European Commission Confirms Data Breach on Official europa.eu Website

European-Commission-Confirms-Data-Breach-on-Official-europa-eu-Website

Data Breach Confirmed

On March 30, 2026, a data breach was confirmed at the European Commission after its Europa.eu web platform was hacked in a cyberattack attributed to the ShinyHunters extortion gang.

Key Facts About the Breach:

  • The breach involved unauthorized access to at least one Amazon Web Services (AWS) account managed by the Commission.
  • The Commission reported that its internal systems remained unaffected by the attack, but data from the affected websites was stolen.
  • The Commission is currently notifying relevant Union entities who may have been impacted by the incident.
  • ShinyHunters claimed to have stolen over 350 gigabytes of data, including multiple databases, prior to their access being blocked.
  • Screenshots provided by the group demonstrate their ability to access employee data stored within the Commission’s AWS accounts.
  • ShinyHunters has posted an archive of over 90 gigabytes of allegedly stolen files on its dark web leak site, including data dumps of email servers, databases, confidential documents, contracts, and other sensitive materials.
According to the European Commission, “The breach is under investigation, but our services are working to determine the full scope of the damage.”

Recent Attacks by ShinyHunters:

  • Infinite Campus
  • CarGurus
  • Canada Goose
  • Panera Bread
  • Betterment
  • SoundCloud
  • PornHub
  • Match Group

Automated Testing Limitations:

The incident highlights the limitations of current security protocols, with automated testing only covering one of six potential surfaces. This emphasizes the need for teams to evaluate the effectiveness of their controls and consider diagnostic questions when assessing tools.

Importance of Robust Cybersecurity Measures:

The breach serves as a reminder of the importance of robust cybersecurity measures and the need for continuous vigilance in protecting against threats from malicious actors. The European Commission has emphasized its commitment to enhancing its cybersecurity capabilities and ensuring the security of its internal systems and data.



About Author

en_USEnglish