European Commission breach exposed data of 30 EU entities, CERT-EU says

2026-04-04T08:51:46Z2f2d56468075d901b16f1b3c623ad58b7d23e80f057758a469946bfc221a857a
AGEWHEEZECISA-KEVCisco patchesCrystalX RATEU institutionsHandalaHasbroIran-linkedMaaSNorth Korea-linkedPSK WindRATTeamPCPWhatsAppcloud breachcryptocurrency heistdata exposurefake-appnonce-based drainphishingspywarestealerzero-day

What happened

Multiple high-impact incidents and vulnerabilities were reported: CERT-EU attributes a European Commission cloud compromise to TeamPCP that exposed data from at least 30 EU entities; a sophisticated $285M crypto heist (likely North Korea-linked) used nonce-based pre-signed/delayed transactions to drain funds; Kaspersky uncovered CrystalX RAT marketed as MaaS combining spyware, stealer and RAT capabilities; pro‑Iran Handala claims breach of Israeli defence contractor PSK Wind Technologies; Hasbro is investigating a disruptive cyberattack; phishing campaign UAC-0255 impersonated CERT‑UA to push

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
2f2d56468075d901b16f1b3c623ad58b7d23e80f057758a469946bfc221a857a
Enrichment time
2026-04-04T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · European Commission breach exposed data of 30 EU entities, CERT-EU says · Baitaphish