TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)
2026-04-05T07:23:44Z•93a799d8ffb389407d6355677ec34f1216e30459c3e2bf903f4067da23da703b
AstraZenecaCERT-EUCVE-2025-30208DPRK-attributionDatabricksLiteLLMMandiantMercor AISaaSSportradarTeamPCPVitecloud-breachdata-exfiltrationransomwaresupply-chainvulnerability-exploit
What happened
SANS ISC Update 006 (Apr 1–3, 2026) on the TeamPCP supply-chain campaign reports CERT-EU confirmation of a European Commission cloud breach and Mandiant estimating the campaign impacted 1,000+ SaaS environments. The update expands on prior disclosures (Mercor AI as a confirmed victim, Wiz post-compromise cloud enumeration, Databricks investigation, dual ransomware operations, AstraZeneca data release), emerging details about Sportradar, DPRK-linked attribution for an Axios compromise, and LiteLLM resumption after a forensic audit. Separately, the feed notes active attempts to exploit exposed V
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 93a799d8ffb389407d6355677ec34f1216e30459c3e2bf903f4067da23da703b
- Enrichment time
- 2026-04-05T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.