Brussels scrambles after 350 gb heist from eu cloud portal
Someone walked out of the European Commission’s cloud with a hard-drive-sized chunk of its web estate, and the attacker is already shopping the loot to the press. The breach, detected on 24 March, hit the Europa.eu portal that funnels citizens to everything from farm-subsidy forms to tender notices. Brussels admits ‘several’ databases were siphoned off; the intruder claims 350 GB and has the mailbox screenshots to back it up.
The entry point is still a black box
Commission spokespeople refuse to say whether the weakness lived in a mis-configured S3 bucket, a hijacked API key, or a supply-chain plug-in. What is clear: the cloud stack that hosts Europa.eu sits physically separate from the Commission’s internal crown-jewel network, so draft legislation and diplomatic cables appear untouched. That separation saved face, but it also means the portal was left to fend for itself with whatever security wrapper the external provider wrapped around it.
The attacker, chatting with BleepingComputer under a fresh Telegram handle, dumped thumbnails of staff LDAP tables and an Exchange server tree. No ransom demand, just a promise to ‘publish it all’ once journalists finish feasting. The Commission’s CERT-EU squad flicked the portal into incident-response mode within hours, yet the data was already long gone, zipped and exfiltrated through what network logs show as legitimate HTTPS traffic.

Union officials play down union fallout
Staff unions were formally notified, but Brussels’ statement stresses that no personal health or banking records were hoovered. Skeptics point out that even ‘only’ CVs, direct phone numbers and internal org-charts are a phisher’s gold mine when the next EU presidency phishing season kicks off. GDPR notifications are trickling out; the clock started ticking at discovery, so enforcement agencies have 72 hours to decide whether the Commission itself becomes the first major EU institution to eat a headline-grabbing fine under its own privacy regime.
Meanwhile, the attacker’s dump timeline is vague. Security teams across EU agencies are now hunting for secondary payloads or backdoors that could let the same actor pivot from brochureware sites into deeper diplomatic systems. Source code repositories tied to the portal have been frozen; penetration testers are replaying every recent pull request, looking for the tell-tale commit that opened the door.

Cloud sovereignty rhetoric meets reality
This is the second time in a year that an EU flagship cloud project has bled data. The last leak, at the European Medicines Agency, ended with regulatory documents circulating on Russian forums. Each bruise feeds the bloc’s narrative that only ‘EU sovereign’ clouds can be trusted, yet the Commission’s own estate still relies on the same hyperscale stacks it lectures member states to abandon. Officials promise a post-mortem will feed into the upcoming Cyber Solidarity Act and NIS2 directive reviews, but the instant takeaway is simpler: 350 GB of Brussels’ digital skin is now in someone else’s game, and the house has not yet found the peephole.
