30 Mars

ShinyHunters breach the European Commission

The European Commission confirmed today that its cloud infrastructure hosting the Europa.eu platform was breached on March 24, with the ShinyHunters extortion group claiming responsibility and dumping over 350GB of stolen data.

The attack targeted at least one of the Commission’s AWS accounts, hitting the cloud environment that serves websites for the Commission, European Parliament, European Council, and other EU institutions. The Commission says its internal systems were not affected and that no Europa websites went offline, but it admits data was taken.

ShinyHunters has already published more than 90GB of files on its Tor leak site. The stolen material reportedly includes mail server dumps, multiple databases, confidential documents, contracts, a full SSO user directory, DKIM signing keys, AWS configuration snapshots, and internal admin URLs. Screenshots shared by the group show employee data accessed from the compromised environment.

The Commission’s official statement downplays the incident, calling the response “swift” and emphasizing that risk mitigation measures were implemented without disrupting service availability. An investigation is ongoing, and the Commission says it is notifying affected EU bodies.

This is the second confirmed breach at the European Commission in 2026. The first targeted its mobile device management platform in February, exploiting Ivanti EPMM vulnerabilities. That earlier incident may have exposed personal data belonging to some Commission staff, according to CERT-EU.

ShinyHunters has been active since 2020 and has ramped up operations recently. The group relies heavily on social engineering, particularly voice phishing, to steal SSO credentials and access Salesforce environments. Recent victims include Google, Chanel, Canada Goose, Panera Bread, CarGurus, and Infinite Campus. The group’s playbook is straightforward: get in, exfiltrate everything, post an initial sample on the leak site, and pressure the target into paying.

The breach lands at an awkward moment for the EU. Just two weeks ago, the bloc sanctioned companies from China and Iran over cyberattacks targeting member states. The EU has also been pushing its NIS2 Directive and Cyber Solidarity Act as frameworks to harden defenses across member nations. A Politico report from March quotes the EU’s own cyber chief warning that “we are losing massively against hackers” and that current cybersecurity measures remain insufficient.

The irony of the institution driving European cybersecurity regulation getting breached twice in three months is hard to ignore. Whether this prompts a serious internal security overhaul or becomes another entry in a growing list of incidents remains to be seen.

Mots-cles

data breach european commission shinyhunters cybersecurity aws eu