Compute & Cloud
European Commission data breach linked to supply chain attack
The European Commission suffered a data breach involving around 92 gigabytes of data, with CERT-EU attributing the incident to a supply chain attack via a compromised security tool.
The European Commission has suffered a data breach involving the theft of around 92 gigabytes of compressed data from a compromised Amazon Web Services account. According to CERT-EU (the Computer Emergency Response Team for the European Union institutions), which reported the breach on Thursday, the incident was the work of a cybercriminal group known as TeamPCP. The compromised account belongs to the European Commission, the executive body of the European Union.
The breach originated on March 19 when hackers acquired a secret API key associated with the European Commission’s AWS account. This occurred after the Commission downloaded a compromised version of Trivy, an open-source security tool developed by Aqua Security, following a supply chain attack on that project. CERT-EU reported that the data of at least 29 other EU entities may be affected by the breach. While the agency is still analyzing the compromised files, it found that close to 52,000 files contain sent email messages. Although the majority of these emails are automated, those that bounced back with errors could contain original user-submitted content, posing a risk of personal data exposure, CERT-EU warned.
The stolen data was subsequently posted online by another hacking group, the notorious ShinyHunters. Beyond this incident, TeamPCP has been linked to ransomware attacks and crypto-mining campaigns, according to Aqua Security. According to security research firm Palo Alto Networks Unit 42, the group has recently been behind a systematic campaign of supply chain attacks compromising open-source security projects. By targeting developers with keys to access sensitive systems, the hackers “then have the ability to hold compromised organizations for ransom, demanding extortion payments,” Unit 42 wrote.
Why it matters
The breach of the European Commission’s AWS account, which may affect at least 29 other EU entities, highlights a significant supply chain vulnerability originating from a compromised open-source security tool.