Emmanuel College
Incident posture
Linked entities
- Victim
- Emmanuel College
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
In February 2026, CERT-EU reported evidence of an intrusion into the European Commission’s IT infrastructure, with potential access to personal information of some staff members.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On March 30, 2026, the European Commission, the executive branch of the European Union, confirmed that it had been targeted in a cyberattack that compromised its cloud infrastructure and resulted in the theft of data. According to a statement issued by the Commission on the Friday preceding the report, the attack affected cloud infrastructure used to host the organization's web presence on the Europa.eu platform, though the Commission's public websites themselves were not disrupted or taken offline. Early findings from the Commission's ongoing investigation indicated that data had been taken from the affected websites, and the Commission stated that it was notifying the Union entities that might have been impacted by the incident. Officials also clarified that the Commission's internal systems were not affected by the cyberattack, suggesting that the intrusion was confined to the externally hosted web infrastructure rather than the core IT environment.
Over the weekend following the Commission's disclosure, a message appeared on the website of the ShinyHunters cyber extortion group claiming responsibility for the breach. The group alleged that more than 350 gigabytes of data had been stolen, including data dumps from mail servers, databases, confidential documents, contracts, and other sensitive material. Reporting from Bleeping Computer indicated, based on information provided by the hackers, that the attackers had targeted the Commission's AWS accounts. AWS subsequently stated that it did not experience a security event and that its services operated as designed, which pointed to the attackers having leveraged either a compromised account or a security misconfiguration to gain access to the Commission's systems, rather than exploiting any vulnerability within AWS products or services themselves.
The Commission's services continued to investigate the full impact of the incident at the time of reporting. This cyberattack represented the second data breach confirmed by the European Commission within 2026. In February of that year, CERT-EU had reported discovering evidence of an intrusion into the Commission's IT infrastructure, in which hackers potentially accessed personal information belonging to some staff members. The recurrence of incidents within the same year highlighted an ongoing pattern of attempted and successful intrusions against the institution's digital infrastructure, with the more recent event being notable for the volume of data claimed to have been exfiltrated by the threat actors. The combination of the official Commission statement, the public claim by ShinyHunters, and the response from AWS regarding its infrastructure provided a multi-source confirmation of the breach and the methods by which the attackers are believed to have gained access to the affected cloud environment.
Sources
Sources available to members: 1 source.