European Commission hit by cyberattack

Hackers stole 92 gigabytes of sensitive data from the EU’s executive body and published it on the dark web, in one of the worst breaches ever to hit a major European institution.

The European Commission confirmed this week that a sophisticated cyberattack breached its cloud infrastructure, exposing data belonging to at least 29 EU entities and leaking it publicly online. The EU’s cybersecurity agency, CERT-EU, attributed the attack to a hacking group known as TeamPCP.

The breach traces back to a supply-chain attack on Trivy, a widely-used open-source security scanning tool. Hackers poisoned Trivy’s update channel, and the Commission unknowingly downloaded the compromised version. This gave attackers access to the Commission’s Amazon Web Services credentials, which they used to extract data from its cloud environment.

The data which is around 340 gigabytes uncompressed was stolen on March 24, and later published on the dark web by ShinyHunters, a notorious extortion group. The exposed files include names, email addresses, and nearly 52,000 email records from the Commission’s Europa.eu platform, used by EU institutions across member states.

The Commission says it has notified CERT-EU the next day, and has since deactivated all compromised access keys. It has also informed the European Data Protection Supervisor as required by law.

About The Author

Leave a Reply

Your email address will not be published. Required fields are marked *