TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)

2026-04-04T19:23:45Zd854317dee51558eba5cadf7ea8cc34bd4a0f0404dddefedd46e5d138c8ee511
AstraZenecaAxiosCERT-EUCVE-2025-30208DPRKDatabricksEuropean CommissionLiteLLMMandiantMercor AISaaSSportradarTeamPCPViteapplication control bypassattributioncloud breachdata exfiltrationexploit attemptsfilelessmalicious scriptpost-compromise enumerationransomwaresupply chain

What happened

Aggregated SANS ISC feed covering multiple April 2026 posts focused on the TeamPCP supply-chain campaign: CERT‑EU confirmed a European Commission cloud breach; Sportradar and other victims (Mercor AI, Databricks, AstraZeneca) disclosed impacts; Mandiant estimates the campaign affected 1,000+ SaaS environments and documents post‑compromise cloud enumeration and a resumption of LiteLLM releases. Additional reporting notes dual ransomware activity by TeamPCP, narrowing attribution (including DPRK for one Axios compromise), and separate advisories about exploitation attempts against Vite (CVE-2025

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
d854317dee51558eba5cadf7ea8cc34bd4a0f0404dddefedd46e5d138c8ee511
Enrichment time
2026-04-04T19:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.