The EU’s cybersecurity agency said on Thursday that a recent hack and data leak at the EU was done by a cybercriminal group called TeamPCP.
In a new report, CERT-EU said that hackers exfiltrated about 92 gigabytes of data from an Amazon Web Services (AWS) account linked to the European Commission. This data had personal information like names, email addresses, and email content.
By infosecbulletin
/ Tuesday , September 29 2026
Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
By infosecbulletin
/ Tuesday , September 29 2026
The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
By infosecbulletin
/ Tuesday , September 29 2026
The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
By infosecbulletin
/ Saturday , September 19 2026
Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
By infosecbulletin
/ Friday , September 18 2026
Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and one of three data-hosting zones in the...
Read More
By infosecbulletin
/ Friday , September 18 2026
A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
By infosecbulletin
/ Thursday , September 17 2026
Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
By infosecbulletin
/ Thursday , September 17 2026
GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
By infosecbulletin
/ Tuesday , September 15 2026
CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
By infosecbulletin
/ Tuesday , September 15 2026
Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
The breach hit the cloud system of the Commission’s Europa.eu site. Member states use this site to host websites and publications for the bloc’s institutions and agencies.
CERT-EU said that at least 29 more EU groups might be affected, and many internal European Commission clients could also have data stolen. The stolen data was then posted online by another hacking group, the notorious ShinyHunters.
A ShinyHunters member told TechCrunch in a chat that they exfiltrated some data from TeamPCP, which had stolen it before, and then shared it.
CERT-EU said that the breach started on March 19 when hackers got a secret API key from the European Commission’s AWS account. This happened after a hack on the open-source tool Trivy. The Commission accidentally downloaded a bad version of Trivy after it was breached, which let the hackers steal the API key and access data in the Commission’s AWS account.
While the service said it’s still analyzing the data published online, close to 52,000 files contain sent email messages. CERT-EU said the majority of these emails are automated with little to no content, but emails that bounced back with an error “may contain the original user-submitted content, posing a risk of personal data exposure.”
CERT-EU said it is already in contact with affected organizations.