TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)
2026-04-04T01:23:48Z•fff56a4044d9683393755c5d97d7c54259eea4c19d323932e44469a227248dd1
AstraZenecaCERT‑EUDatabricksEuropean-CommissionLiteLLMMandiantMercor-AISaaS-compromiseSportradarTeamPCPViteWizattribution-DPRKaxioscloud-breachdata-exfiltrationfileless-malwarepost-compromise-enumerationransomwareregistry-persistencesupply-chainvulnerability-exploitation
What happened
Multiple SANS ISC diary items (Apr 1–3, 2026) describe an active, large-scale supply‑chain campaign dubbed “TeamPCP” that has compromised cloud/SaaS environments and third‑party tooling. CERT‑EU confirms a European Commission cloud breach; Mandiant estimates the campaign affected 1,000+ SaaS environments. Confirmed and reported impacts include Mercor AI (first disclosed victim), Databricks investigating an alleged compromise, AstraZeneca data released, and emerging details from Sportradar. Post‑compromise cloud enumeration and dual ransomware operations are observed; attribution for one Axios
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- fff56a4044d9683393755c5d97d7c54259eea4c19d323932e44469a227248dd1
- Enrichment time
- 2026-04-04T01:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.