TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)
2026-04-06T01:23:50Z•9058edf5d862dc3c570bae235c8baa982fa5580c112e45667a4141657da71056
AstraZenecaCERT-EUCVE-2025-30208DatabricksEuropean CommissionLiteLLMMandiantMercor AISaaS-compromiseSportradarTeamPCPViteWizapplication-control-bypasscloud-breachdata-exfiltrationfileless-malwarepost-compromise-cloud-enumerationransomwaresupply-chain
What happened
Multiple ISC SANS diary entries detail an ongoing TeamPCP supply-chain campaign that has escalated: CERT-EU confirmed a European Commission cloud breach, Sportradar-related details emerged, and Mandiant estimates the campaign has impacted 1,000+ SaaS environments. Prior and related disclosures include the first confirmed victim (Mercor AI), Databricks and AstraZeneca incidents, dual ransomware activity, post-compromise cloud enumeration (Wiz), and resumed LiteLLM releases after Mandiant's audit. Separate advisories note exploitation attempts against exposed Vite installations (CVE-2025-30208);
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 9058edf5d862dc3c570bae235c8baa982fa5580c112e45667a4141657da71056
- Enrichment time
- 2026-04-06T01:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.