TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)

2026-04-05T13:23:48Ze00f8fe6e7a5345eec5e2233eec2b11655d12d1004ff7edc00804fd9c46f6758
CERT-EUEuropean-CommissionMandiantSaaS-compromiseSportradarTeamPCPVitecloud-breachdata-exfiltrationfileless-malwarepost-compromise-enumerationransomwaresupply-chain

What happened

Ongoing TeamPCP supply‑chain campaign (updates through Apr 1–3, 2026) has escalated: CERT‑EU confirmed a breach of a European Commission cloud environment, Sportradar compromise details surfaced, and Mandiant estimates the campaign impacted 1,000+ SaaS environments. Prior and concurrent findings referenced in the updates include confirmed victim disclosures (Mercor AI), Databricks and AstraZeneca incidents, dual ransomware activity, post‑compromise cloud enumeration, DPRK attribution of an Axios compromise, and LiteLLM release/activity. Separately, ISC notes active attempts to exploit Vite (CV

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
e00f8fe6e7a5345eec5e2233eec2b11655d12d1004ff7edc00804fd9c46f6758
Enrichment time
2026-04-05T13:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.