惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
腾讯CDC
Recent Announcements
Recent Announcements
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Hugging Face - Blog
Hugging Face - Blog
H
Help Net Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
博客园_首页
D
DataBreaches.Net
P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
月光博客
月光博客
Jina AI
Jina AI
Stack Overflow Blog
Stack Overflow Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
Vercel News
Vercel News
WordPress大学
WordPress大学
J
Java Code Geeks
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
U
Unit 42

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty
European Commission admits breach of public web systems
Carly Page Carly Page · 2026-03-30 · via The Register - Security: Cyber-crime

Cyber-crime

European Commission admits attackers broke into public web systems, but says little else

Brussels notifying 'Union entities' whose data may've been snatched in websites breach

The European Commission has admitted that attackers broke into its public-facing web infrastructure and siphoned off data in a bare-bones disclosure that answers the what but ducks most of the how.

The intrusion was spotted on March 24 and hit cloud systems hosting the Commission's Europa websites, the front door for everything from policy pages to public information. Officials say they contained the incident quickly and that the sites stayed online, so there was no obvious outage while someone was poking around the back end.

What that someone actually got is another matter. The Commission says data may have been exfiltrated, but leaves it there. There are no details about what kind of data was taken, how much, or who might be affected. There's also no word on initial access, how long the attackers had access, or who might be responsible.

"Early findings of our ongoing investigation suggest that data have been taken from those websites," the EC said. "The Commission is duly notifying the Union entities who might have been affected by the incident. The Commission's services are still investigating the full impact of the incident."

For an institution that often emphasizes breach transparency, it's a pretty thin statement. The European Commission did not respond to The Register's questions.

While the EC isn't saying much, reports claim a threat actor may have gained access to the Commission's AWS cloud environment and exfiltrated more than 350 GB of data

One line the Commission is keen to stress is that internal systems were not affected, at least based on what it knows so far. If that assessment holds, it suggests reasonable separation between public web services and the core network, limiting how far an attacker could go once inside.

Even so, this is the Commission's second security headache in quick succession. Just last month, Brussels admitted that Commission-issued mobile phones had been compromised, an intrusion that "may have resulted in access to staff names and mobile numbers of some of its staff members."

The EC's barely there statement leans on the usual line about Europe facing constant cyber pressure, with references to NIS2 and other initiatives. That may be true, but it doesn't explain how this one happened – or why there's so little detail about it. ®