Eu commission investigates massive data leak following cloud cyberattack
The European Commission is probing a massive data breach resulting from a recent cloud-based cyberattack.

Over 350gb of sensitive information reportedly stolen.
Authorities detected the intrusion on March 24 and swiftly implemented measures to contain the malicious activity. These included deploying risk mitigation strategies to safeguard services and data without disrupting website availability on the EU's platform.
Initial findings suggest the attackers exploited the Commission's cloud infrastructure, which hosts its online presence via the Europa.eu portal, to pilfer sensitive data from various EU websites. These sites serve as entry points to numerous user services.
The Commission has notified relevant stakeholders potentially impacted by the incident, with incident response teams continuing to investigate the full scope of the breach.
The perpetrator claims to have stolen over 350GB of data, including multiple databases, and has shared screenshots showing employee information and a company email server as proof of unauthorized access.
The threat actor plans to leak the stolen data online and has no intention of extorting the Commission for its return.
Although internal systems remained unaffected, the Commission vows to closely monitor the situation and take necessary steps to ensure the security of its internal systems and data. The attack will also inform efforts to bolster the EU's cybersecurity resilience, referencing initiatives like the Cybersecurity Regulation, NIS2 Directive, and Solidarity Law.
