Skip to main content

Share story

Security Policy

European Commission Confirms Data Breach After ShinyHunters Claims Intrusion

The European Commission has confirmed a data breach after hacking group ShinyHunters claimed responsibility for an intrusion into its systems, according to reporting by SC Media published Monday. ShinyHunters, a prolific threat actor responsible for several high-profile data thefts in recent years, posted claims of access to Commission systems on underground forums. The Commission's confirmation follows earlier reports that the group posted what it described as Commission data for sale. The European Commission is the executive arm of the European Union, overseeing regulatory policy including enforcement of the EU's AI Act, General Data Protection Regulation, and the Digital Markets Act. A breach of Commission systems raises concerns about the potential exposure of policy deliberations, personnel records, and communications with member states and industry. Details of the intrusion's scope, including what categories of data were accessed and how long the threat actor maintained access, were not immediately disclosed. ShinyHunters has a documented history of large-scale credential theft and database exfiltration, including a breach of AT&T that exposed records from approximately 73 million customers and a 2021 intrusion at Ticketmaster affecting 560 million records. The incident adds to a pattern of breaches involving European institutions. The European Central Bank, European Medicines Agency, and European Parliament have all experienced security incidents in recent years, raising questions about baseline cybersecurity standards across EU bodies. No attribution of the intrusion to a specific nation-state actor was made in initial reporting.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from SC Media and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products Capital
Products Capital

Numeral raises $100M for sales tax automation

Numeral raised a $100M Series C led by Insight Partners, FinTech Global reported. Its AI-powered platform automates sales tax compliance workflows in over 90 countries. The financing adds capital to a business serving companies t...

Infrastructure Capital
Infrastructure Capital

PicoJool raises $27.5M for AI data center interconnects

PicoJool raised a $27.5M Series A led by Socratic Partners, SiliconANGLE reported. The startup is developing interconnects for AI data centers based on vertical cavity surface emitting lasers. Former Intel chief executive Pat Gel...

Security Infrastructure
Security Infrastructure

Two unpatched NetScaler flaws reportedly exploited in attacks

Security firm watchTowr says attackers have exploited two previously undisclosed flaws that could allow remote code execution on Citrix NetScaler appliances. The firm said it identified the flaws during forensic investigations and...

Security Policy
Security Policy

CISA sets deadlines for agencies to address four exploited software flaws

CISA has added exploited vulnerabilities affecting WSO2 products, Adobe Commerce, Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities catalog. Federal agencies using the affected products must apply r...

Security
Security

Attackers evade firewall rules to exploit Oracle PeopleSoft flaw

Attackers have renewed widespread exploitation of an Oracle PeopleSoft vulnerability by altering requests to evade web application firewall rules, Google's Mandiant said. The campaign has targeted organizations in several sectors,...

Security Infrastructure
Security Infrastructure

Researchers find personal data exposed in around 16,000 Supabase databases

Security firm UpGuard found around 16,000 databases hosted by Supabase with some personal data exposed to the public web, TechCrunch reports. The accessible information included names, addresses and phone numbers; a smaller number...