Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials

June 25, 2026

The Top 10 Attack Surface Exposures in 2026

June 25, 2026

Operation Endgame Takes Down StealC and Amadey Infostealers

June 25, 2026
Facebook X (Twitter) Instagram
Thursday, June 25
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»European Commission Confirms Cloud Data Breach
Cyber Security

European Commission Confirms Cloud Data Breach

Team-CWDBy Team-CWDMarch 30, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The European Commission has admitted that hackers may have taken data from the cloud infrastructure hosting its Europa.eu platform.

The executive body released a statement on March 27 confirming it had discovered the cyber-attack on March 24 and took “immediate steps” to investigate and contain the breach.

“The commission’s swift response ensured the incident was contained and risk mitigation measures were implemented to protect services and data, without disrupting the availability of the Europa websites,” it continued.

“Early findings of our ongoing investigation suggest that data have been taken from those websites. The commission is duly notifying the Union entities who might have been affected by the incident. The commission’s services are still investigating the full impact of the incident.”

Read more on European Commission-related incidents: European Governments Breached in Zero-Day Attacks Targeting Ivanti.

The commission said that its “internal systems” were not impacted by the attack, and that it will continue to monitor the situation, analyze the incident and use any findings to “further enhance its cybersecurity capabilities.”

According to screenshots posted to X (formerly Twitter), extortion group ShinyHunters claims to have compromised over 350GB of European Commission data, including data dumps of mail servers, databases, confidential documents, contracts, and much more sensitive material.

Separate screenshots allegedly posted by ShinyHunters appear to show the personally identifiable information (PII) of employees.

Security researchers at the International Cyber Digest claimed that the hackers compromised emails, DKIM signing keys, internal admin URLs, and data from content collaboration platform NextCloud and military financing mechanism Athena. A full single sign on (SSO) user directory may also have been taken.

ShinyHunters On the Prowl

ShinyHunters is a prolific hacking group with a string of big-name victims. Its most noteworthy campaign targeted SSO credentials and Salesforce data at Google, Chanel, Pandora, Panera Bread, Match Group and scores of other organizations last year. It followed that up with another campaign earlier this month targeted Experience Cloud websites.

The group specializes in vishing – and in some attacks it impersonates the IT helpdesk in calls to victims, tricking them into entering their credentials into phishing sites spoofed to look like legitimate corporate portals.

It’s unclear how the European Commission was breached although reports suggest its AWS infrastructure was targeted. Unconfirmed chatter on social media suggested EU security agency ENISA may also have been compromised.

Nick Tausek, lead security automation architect at Swimlane, argued that the breach could open the door to identity risk, operational disruption and secondary spear-phishing attacks.

“The attacker claiming they will not extort does not make it less serious, it just changes the playbook,” he added. “A quiet leak can be just as damaging for trust, diplomacy, and ongoing investigations, and it forces defenders into a messy mix of containment, forensics, and communications while the organization is still determining what was breached and what is still exposed.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCritical Citrix NetScaler Vulnerability Exploited in the Wild
Next Article Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
Team-CWD
  • Website

Related Posts

Cyber Security

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage

June 25, 2026
Cyber Security

UK Museums Face Cybersecurity Risks, MPs Warn

June 24, 2026
Cyber Security

Trump Issues Executive Order to Fast-Track Post-Quantum Migration

June 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Beware of Winter Olympics scams and other cyberthreats

February 2, 2026

Why you should never pay to get paid

September 15, 2025

What if your romantic AI chatbot can’t keep a secret?

November 18, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.