Black Week: EU Commission Hacked, Romania Under Siege, Russian Hackers Return to Old Targets
The first week of April 2026 will be remembered as an inflection point in European cybersecurity. Three apparently distinct events — the compromise of the European Commission cloud by the TeamPCP group, the Romanian Defense Minister's declaration of 10,000 daily cyber attacks, and CERT-UA's alarm about APT28 and Void Blizzard systematically returning to previously compromised Ukrainian networks — converge into a picture that no longer admits fragmented readings. Europe is the battlefield of a multi-vector hybrid war in which state actors (Russia, China, Iran, North Korea), proxy groups, and opportunistic cybercriminals operate in an unprecedented operational convergence.
1. The European Commission Breached: The TeamPCP Operation
On March 10, 2026, a threat actor identified as TeamPCP exploited a stolen AWS API key — obtained through a supply-chain attack on the Trivy platform — to penetrate the European Commission's Amazon cloud environment. The intrusion remained undetected for 14 days: the Cybersecurity Operations Center identified the anomaly only on March 24, notifying CERT-EU the following day. On March 27, the Commission publicly disclosed the breach. On March 28, the ShinyHunters group published the stolen dataset on the dark web.
The impact is massive: 42 internal European Commission clients and at least 29 other Union organizations using the europa.eu hosting service were affected. CERT-EU confirmed the exposure of 51,992 files (2.22 GB) related to email communications, containing names, email addresses, usernames, and outbound communication content. The complete archive published on the dark web amounts to 90 GB compressed, approximately 340 GB uncompressed.
The TeamPCP attack chain is a textbook supply-chain compromise: stolen API key via Trivy → access to Commission AWS environment → TruffleHog deployment for additional cloud credential scanning → new access key creation on existing user account for evasion → massive exfiltration. The 14-day detection gap is particularly critical: in a two-week window, the attacker had complete access to the cloud data of a cornerstone EU institution.
TeamPCP is not an unknown actor. CERT-EU has linked it to previous supply-chain attacks on GitHub, PyPI, NPM, and Docker, and to the distribution of the "TeamPCP Cloud Stealer" malware through the LiteLLM PyPI package, which compromised tens of thousands of devices. The group represents the most dangerous evolution of the current threat landscape: actors that strike the software supply chain to access high-value government targets. The Commission confirmed that no websites were compromised, no tampering was detected, and no lateral movement to other AWS accounts was identified, but analysis of exfiltrated databases is still ongoing.
2. Romania: 10,000 Attacks Per Day and Hybrid War at NATO's Borders
On April 1, 2026, Romanian Defense Minister Radu Miruta publicly declared that Romania faces more than 10,000 cyber attacks per day against its institutions. Dan Cîmpean, director of Romania's National Cybersecurity Directorate, described the attacks as "systematic, well-prepared" and highlighted how they "often coincide with political decisions or social developments in Romania, particularly those linked to support for Ukraine."
Attribution is explicit: Russian-speaking groups, including the Qilin and Gentlemen ransomware collectives, with suspected ties to Moscow. Targets include the national water agency (hit by ransomware), energy providers, government institutions, and critical infrastructure. But cyber attacks are just one component of a broader hybrid operation that includes disinformation campaigns aimed at eroding institutional trust and influencing Romanian public opinion on the Ukraine question.
There are many institutions that can be attacked, and we see more than 10,000 such attacks every day. The attacks are systematic, well-prepared, and often coincide with political decisions linked to support for Ukraine.
— Dan Cîmpean, Romania National Cybersecurity Director — April 2026
Romania represents a paradigmatic case for the entire NATO alliance. Its geographic position on the eastern borders of the Union, its role as a logistics hub for Ukraine support, and the presence of allied military bases make it a priority target for Russian hybrid operations. The volume of 10,000 daily attacks — if confirmed — far exceeds European averages and suggests a level of dedicated targeting comparable to that suffered by Estonia in 2007 and Ukraine since 2022, but on a sustained scale over time.
3. The CERT-UA Alarm: APT28 and Void Blizzard Return to Breached Networks
On April 3, 2026, CERT-UA issued a warning that should concern every security officer in Europe: Russian groups APT28 (Fancy Bear) and Void Blizzard are systematically revisiting previously compromised networks to verify whether access is still active, whether vulnerabilities have been patched, and whether stolen credentials remain valid. These are not new attacks: this is industrial-scale reconnaissance of past compromises.
CERT-UA documented a significant evolution in initial access tactics: traditional phishing is giving way to sophisticated social engineering. Operators use Ukrainian phone numbers, legitimate messaging accounts, and speak fluent Ukrainian with detailed knowledge of targets. They build trust through phone calls and video chats before sending malicious files. This evolution indicates a level of HUMINT (Human Intelligence) operational investment integrated with cyber capabilities — a qualitative leap from the mass phishing campaigns of previous years.
The shift documented by CERT-UA — from "steal-and-go" mode in H1 2025 to long-term persistent access in H2 — indicates a strategic change by APT28 and Void Blizzard. They are no longer seeking data to steal immediately: they are pre-positioning for future operations. As CERT-UA itself admitted: "Unfortunately, these attempts sometimes succeed when the root cause of the initial incident has not been completely eliminated."
One positive data point emerges from the analysis: overall cyber incidents in Ukraine declined in H2 2025 compared to H1 — the first decrease since the full-scale invasion began. This suggests that Ukrainian organizational defenses are improving. But the return to old targets by APT28 indicates Russia is changing strategy: instead of seeking new victims, it exploits previous compromises where remediation was incomplete.
4. The Parallel Front: North Korea and Iran in the Same Week
While Europe faces the Russian threat, the same week saw two additional high-profile operations by other state actors. On April 1, North Korean actors stole $280 million from the DeFi platform Drift Protocol through a sophisticated attack that enabled takeover of the platform's administrative Security Council. Elliptic confirmed DPRK attribution based on on-chain indicators, laundering methodologies, and network-level indicators. This is the eighteenth attack attributed to North Korea in 2026, bringing the annual total to over $300 million — funds that directly finance Pyongyang's nuclear and missile program.
Simultaneously, on March 11, the Iranian group Handala — linked to Iran's Ministry of Intelligence and Security (MOIS) — conducted a destructive attack against Stryker Corporation, a $22.6 billion medtech giant with over 53,000 employees. The attack wiped approximately 80,000 devices and the attackers claimed to have exfiltrated 50 terabytes of data before destruction. Stryker took three weeks to restore full operations. CISA and Microsoft released specific hardening guidance in response, and the FBI seized two Handala data leak websites.
The Handala attack on Stryker represents a direct threat to the European healthcare sector. Stryker supplies medical devices and surgical technologies to hospitals across the continent. A wiper attack that erases 80,000 devices of a global medical supplier is not an IT incident: it is a potential public health risk. The convergence of state-sponsored hacktivism and healthcare sector targeting is the most alarming trend of 2026.
5. The Converging Picture: A Multi-Vector Hybrid War
The week of March 28 - April 3, 2026, is not a series of coincidences. It is the operational expression of a threat landscape that has reached a new level of complexity. Four state actors — Russia, China (through TeamPCP supply-chain connections), Iran, and North Korea — conducted significant operations against European and Western targets within the same time window. The techniques are different but complementary: supply-chain compromise (TeamPCP/EU Commission), volumetric attacks and ransomware (Russia/Romania), persistent reconnaissance (APT28/Void Blizzard in Ukraine), financial theft (DPRK/Drift), and destructive operations (Iran/Handala against Stryker).
This operational convergence does not require formal coordination between actors. As documented by the Google Threat Intelligence Report of February 2026, the cumulative pressure of four state-sponsored offensive cyber programs simultaneously hitting the same ecosystems — critical infrastructure, software supply chains, government institutions, financial sector, healthcare — creates an attack surface that no single sectoral defense can contain. The result is a systemic erosion of trust in European digital infrastructure.
6. Implications for Organizations and Operational Recommendations
Every organization within the EU and NATO is directly exposed to the attack vectors documented this week. The EU Commission compromise through the AWS supply chain has direct implications for any entity using europa.eu cloud services or interfacing with Commission systems. Romania's targeting — another NATO eastern flank member — suggests that any country supporting Ukraine is a legitimate target for Russian hybrid operations. The CERT-UA alert on returning to previously breached networks should push every organization to verify whether past incidents were effectively remediated down to the root cause.
- 1.Immediate software supply chain audit: verify the integrity of all cloud dependencies, API keys with administrative privileges, and packages from public repositories (PyPI, NPM, Docker). The TeamPCP attack demonstrates that a single compromised key can expose an entire institution.
- 2.Review remediation of past incidents: based on the CERT-UA alert, every organization that suffered an incident in the last 24 months must verify whether the root cause was eliminated, credentials were fully rotated, and original access points were cleaned.
- 3.Implement zero-trust architectures for cloud environments: the European Commission's 14-day detection gap is unacceptable. Continuous monitoring of cloud access, privilege segmentation, and behavior-based anomaly detection must be immediate priorities.
- 4.Healthcare sector hardening: the Handala attack on Stryker demonstrates that medical technology suppliers are direct targets. Every hospital must assess exposure to critical suppliers and implement business continuity plans that consider medical supply chain compromise.
- 5.NIS2 compliance preparation: the directive imposes security obligations and incident notification requirements on essential and important service operators. Penalties reach 10 million euros or 2% of global turnover. The time for compliance is now.
- 6.Critical communications encryption: in a persistent threat scenario where state actors conduct surveillance and pre-positioning operations, protecting internal communications with end-to-end encryption and peer-to-peer architectures is not optional: it is an operational necessity.
Conclusion: The New Normal
Europe's black week is not an anomaly. It is the new normal for a continent operating under constant cyber pressure from multiple simultaneous state actors. The European Commission breached, Romania under siege, Ukraine warning about hackers returning to old wounds, North Korea funding its nuclear program with crypto theft, and Iran wiping a medtech giant's infrastructure — all in the same week — is not the perfect storm. It is the weather now, and it will continue to be.
The transition from reactive defense to anticipatory resilience — invoked at the NATO Cyber Champions Summit in Prague in March 2026 — is no longer a long-term strategic objective. It is a daily operational necessity. For every organization, the question is no longer "if" it will be hit, but whether it has the architecture, processes, and awareness to continue operating when — not if — the attack arrives.
This analysis covers events occurring between March 28 and April 3, 2026. Primary sources include: CERT-EU (formal analysis, April 3), Romanian Ministry of Defense (statement, April 1), CERT-UA (report, April 3), The Record by Recorded Future, BleepingComputer, Elliptic (Drift Protocol blockchain analysis), CISA/FBI (post-Stryker guidance). The picture is evolving and further details on the European Commission compromise will emerge from CERT-EU's ongoing analysis.