin
/ Tuesday , September 8 2026
A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big...
Read More
By infosecbulletin
/ Tuesday , September 8 2026
A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target's WeChat...
Read More
By infosecbulletin
/ Tuesday , September 8 2026
Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
By infosecbulletin
/ Monday , September 7 2026
Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
By infosecbulletin
/ Monday , September 7 2026
Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
By infosecbulletin
/ Monday , September 7 2026
Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
By infosecbulletin
/ Sunday , September 6 2026
CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
By infosecbulletin
/ Saturday , September 5 2026
Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
By infosecbulletin
/ Saturday , September 5 2026
India is making its communication systems safer and stronger by launching 14 local quantum products. These products were made by...
Read More
By infosecbulletin
/ Saturday , September 5 2026
Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices...
Read More
The breach hit the cloud system of the Commission’s Europa.eu site. Member states use this site to host websites and publications for the bloc’s institutions and agencies.
CERT-EU said that at least 29 more EU groups might be affected, and many internal European Commission clients could also have data stolen. The stolen data was then posted online by another hacking group, the notorious ShinyHunters.
A ShinyHunters member told TechCrunch in a chat that they exfiltrated some data from TeamPCP, which had stolen it before, and then shared it.
CERT-EU said that the breach started on March 19 when hackers got a secret API key from the European Commission’s AWS account. This happened after a hack on the open-source tool Trivy. The Commission accidentally downloaded a bad version of Trivy after it was breached, which let the hackers steal the API key and access data in the Commission’s AWS account.
While the service said it’s still analyzing the data published online, close to 52,000 files contain sent email messages. CERT-EU said the majority of these emails are automated with little to no content, but emails that bounced back with an error “may contain the original user-submitted content, posing a risk of personal data exposure.”
CERT-EU said it is already in contact with affected organizations.