logo

Trivy supply chain attack enabled European Commission cloud breach

ID: 7e8b5f74-f54d-59bd-a40c-81b5a4d244a9

STIX ID: report--7e8b5f74-f54d-59bd-a40c-81b5a4d244a9

Feed Name: Help Net Security

Threat Score
90/100

Date Published: 2026-04-03

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

CERT-EU confirmed that the ShinyHunters group published roughly 340 GB of data exfiltrated from European Commission cloud infrastructure; the breach (initial access on 2026-03-19, detected 2026-03-24, published 2026-03-28) appears tied to a Trivy supply-chain compromise that enabled attackers to obtain and validate AWS API credentials (using TruffleHog) and access EC AWS accounts. The leaked dataset includes personal data (names, usernames, emails) and ~51,992 outbound email files (~2.22 GB); EC revoked compromised keys and reported no evidence of lateral movement so far, while investigations continue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.