<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cert-eu-attributes-europa-eu-breach-to-trivy-supply-chain-attack-350-gb-stolen-mgrwkz2vn" -->

---
title: CERT-EU attributes Europa.eu breach to Trivy supply...
description: CERT-EU has attributed a breach of the European Commission&#x27;s Europa.eu infrastructure to a supply chain attack on Trivy, Aqua Security&#x27;s open-source...
canonical: https://daily.dev/posts/cert-eu-attributes-europa-eu-breach-to-trivy-supply-chain-attack-350-gb-stolen-mgrwkz2vn
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CERT-EU attributes Europa.eu breach to Trivy supply chain attack, 350 GB stolen | daily.dev
og:description: CERT-EU has attributed a breach of the European Commission&#x27;s Europa.eu infrastructure to a supply chain attack on Trivy, Aqua Security&#x27;s open-source...
og:url: https://daily.dev/posts/cert-eu-attributes-europa-eu-breach-to-trivy-supply-chain-attack-350-gb-stolen-mgrwkz2vn
og:image: https://api.daily.dev/og/posts/mGRwKz2VN.png
og:image:alt: CERT-EU attributes Europa.eu breach to Trivy supply chain attack, 350 GB stolen
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CERT-EU attributes Europa.eu breach to Trivy supply chain attack, 350 GB stolen

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

CERT-EU has attributed a breach of the European Commission's Europa.eu infrastructure to a supply chain attack on Trivy, Aqua Security's open-source vulnerability scanner. Attackers exploited a GitHub Actions misconfiguration (CVE-2026-33634) to inject credential-stealing malware into Trivy's CI/CD pipeline, obtaining AWS API keys that enabled access to cloud-hosted EU websites. The threat group TeamPCP exfiltrated approximately 350 GB of data, with 92 GB leaked publicly via ShinyHunters on the dark web, affecting 42 internal Commission clients and 29 other EU entities. The same campaign has reportedly compromised over 1,000 SaaS environments, with Cisco, Checkmarx, and LiteLLM also confirmed as victims. CERT-EU recommends updating Trivy immediately, rotating exposed credentials, auditing CI/CD configurations, and pinning GitHub Actions to immutable SHA-1 commit hashes.

## Content

The European Commission confirmed on March 24 that attackers breached its public-facing Europa.eu web infrastructure and exfiltrated data from cloud systems. The official disclosure was sparse — no attack vector, no timeline, no description of what was taken. External reporting has since filled in most of those gaps.

## What actually happened

CERT-EU traced the breach to a supply chain attack on Trivy, Aqua Security's open-source vulnerability scanner. Attackers exploited a GitHub Actions misconfiguration (CVE-2026-33634) to inject credential-stealing malware into Trivy's CI/CD pipeline. That gave them AWS API keys and other cloud credentials, which they used to access the AWS infrastructure hosting European Commission websites.

The group behind the intrusion, identified as TeamPCP, stole roughly 350 GB of data from those AWS environments. About 92 GB of that was compressed and leaked publicly on the dark web through the ShinyHunters extortion group. The leaked data reportedly includes personal information and email contents belonging to staff across dozens of EU institutions — 42 internal Commission clients and 29 other EU entities are affected.

Internal Commission systems are said to be unaffected. The breach was limited to the public-facing cloud infrastructure.

## Wider fallout

The Trivy compromise didn't stop at the Commission. CERT-EU says the same attack has hit over 1,000 SaaS environments, with Cisco, Checkmarx, and LiteLLM also confirmed as victims. LiteLLM was apparently compromised in an earlier phase of the same campaign.

This is also the Commission's second security incident in two months — in February, staff mobile phones were compromised in a separate incident.

## What CERT-EU recommends

CERT-EU's guidance is fairly standard for a CI/CD supply chain compromise:

- Update Trivy immediately
- Rotate all credentials that may have been exposed
- Audit CI/CD pipeline configurations
- Pin GitHub Actions to immutable SHA-1 commit hashes rather than mutable version tags

The full scope of the breach is still being assessed.

## Similar posts on daily.dev

- [1K\+ cloud environments infected via Trivy attack](https://daily.dev/posts/1k-cloud-environments-infected-via-trivy-attack-i6q0a8ukt) · The Register · 0 upvotes · 0 comments
- [Sophisticated Supply Chain Attack Targeting Trivy Expands to Checkmarx, LiteLLM](https://daily.dev/posts/sophisticated-supply-chain-attack-targeting-trivy-expands-to-checkmarx-litellm-setw9szuc) · DevOps.com · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#aws](https://daily.dev/tags/aws), [#cicd](https://daily.dev/tags/cicd), [#github-actions](https://daily.dev/tags/github-actions)

[View this post on daily.dev](https://daily.dev/posts/cert-eu-attributes-europa-eu-breach-to-trivy-supply-chain-attack-350-gb-stolen-mgrwkz2vn)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CERT-EU attributes Europa.eu breach to Trivy supply chain attack, 350 GB stolen","url":"https://daily.dev/posts/cert-eu-attributes-europa-eu-breach-to-trivy-supply-chain-attack-350-gb-stolen-mgrwkz2vn","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cert-eu-attributes-europa-eu-breach-to-trivy-supply-chain-attack-350-gb-stolen-mgrwkz2vn"},"datePublished":"2026-04-05T13:57:21.938Z","dateModified":"2026-04-05T13:57:57.477Z","description":"CERT-EU has attributed a breach of the European Commission's Europa.eu infrastructure to a supply chain attack on Trivy, Aqua Security's open-source...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/461e0dba8d7e553cf05ddca93d04da67?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/461e0dba8d7e553cf05ddca93d04da67?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cert-eu-attributes-europa-eu-breach-to-trivy-supply-chain-attack-350-gb-stolen-mgrwkz2vn","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,aws,cicd,github-actions","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"CERT-EU attributes Europa.eu breach to Trivy supply chain attack, 350 GB stolen"}]}
```

