The European Commission, headquartered in Brussels, has confirmed that hackers breached cloud infrastructure hosting part of its Europa.eu web platform, marking the second confirmed breach of Commission systems in 2026 after an earlier incident in February exposed potential personal information belonging to staff. The extortion group ShinyHunters claimed responsibility, saying it had taken more than 350GB of data including mail servers, databases, confidential documents and contracts.

The Commission said in a statement that "data have been taken from those websites" and that it was "duly notifying the Union entities who might have been affected," while stressing that the breach did not disrupt public-facing websites and that internal Commission systems were not compromised. Amazon Web Services, which hosts the affected infrastructure, confirmed it "did not experience a security event," pointing instead to a compromised account or misconfiguration on the Commission side rather than a vulnerability in the AWS platform itself.

The breach places Brussels' central administrative apparatus in an uncomfortable position: the city that houses the EU's chief AI and data regulator is now fielding questions about its own cybersecurity practices twice in a single year, at a moment when it is simultaneously asking companies across the bloc to meet stricter data-protection and risk-management standards under EU law.

AdvertisementIn-Article