Emmanuel College
Incident posture
Linked entities
- Victim
- Emmanuel College
- Threat actors
- 2 actors
- Sources
- 1 source
Timeline
Summary
The provided articles do not mention Emmanuel College. Instead, they describe a data breach affecting the European Commission’s AWS environment linked to a compromised Trivy API key. The breach involved exfiltration of over 300GB of data, including personal information such as names, email addresses, and usernames from hosted websites. Thus, no details about a different organization’s incident are present in the source material.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On March 19, 2026, an API key used by the Aqua Security Trivy vulnerability scanner was compromised in a supply chain attack carried out by the TeamPCP hacking group. The compromised key was subsequently used by the European Commission, which had unknowingly installed a compromised version of Trivy through normal software update channels. On March 24, attackers leveraged the stolen API key to gain access to an AWS cloud account that formed part of the backend for the Europa.eu hosting service supporting the European Commission and other EU entities. The breach was not publicly disclosed until March 27, when the European Commission warned that its cloud infrastructure hosting Europa.eu resources had been breached.
Once inside the AWS account, the threat actor created and attached a new access key to a user account and conducted reconnaissance of the environment. Using the compromised credentials, they launched TruffleHog to scan for secrets and validate AWS credentials via the Security Token Service. The attackers then exfiltrated approximately 340 gigabytes of uncompressed data from the affected cloud environment, which included personal information such as names, email addresses, and usernames primarily from European Commission websites. Additionally, about 2.22 gigabytes of the stolen data, comprising 51,992 files, consisted of automated notifications and bounce‑back messages that could contain user‑submitted content. The breach affected up to 71 clients of the Europa web hosting service, namely 42 internal European Commission entities and at least 29 other European Union organizations. On March 28, the ShinyHunters extortion group posted the stolen information on its Tor‑based leak site.
Upon learning of the compromise, the European Commission revoked the compromised account’s privileges, deactivated and rotated the exposed credentials, and notified the relevant data protection authorities. The Commission confirmed that the incident did not affect its internal systems and that analysis of the databases linked to the hosted websites was ongoing due to the volume and complexity of the data. No further details about residual impact or ongoing mitigation were provided in the source.
Sources
Sources available to members: 1 source.