TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)

2026-04-05T07:23:44Z93a799d8ffb389407d6355677ec34f1216e30459c3e2bf903f4067da23da703b
AstraZenecaCERT-EUCVE-2025-30208DPRK-attributionDatabricksLiteLLMMandiantMercor AISaaSSportradarTeamPCPVitecloud-breachdata-exfiltrationransomwaresupply-chainvulnerability-exploit

What happened

SANS ISC Update 006 (Apr 1–3, 2026) on the TeamPCP supply-chain campaign reports CERT-EU confirmation of a European Commission cloud breach and Mandiant estimating the campaign impacted 1,000+ SaaS environments. The update expands on prior disclosures (Mercor AI as a confirmed victim, Wiz post-compromise cloud enumeration, Databricks investigation, dual ransomware operations, AstraZeneca data release), emerging details about Sportradar, DPRK-linked attribution for an Axios compromise, and LiteLLM resumption after a forensic audit. Separately, the feed notes active attempts to exploit exposed V

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
93a799d8ffb389407d6355677ec34f1216e30459c3e2bf903f4067da23da703b
Enrichment time
2026-04-05T07:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd) · Baitaphish