European Commission confirms data breach after Europa.eu hack
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户给的文章是关于欧洲委员会的数据泄露事件。首先,我得通读全文,抓住主要信息。 文章提到欧洲委员会的Europa.eu平台被黑客攻击,ShinyHunters勒索团伙声称对此负责。BleepingComputer报道说这次攻击影响了委员会的一个AWS账户。委员会表示攻击没有影响到网站运营,他们采取了措施控制事件,并防止进一步的数据泄露。 调查发现数据被窃取,委员会正在评估影响,并通知可能受影响的机构。内部系统没有受到影响,他们将继续监控并加强安全措施。ShinyHunters在暗网泄露了超过90GB的数据,包括邮件服务器、数据库、合同等敏感信息。 最近几个月,ShinyHunters还攻击了多个知名公司。委员会之前也披露过另一次数据泄露事件。这些事件发生在委员会提出新的网络安全立法之后。 现在我需要把这些信息浓缩到100字以内。要包括被攻击的平台、黑客组织、数据泄露情况、影响和应对措施,以及后续行动。 可能的结构是:欧洲委员会网站被黑,ShinyHunters团伙声称责任,导致350GB数据泄露,包括员工信息和敏感文件。虽然内部系统未受影响,但委员会正在调查并加强安全措施。这是最近一系列攻击中的一起。 检查字数是否符合要求,并确保信息准确全面。 </think> 欧洲委员会的Europa.eu网站遭网络攻击,ShinyHunters勒索团伙声称责任。此次攻击导致至少350GB数据泄露,包括员工信息和敏感文件。尽管内部系统未受影响,但委员会正在调查并采取措施加强安全防护。这是近期多起类似事件之一。 2026-3-30 06:45:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:1 收藏

European Union flags

The European Commission has confirmed a data breach after its Europa.eu web platform was hacked in a cyberattack claimed by the ShinyHunters extortion gang.

BleepingComputer first reported on Friday that this breach affects at least one of the Commission's AWS (Amazon Web Services) accounts.

The Commission says the attack didn't disrupt any Europa websites and that its staff took measures to contain the incident and prevent further data theft.

"Early findings of our ongoing investigation suggest that data have been taken from those websites. The Commission is duly notifying the Union entities who might have been affected by the incident. The Commission's services are still investigating the full impact of the incident," the European Union's main executive body said in a Friday press release published after BleepingComputer reached out for more details on the cyberattack.

"The Commission's internal systems were not affected by the cyber-attack. The Commission will continue to monitor the situation and take all necessary measures to ensure the security of its internal systems and data. It will analyse the incident and use the results to further enhance its cybersecurity capabilities."

While the Commission didn't share further information regarding the attack, the threat actor who claimed responsibility for the breach told BleepingComputer last week that they had stolen over 350 GB of data before their access was blocked, including multiple databases.

Although they didn't disclose how they breached the Commission's Amazon AWS accounts, they provided screenshots proving they had access to some European Commission employees' data.

Data extortion group ShinyHunters has also added an European Commission entry to its dark web leak site, claiming that the theft of "data dumps of mail servers, datavases, confidential documents, contracts, and much more sensitive material," and released an archive of over 90GB of files allegedly stolen from the Commission's compromised cloud environment.

ShinyHunters European Commission data leak
ShinyHunters European Commission data leak (BleepingComputer)

In recent months, ShinyHunters has also claimed breaches at Infinite CampusCarGurusCanada Goose, Panera Bread, Betterment, SoundCloudPornHub, and online dating giant Match Group (which owns multiple popular dating services, including Tinder, Hinge, Meetic, Match.com, and OkCupid).

Some of these victims were breached in a large-scale voice phishing (vishing) campaign that targeted single sign-on (SSO) accounts at Okta, Microsoft, and Google across more than 100 high-profile organizations.

The Commission also disclosed a data breach in February after discovering that the mobile device management platform it uses to manage staff's devices had been hacked.

These security breaches were disclosed after the Commission's proposed new cybersecurity legislation to strengthen member states' defenses against state-backed actors and cybercrime groups targeting their critical infrastructure.

tines

Automated Pentesting Covers Only 1 of 6 Surfaces.

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.


文章来源: https://www.bleepingcomputer.com/news/security/european-commission-confirms-data-breach-after-europaeu-hack/
如有侵权请联系:admin#unsafe.sh