TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)

2026-04-04T01:23:48Zfff56a4044d9683393755c5d97d7c54259eea4c19d323932e44469a227248dd1
AstraZenecaCERT‑EUDatabricksEuropean-CommissionLiteLLMMandiantMercor-AISaaS-compromiseSportradarTeamPCPViteWizattribution-DPRKaxioscloud-breachdata-exfiltrationfileless-malwarepost-compromise-enumerationransomwareregistry-persistencesupply-chainvulnerability-exploitation

What happened

Multiple SANS ISC diary items (Apr 1–3, 2026) describe an active, large-scale supply‑chain campaign dubbed “TeamPCP” that has compromised cloud/SaaS environments and third‑party tooling. CERT‑EU confirms a European Commission cloud breach; Mandiant estimates the campaign affected 1,000+ SaaS environments. Confirmed and reported impacts include Mercor AI (first disclosed victim), Databricks investigating an alleged compromise, AstraZeneca data released, and emerging details from Sportradar. Post‑compromise cloud enumeration and dual ransomware operations are observed; attribution for one Axios‍

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
fff56a4044d9683393755c5d97d7c54259eea4c19d323932e44469a227248dd1
Enrichment time
2026-04-04T01:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd) · Baitaphish