{"id":1007,"date":"2026-03-30T12:55:15","date_gmt":"2026-03-30T12:55:15","guid":{"rendered":"https:\/\/www.europesays.com\/europe\/1007\/"},"modified":"2026-03-30T12:55:15","modified_gmt":"2026-03-30T12:55:15","slug":"european-commissions-data-stolen-in-hack-on-aws-account","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/europe\/1007\/","title":{"rendered":"European Commission\u2019s Data Stolen in Hack on AWS Account"},"content":{"rendered":"<p class=\"bloomberg\">The European Commission was hit by a cyberattack that may have resulted in the theft of internal data, months after another incident potentially exposed some staff details.<\/p>\n<p>The European Union\u2019s executive arm experienced a breach on March 24, a spokesman said. The attack struck the commission\u2019s Amazon Web Services account before being detected and blocked. An internal investigation is ongoing to establish the extent of the breach, he said.<\/p>\n<p>\u201cI can confirm that the commission discovered a cyber-attack, which affected part of our cloud infrastructure,\u201d spokesman Thomas Regnier said. \u201cThe commission\u2019s internal systems were not affected by the cyber-attack.\u201d<\/p>\n<p>Government agencies are increasingly under attack by hackers and nation-state bad actors. In the EU, public administration networks have emerged as one of the biggest targets, accounting for 38% of incidents, according to Enisa\u2019s <a href=\"https:\/\/www.enisa.europa.eu\/sites\/default\/files\/2026-01\/ENISA%20Threat%20Landscape%202025_v1.2.pdf\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">annual threat report.<\/a> Hans De Vries, chief cybersecurity and operations officer at the European Union Agency for Cybersecurity, commented on the earlier breach in a panel conversation at the RSA cybersecurity even in San Francisco on Tuesday. \u201cEvery organization has incidents,\u201d he said. \u201cSo do we.\u201d<\/p>\n<p>In January, the commission <a href=\"https:\/\/www.insurancejournal.com\/news\/international\/2026\/02\/09\/857349.htm\" target=\"_blank\" rel=\"noopener nofollow\">detected another incident<\/a> that may have exposed limited staff contact details. At the time the EU said it would review the security of its systems and take additional precautions if needed.<\/p>\n<p>Amazon Web Services said the hack was the result of compromised account credentials, not a breach of Amazon\u2019s systems. \u201cAWS did not experience a security event, and our services operated as designed,\u201d a company spokesperson said in an emailed statement.<\/p>\n<p>The incident was first reported by cybersecurity blog <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/european-commission-investigating-breach-after-amazon-cloud-account-hack\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Bleeping Computer<\/a>, which said that the person responsible for the hack reached out claiming to have stolen more than 350 gigabytes of data.<\/p>\n<p>The attack also follows a security incident affecting a high-ranking commission official. Earlier this month, someone uploaded an intercepted WhatsApp call between the official and a Politico journalist onto YouTube. Both Politico and the commission later said that their devices and networks showed no evidence of being compromised.<\/p>\n<p>Cloud-focused attacks, especially from nation-states, are soaring and artificial intelligence has boosted the speed they move, according to CrowdStrike\u2019s 2026 Global Threat Report released last month. In one of the worst cloud data breaches in recent years, a 2024 attack on Snowflake Inc. exposed the personal information of millions of people, including customers of Ticketmaster LLC, AT&amp;T Inc. and Advance Auto Parts Inc.<\/p>\n<p>About a third of cloud incidents come from account abuse, where the attackers log in using stolen credentials, CrowdStrike found.<\/p>\n<p>Photograph: The European Commission\u2019s headquarters in Brussels; photo credit: Simon Wohlfahrt\/Bloomberg<\/p>\n<p>Copyright 2026 Bloomberg.<\/p>\n<p class=\"tagtag\">\n            Topics<br \/>\n            <a href=\"https:\/\/www.insurancejournal.com\/cyber\/\" class=\"btn btn-sm btn-primary tagtag\" style=\"color: #fff; padding: 2px 8px; text-decoration: none; margin: 0 2px;\" rel=\"nofollow noopener\" target=\"_blank\">Cyber<\/a><br \/>\n            <a href=\"https:\/\/www.insurancejournal.com\/fraud\/\" class=\"btn btn-sm btn-primary tagtag\" style=\"color: #fff; padding: 2px 8px; text-decoration: none; margin: 0 2px;\" rel=\"nofollow noopener\" target=\"_blank\">Fraud<\/a><br \/>\n            <a href=\"https:\/\/www.insurancejournal.com\/location\/europe\/\" class=\"btn btn-sm btn-primary tagtag\" style=\"color: #fff; padding: 2px 8px; text-decoration: none; margin: 0 2px;\" rel=\"nofollow noopener\" target=\"_blank\">Europe<\/a><br \/>\n            <a href=\"https:\/\/www.insurancejournal.com\/company\/amazon\/\" class=\"btn btn-sm btn-primary tagtag\" style=\"color: #fff; padding: 2px 8px; text-decoration: none; margin: 0 2px;\" rel=\"nofollow noopener\" target=\"_blank\">Amazon<\/a>\n                    <\/p>\n<p>            Interested in Cyber?<\/p>\n<p>Get automatic alerts for this topic.<\/p>\n","protected":false},"excerpt":{"rendered":"The European Commission was hit by a cyberattack that may have resulted in the theft of internal data,&hellip;\n","protected":false},"author":2,"featured_media":1008,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[1178,1179,1180,1181,1182,15,1183],"class_list":["post-1007","post","type-post","status-publish","format-standard","has-post-thumbnail","category-europe","tag-amazon-web-services-aws","tag-cyber","tag-cyber-and-supply-chain-risks","tag-cyber-attacks","tag-eu-cyber-defenses","tag-european","tag-state-sponsored-cyber-attacks"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/europe\/wp-json\/wp\/v2\/posts\/1007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/europe\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/europe\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/europe\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/europe\/wp-json\/wp\/v2\/comments?post=1007"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/europe\/wp-json\/wp\/v2\/posts\/1007\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/europe\/wp-json\/wp\/v2\/media\/1008"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/europe\/wp-json\/wp\/v2\/media?parent=1007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/europe\/wp-json\/wp\/v2\/categories?post=1007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/europe\/wp-json\/wp\/v2\/tags?post=1007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}