TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)
2026-04-04T13:23:46Z•28d1c191e648d3a323b994c70c6f87f08d94810faf627fbf78875cb2c6d800ae
CERT-EUCVE-2025-30208MandiantSaaSSportradarTeamPCPVitecloud-breachdata-exfiltrationransomwaresoftware-supply-chainsupply-chain
What happened
SANS ISC diary update covering April 1–3, 2026 summarizes ongoing TeamPCP supply-chain campaign (“When the Security Scanner Became the Weapon” v3.0). CERT‑EU confirmed a cloud breach affecting the European Commission, Mandiant estimates the campaign has impacted 1,000+ SaaS environments, and additional victim/details (Sportradar, Mercor AI, Databricks, AstraZeneca) and monetization/ransomware activity were reported. Related developments include DPRK attribution narrowing for an Axios compromise, LiteLLM release activity, and separate technical advisories such as active attempts to exploit Vite
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 28d1c191e648d3a323b994c70c6f87f08d94810faf627fbf78875cb2c6d800ae
- Enrichment time
- 2026-04-04T13:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.