Breach tracker

Breach report

CERT-EU ties European Commission cloud breach to Trivy supply-chain compromise

ConfirmedDisclosed Updated European UnionGovernmentBy Vivek Kumar
Records UnknownCause Data theftAttributed / claimed TeamPCP / ShinyHunters
Conceptual illustration: A generic institutional building silhouette behind a cloud server and compromised access-key symbol, with anonymous file fragments. Headline: EU COMMISSION CYBER INCIDENT.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

An AWS key taken through a poisoned Trivy update let an attacker copy about 92 GB of compressed data from the Commission's Europa hosting platform. ShinyHunters later published it.

What happened

On 19 March 2026 the European Commission unknowingly ran a compromised version of Trivy, a widely used open-source security scanner, through normal update channels, according to CERT-EU, the cybersecurity service for EU institutions. The poisoned tool exposed an Amazon Web Services secret key with management rights over other cloud accounts. The attacker ran the TruffleHog secrets scanner, created new access keys on existing accounts and copied data from the environment behind Europa, the Commission's web hosting service.

The Commission's security operations centre raised alerts on 24 March, CERT-EU was notified on 25 March and the Commission disclosed the incident on 27 March. On 28 March the ShinyHunters group published the stolen dataset online.

Confirmed vs. claimed

Confirmed by CERT-EU: about 91.7 GB compressed (roughly 340 GB uncompressed) was taken, including names, usernames, email addresses and at least 51,992 email-related files, most of them automated messages. Up to 71 Europa hosting clients may be affected: 42 internal Commission clients and at least 29 other EU entities. CERT-EU relies on Aqua Security's public attribution of the Trivy compromise to TeamPCP.

Claimed: ShinyHunters said it held mail servers, databases and contracts. A ShinyHunters member told TechCrunch the group obtained data TeamPCP had already stolen; this has not been independently confirmed.

Who is affected

Staff and contacts of the Commission and EU bodies whose websites run on Europa hosting, and people whose details appear in emails or site databases. The Commission began notifying affected clients on 31 March.

What to do

  • Update Trivy to a known-safe version and check pipeline logs from mid-March 2026.
  • Rotate any cloud keys that CI/CD (automated build and deployment) pipelines could read during the compromise window.
  • Keep long-lived cloud keys out of build systems where possible.
  • If you corresponded with an EU body, treat unexpected follow-up emails quoting past messages with care.

Sources