Hack via Trivy hit the European Commission. Attackers stole data from AWS
The European Commission faced a serious cyber incident in March that, according to CERT-EU analysis, is related to a supply chain compromise of the Trivy tool. With a high degree of certainty, the attack is attributed to the group TeamPCP.

The European Commission faced a serious cyber incident in March that, according to CERT-EU analysis, is related to a supply chain compromise of the Trivy tool. With a high degree of certainty, the attack is attributed to the group TeamPCP.
According to findings, the attackers gained access on 19 March by abusing an AWS API key and subsequently removed approximately 91.7 GB of compressed data from the cloud environment.
Únik zasáhl desítky systémů a tisíce souborů
The compromise affected the infrastructure of the europa.eu platform running on Amazon Web Services, which the European Commission uses to host its own sites and those of other EU institutions.
According to CERT-EU, the incident may affect up to 71 clients of this service. Specifically, this concerns 42 internal Commission systems and at least 29 other EU entities.
The leaked data include personal information such as names, usernames and email addresses. The report also confirms nearly 52,000 files related to outbound email communication totaling approximately 2.2 GB.
Most of these messages were automated, but the main risk comes from bounce-back notifications, which can contain parts of the original communication.
Kompromitace přes aktualizaci. Supply chain jako vstupní bod
The investigation points to a compromised version of the Trivy tool that the European Commission was using during the period via standard updates.
CERT-EU bases the attribution on the timing, the type of abused credentials and the fact that the organization was indeed running the compromised version of the tool. The same incident was previously attributed to TeamPCP by Aqua Security.
This type of attack is crucial – it is not a direct compromise of the organization, but an exploitation of trust in a commonly used tool.
Přístup do cloudu s vyššími oprávněními
According to the report, the attacker obtained so-called management rights to the compromised AWS key. That could theoretically have allowed broader control over the environment and potential movement between other accounts.
CERT-EU also emphasizes, however, that there is currently no evidence that such lateral movement actually occurred.
The incident was detected only on 24 March based on anomalies in operation and suspicion of API abuse. It was handed over to CERT-EU a day later.
Data se objevila na dark webu
Already on 28 March the stolen dataset appeared on the leak sites of the ShinyHunters group.
They claim to have published databases, email servers and confidential documents. CERT-EU links this step to a broader trend of cooperation between cybercriminal groups, where one group obtains the data and another monetizes it.
Další potvrzení trendu: útoky přes CI/CD a cloud
The incident fits into the broader picture of recent months. TeamPCP is also linked to attacks on tools like LiteLLM and, according to security firms, focuses specifically on CI/CD environments, access keys and cloud infrastructure.