CERT-EU: European Commission hack exposes data of 30 EU entities

2026-04-03T07:23:34Z60c58be56eae860f21187fcf1a03ff1a7c3e3b3ef50ec68db978c77fb26d22a6
CERT-EUCisco IMCClaude Code leakDrift ProtocolEuropean CommissionGitHub supply-chain abuseHandalaIP reputation evasionNorth Korean actorsProgress ShareFileStrykerTeamPCPVidarauthentication bypasscloud hackcryptocurrency theftdata exposuredata-wipinghybrid cybercrimeinfostealermail interceptionpre-auth RCEresidential proxiesunauthenticated exfiltrationwiper

What happened

News roundup: CERT-EU attributes a cloud hack of the European Commission to TeamPCP, exposing data from the Commission and at least 29 other EU entities. Threat actors are abusing the leaked Claude Code on fake GitHub repos to deliver Vidar infostealer. The Drift Protocol lost ~$280M after attackers (linked to North Korea) seized governance powers. Researchers report residential proxy traffic evades IP reputation checks at scale, while adversaries exploit vacant homes as mail drop addresses for hybrid fraud. Two pre-auth vulnerabilities in Progress ShareFile can be chained for unauthenticatedR

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
60c58be56eae860f21187fcf1a03ff1a7c3e3b3ef50ec68db978c77fb26d22a6
Enrichment time
2026-04-03T07:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CERT-EU: European Commission hack exposes data of 30 EU entities · Baitaphish