Trivy supply chain attack enabled European Commission cloud breach
ID: 7e8b5f74-f54d-59bd-a40c-81b5a4d244a9
STIX ID: report--7e8b5f74-f54d-59bd-a40c-81b5a4d244a9
Feed Name: Help Net Security
CERT-EU confirmed that the ShinyHunters group published roughly 340 GB of data exfiltrated from European Commission cloud infrastructure; the breach (initial access on 2026-03-19, detected 2026-03-24, published 2026-03-28) appears tied to a Trivy supply-chain compromise that enabled attackers to obtain and validate AWS API credentials (using TruffleHog) and access EC AWS accounts. The leaked dataset includes personal data (names, usernames, emails) and ~51,992 outbound email files (~2.22 GB); EC revoked compromised keys and reported no evidence of lateral movement so far, while investigations continue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
