CERT‑EU Blames TeamPCP for 92 GB EU AWS Breach

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CERT‑EU attributed the European Commission’s AWS data breach to the cybercriminal group TeamPCP, which stole about 92 GB of compressed data including personal identifiers and email contents.
- TeamPCP accessed the Commission’s AWS account on March 19 by exploiting a secret API key obtained after the Commission downloaded a compromised version of the open‑source security tool Trivy.
- ShinyHunters later posted the stolen data online, claiming they had taken some of the files that TeamPCP had previously exfiltrated.
- European Commission may have exposed data of at least 29 other EU entities and dozens of internal clients, with roughly 52 000 email files found, many automated but some containing user‑submitted content.
- Aqua Security linked TeamPCP to prior ransomware and crypto‑mining campaigns.
- Palo Alto Networks Unit 42 noted TeamPCP’s systematic supply‑chain attacks on open‑source security projects.
Why it matters: The breach compromises personal data of EU officials and dozens of agencies, forcing the Commission to notify affected parties and likely prompting tighter controls over cloud and open‑source tool usage, while the public release by ShinyHunters amplifies the privacy risk.



