European Institutions Face Cloud Extortion
Coverage from TechRepublic, Safestate, and others

European institutions are facing a series of cyber incidents involving cloud environments, hosted websites, employee data, and public leak threats.
The European Commission confirmed that attackers accessed its AWS environment and exposed data associated with multiple Europa.eu clients, while CERT-EU attributed the intrusion to TeamPCP and linked the stolen credential to a Trivy supply-chain attack. ShinyHunters has separately claimed extensive theft from the Council of Europe, but that allegation remains under investigation and has not been independently verified.
The story now places stronger emphasis on the Commission breach as a broader multi-institution exposure, with a higher affected-client count and a new supply-chain link to a Trivy-stolen AWS credential. It also adds a separate reported intrusion path involving Ivanti Endpoint Manager Mobile vulnerabilities, widening the technical scope beyond cloud credential theft alone.
CERT-EU has now attributed the Commission breach more specifically to TeamPCP and tied it to a stolen management-level API key from a Trivy supply-chain attack, sharpening the technical understanding of how the intrusion occurred. The scope was also clarified upward, with tens of thousands of files confirmed exfiltrated and the Council of Europe claim still remaining unverified.
