The EU’s AWS “Master Key”: How a Compromised Trivy Update Leaked 340GB of Data
ID: 51f9329e-262c-5045-8c05-6e9bf3de986a
STIX ID: report--51f9329e-262c-5045-8c05-6e9bf3de986a
Feed Name: securityonline.info
In March 2026 a supply‑chain compromise of the Trivy security tool (attributed to TeamPCP) enabled attackers to steal an AWS API key and exfiltrate approximately 91.7 GB compressed (~340 GB raw) of data from the European Commission's public europa.eu platform; the dataset containing emails, databases, contracts and personal data was later published by extortion group ShinyHunters and may affect at least 29 other Union entities. CERT‑EU and the Commission responded by revoking keys, advising credential rotation, securing CI/CD pipelines, and monitoring for anomalous activity, while the community braces for follow‑on phishing and misuse of exposed personal data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
