TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)
2026-04-05T19:23:46Z•aec9bd3a4b15178f3d25ec9abc1c65b580a513371fdf2cabc9cb97795b7b9543
AxiosCERT-EUCVE-2025-30208DatabricksEuropean-CommissionLiteLLMMandiantMercor-AISaaS-compromiseSportradarTeamPCPVitecloud-breachdata-leakpost-compromise-enumerationransomwaresupply-chain
What happened
Update 006 (Apr 1–3, 2026) on the TeamPCP supply‑chain campaign: CERT‑EU confirmed a cloud breach impacting the European Commission; Sportradar disclosed additional victim details; and Mandiant estimates the campaign has compromised 1,000+ SaaS environments. The campaign continues to weaponize a compromised security scanner to achieve post‑compromise cloud enumeration, monetization (including dual ransomware operations) and data leakage (e.g., AstraZeneca). Prior confirmed victims (e.g., Mercor AI) and investigations (Databricks, Axios attribution narrowing, LiteLLM developments) were noted. A
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- aec9bd3a4b15178f3d25ec9abc1c65b580a513371fdf2cabc9cb97795b7b9543
- Enrichment time
- 2026-04-05T19:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.