TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)
2026-04-05T01:23:46Z•f79f4f320a290d68c05db9201521f1fbfbcdf9fc542e9b67bf92e5294ceb6a68
AstraZenecaAxiosCERT-EUCVE-2025-30208DPRKDatabricksEuropean CommissionLiteLLMMandiantMercor AISaaS compromiseSportradarTeamPCPViteWizcloud breachexploit attemptspost-compromise enumerationransomwaresupply-chain
What happened
SANS ISC update (Apr 1–3, 2026) on the TeamPCP supply‑chain campaign: CERT‑EU confirmed a breach of a European Commission cloud environment; Sportradar disclosure details emerged; Mandiant estimates the campaign has impacted 1,000+ SaaS environments. Additional reported developments across updates include the first confirmed victim (Mercor AI), Wiz documented post‑compromise cloud enumeration, DPRK attribution narrowing for the Axios compromise, LiteLLM release resumption after forensic review, Databricks investigating an alleged compromise, dual ransomware operations, and an AstraZeneca data
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- f79f4f320a290d68c05db9201521f1fbfbcdf9fc542e9b67bf92e5294ceb6a68
- Enrichment time
- 2026-04-05T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.