TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)

2026-04-03T13:23:49Zf8cac8276eebb8fa3acdc249ef73eaad100ea20061caf887bfc2ffa8dacbf3f5
AstraZenecaCERT-EUDatabricksEuropean-CommissionMandiantMercor AISaaSSportradarTeamPCPcloud-breachdata-exfiltrationpost-compromise-enumerationransomwaresecurity-scannersupply-chainthreat-campaign

What happened

SANS ISC feed (Apr 1–3, 2026) reports ongoing TeamPCP supply‑chain campaign (When the Security Scanner Became the Weapon v3.0). CERT‑EU confirmed a breach of a European Commission cloud tenant; Sportradar-related details have emerged; and Mandiant estimates the campaign has impacted 1,000+ SaaS environments. Earlier confirmed and suspected victims include Mercor AI, Databricks (investigating), and AstraZeneca (data released); the campaign has involved post‑compromise cloud enumeration, dual ransomware operations, data exfiltration, and attribution developments (Axios-related attribution noted/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
f8cac8276eebb8fa3acdc249ef73eaad100ea20061caf887bfc2ffa8dacbf3f5
Enrichment time
2026-04-03T13:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd) · Baitaphish