The European Commission has allegedly been breached by ShinyHunters, with reported data dumps including content from mail servers.
The European Commission has allegedly been breached by ShinyHunters, with reported data dumps including content from mail servers and internal communications systems.
The cybercrime group added the Commission to its Tor data leak site, claiming the theft of over 350 GB+ of data. Stolen data may include data dumps of mail servers, databases, confidential documents, contracts, and much more sensitive material.
The European Commission has allegedly been breached by ShinyHunters including data dumps of mail servers pic.twitter.com/J8T5H5o1M4
— Dominic Alvieri (@AlvieriD) March 28, 2026

On March 24, the European Commission detected a cyberattack affecting the cloud infrastructure hosting its Europa.eu websites. The incident was quickly contained, with mitigation measures applied and no disruption to website availability. Early findings suggest some data may have been accessed, and potentially affected EU entities are being notified.
“Early findings of our ongoing investigation suggest that data have been taken from those websites. The Commission is duly notifying the Union entities who might have been affected by the incident.” reads the press release published by the European Commission. “The Commission’s services are still investigating the full impact of the incident. “
EXPLORE MORE
‘This is a canonical mess’: Fr. Murray explains why SSPX priests, laity are not excommunicated
Renowned canon lawyer Fr. Gerald Murray explained Friday why a recent document…
US punished Colombia’s outgoing leader for calling Gaza war ‘genocide’ – FM to RT (VIDEO) — RT World News
Washington’s sanctions against Gustavo Petro and its worsening ties with Bogota had…
Endangered Missing Juveile Chase Cobb from the 22nd District
The Philadelphia Police Department is seeking the public’s assistance in locating endangered…
How AI Aids Incident Response: Why Humans Alone Cannot Do IR Efficiently
AI accelerates incident response by correlating alerts and generating reports in minutes,…
YMCA drops ‘gender identity’ pledge after parents group warns about pro-transgender policies
The YMCA has dropped its “gender identity” pledge after a national parents…
Hackers abused Cisco SD-WAN zero-day since 2023 to gain full admin control
Cisco SD-WAN vulnerability CVE-2026-20127 has been exploited since 2023 to gain unauthenticated…
The EU has launched an investigation into the security breach to determine its full impact. However, the Commission pointed out that its internal systems were not affected, limiting the overall impact of the attack.
The Commission said its internal systems were not affected and will continue monitoring the situation while strengthening protections. It will analyze the incident to improve cybersecurity, as the EU faces ongoing cyber and hybrid threats targeting critical services and institutions.
BleepingComputer first reported the incident, claiming that threat actors breached the European Commission’s AWS account, stealing hundreds of gigabytes of data, including databases, and providing screenshots as proof. The exact type of stolen data remains unclear. AWS said it did not suffer a security incident and that its services functioned as expected.
The attack vector is still unknown.
On 30 January, the European Commission detected another cyberattack on its mobile device management system. The organization pointed out that no mobile devices were compromised. The Commission contained and cleaned the system within nine hours.
Attackers may have accessed some staff data, including names and phone numbers, but so far they have not compromised any devices.
The ShinyHunters extortion group has recently targeted major companies, leaking data when ransom demands fail. Victims include Odido, Figure, Canada Goose, and SoundCloud. The group primarily uses social engineering, especially voice phishing, to steal credentials and access SaaS platforms like Salesforce, Okta, and Microsoft 365.
