Pandorex
Security

EU Commission Hacked: Attackers Breached AWS Cloud of Europa Websites

Published Pandorex Redaktion·5 min read
—

The European Commission has confirmed that attackers breached its public web infrastructure on March 24, 2026, and exfiltrated data. The affected cloud systems host the Europa websites -- the central portal for policy pages, public information, and EU documents.

What Is Known

The Commission stated in a brief press release: "Initial findings from our ongoing investigation suggest that data was stolen from these websites." The affected EU bodies are being notified. The websites remained online -- there was no visible outage.

What Is Not Known

Critical questions remain open: What type of data was stolen? How large was the scope? How long did the attackers have access? Who is responsible? How was initial access achieved? The Commission has not answered any of these questions so far.

According to BleepingComputer, reports suggest that a threat actor may have gained access to the Commission's AWS cloud account.

Assessment

For an institution that regularly demands transparency in data breaches, its own communication is remarkably thin. The irony is not lost: The EU Commission is co-author of the GDPR, which addresses exactly such breaches with notification obligations and transparency requirements.

Sources: EU Commission Press Release IP/26/748, The Register (30.03.2026), BleepingComputer.

Comments

Sign in to write a comment.

Swipe up
Next Article

Context Hub: Andrew Ngs New Service Opens Door for AI Supply Chain Attacks

Security