CERT-EU ties Europa.eu breach to Trivy supply chain attack

CERT-EU says the Europa.eu data theft began with the recent compromise of Aqua Security's Trivy vulnerability scanner. The incident exposed European Commission web data and raises the risk of follow-on extortion.

CERT-EU has linked the theft of data from the Europa.eu platform to the recent supply chain attack on Aqua Security’s Trivy open-source vulnerability scanner. The attack on the AWS cloud infrastructure hosting the Europa.eu web hub on March 24 resulted in the theft of 350 GB of data (91.7 GB compressed), including personal names, email addresses, and messages, according to CERT-EU’s analysis.

The compromise of Trivy allowed attackers to access an AWS API key, giving them entry to European Commission web data tied to 42 internal clients of the European Commission, and at least 29 other Union entities using the service. CERT-EU said the threat actor used the compromised AWS secret to create and attach a new access key to an existing user to evade detection, then carried out reconnaissance activities. It found no evidence that the attackers had moved laterally to other AWS accounts belonging to the Commission. CERT-EU assessed with high confidence that the initial access vector was the Trivy supply-chain compromise, publicly attributed to TeamPCP by Aqua Security. The stolen data later became public after TeamPCP leaked it to the ShinyHunters extortion group, which published it on the dark web on March 28.

The Trivy compromise dates to February, when TeamPCP exploited a misconfiguration in Trivy’s GitHub Actions environment, now identified as CVE-2026-33634, to gain a foothold through a privileged access token, according to Aqua Security. Aqua Security rotated credentials, but some remained valid during the process, allowing the attackers to steal the newly rotated credentials. By manipulating trusted Trivy version tags, TeamPCP caused CI/CD pipelines using the tool to automatically download credential-stealing malware. Security researchers at Palo Alto Networks said this gave the attackers access to AWS, GCP, Azure cloud credentials, Kubernetes tokens, Docker registry credentials, database passwords, TLS private keys, SSH keys, and cryptocurrency wallet files.

CERT-EU urged affected organizations to update immediately to a known safe version, rotate AWS and other credentials, audit Trivy versions in CI/CD pipelines, and ensure GitHub Actions are pinned to immutable SHA-1 hashes rather than mutable tags. It also advised looking for indicators of compromise such as unusual Cloudflare tunnelling activity or traffic spikes that could signal data exfiltration. The compromise of Trivy is estimated to have affected at least 1,000 SaaS environments, with other reported victims including Cisco, Checkmarx, and Artificial Intelligence gateway company LiteLLM. CERT-EU warned the handoff of stolen data to a major ransomware group could lead to a wave of extortion demands in the coming weeks.

71

Impact Score

Simple Artificial Intelligence recommendations for small business growth

Research from the University of Warwick and Nanyang Technological University, Singapore, examines how small and medium sized enterprises can use simpler Artificial Intelligence recommendation systems without large datasets or costly infrastructure. Findings from a field experiment suggest low data approaches can still increase customer engagement and spending.

Quantexa wins HMRC data modernisation contract

Quantexa has secured a £175 million, 10-year contract from HM Revenue & Customs to modernise the tax authority’s data infrastructure and support governed use of Artificial Intelligence across core operations. The deal positions the London-founded company at the centre of a major UK public sector data transformation programme.

EU Artificial Intelligence Act delay gives HR more time to prepare

The European Union has pushed back compliance deadlines for high-risk Artificial Intelligence systems, giving HR teams more time to prepare for rules that still carry broad reach beyond Europe. Experts say the delay should be treated as a chance to strengthen governance, data practices, and cross-functional accountability rather than slow down.

Uk falling behind on Artificial Intelligence adoption

New research indicates the UK is losing ground on Artificial Intelligence adoption as many businesses fail to move beyond early experimentation. More than half remain stuck in the pilot phase, pointing to slow deployment across the market.

OpenAI pauses UK Artificial Intelligence investment plans

OpenAI has paused its role in Stargate UK, a major Artificial Intelligence and infrastructure project tied to a wider £31 billion UK-US investment programme. The decision sharpens concerns about energy costs, regulation, and infrastructure readiness for large-scale tech investment in Britain.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.