---
title: "European Commission AWS Cloud Breach 350GB | Firevault"
description: "The European Commission is investigating the theft of over 350GB of data from its Europa.eu cloud infrastructure hosted on AWS. The attacker plans to leak the…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/european-commission-aws-cloud-data-breach-350gb#webpage",
      "url": "https://fire-vault.com/news/european-commission-aws-cloud-data-breach-350gb",
      "name": "European Commission AWS Cloud Breach 350GB",
      "description": "The European Commission is investigating the theft of over 350GB of data from its Europa.eu cloud infrastructure hosted on AWS. The attacker plans to leak the…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/european-commission-aws-cloud-data-breach-350gb.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/european-commission-aws-cloud-data-breach-350gb#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/european-commission-aws-cloud-data-breach-350gb#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "European Commission Breach: 350GB from Cloud",
          "item": "https://fire-vault.com/news/european-commission-aws-cloud-data-breach-350gb"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "European Commission Breach: 350GB from Cloud",
      "description": "The European Commission is investigating the theft of over 350GB of data from its Europa.eu cloud infrastructure hosted on AWS. The attacker plans to leak the data publicly rather than extort the institution, highlighting why sovereign data must be physically disconnected from cloud platforms.",
      "url": "https://fire-vault.com/news/european-commission-aws-cloud-data-breach-350gb",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/european-commission-aws-cloud-data-breach-350gb.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/european-commission-aws-cloud-data-breach-350gb.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/european-commission-aws-cloud-data-breach-350gb.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/european-commission-aws-cloud-data-breach-350gb.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-03-30T19:37:59.197728+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/european-commission-aws-cloud-data-breach-350gb"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 1034,
      "keywords": "European, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Originally reported by Howard Solomon, CSO Online, 27 March 2026 What Happened The European Commission has confirmed a cyber attack on its Europa.eu platform, with an unnamed threat actor claiming to have stolen over 350 gigabytes of data from the institution's cloud infrastructure hosted on Amazon Web Services (AWS). The attack, which came to light on Thursday 27 March 2026, involved the compromi",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What HappenedWhat Data Was ExposedThe IAM ChallengeWhy This MattersThe Offline AlternativeKey TakeawaysMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 30 March 2026 

# European Commission Breach: 350GB from Cloud

The European Commission is investigating the theft of over 350GB of data from its Europa.eu cloud infrastructure hosted on AWS. The attacker plans to leak the data publicly rather than extort the institution, highlighting why sovereign data must be physically disconnected from cloud platforms.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

6 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Feuropean-commission-aws-cloud-data-breach-350gb)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Feuropean-commission-aws-cloud-data-breach-350gb&text=European%20Commission%20Breach%3A%20350GB%20from%20Cloud%0A%0AThe%20European%20Commission%20is%20investigating%20the%20theft%20of%20over%20350GB%20of%20data%20from%20its%20Europa.eu%20cloud%20infrastructure%20hosted%20on%20AWS.%20The%20attacker%20plans%20to%20leak%20the%20data%20publicly%20rather%20than%20extort%20the%20institution%2C%20highlighting%20why%20sovereign%20data%20must%20be%20physically%20disconnected%20from%20cloud%20platforms.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Feuropean-commission-aws-cloud-data-breach-350gb)[](mailto:?subject=European%20Commission%20Breach%3A%20350GB%20from%20Cloud&body=The%20European%20Commission%20is%20investigating%20the%20theft%20of%20over%20350GB%20of%20data%20from%20its%20Europa.eu%20cloud%20infrastructure%20hosted%20on%20AWS.%20The%20attacker%20plans%20to%20leak%20the%20data%20publicly%20rather%20than%20extort%20the%20institution%2C%20highlighting%20why%20sovereign%20data%20must%20be%20physically%20disconnected%20from%20cloud%20platforms.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Feuropean-commission-aws-cloud-data-breach-350gb)

![The European Commission Berlaymont building in Brussels at blue hour with dramatic clouds and warm amber light glowing from windows](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/european-commission-aws-cloud-data-breach-350gb.jpg)

The European Commission Berlaymont building in Brussels at blue hour with dramatic clouds and warm amber light glowing from windows

Why it matters

## What this means for organisations holding critical data

The European Commission is investigating the theft of over 350GB of data from its Europa.eu cloud infrastructure hosted on AWS. The attacker plans to leak the data publicly rather than extort the institution, highlighting why sovereign data must be physically disconnected from cloud platforms.

In this analysis

1.  01 [What Happened](#section-0)
2.  02 [What Data Was Exposed](#section-1)
3.  03 [The IAM Challenge](#section-2)
4.  04 [Why This Matters](#section-3)
5.  05 [The Offline Alternative](#section-4)

**On this page**[What Happened](#section-0)[What Data Was Exposed](#section-1)[The IAM Challenge](#section-2)[Why This Matters](#section-3)[The Offline Alternative](#section-4)

_Originally reported by Howard Solomon, CSO Online, 27 March 2026_

## What Happened

The European Commission has confirmed a cyber attack on its Europa.eu platform, with an unnamed threat actor claiming to have stolen over 350 gigabytes of data from the institution's cloud infrastructure hosted on Amazon Web Services (AWS).

The attack, which came to light on Thursday 27 March 2026, involved the compromise of one or more AWS accounts. The threat actor provided screenshots as evidence to security news site Bleeping Computer and stated they intend to leak the data publicly rather than attempt to extort the Commission.

Amazon responded by stating that "AWS did not experience a security event, and our services operated as designed," placing responsibility on the Commission's own account security and access controls.

The Commission said its Europa websites remain available and that its "swift response ensured the incident was contained and risk mitigation measures were implemented to protect services and data." It added that its internal IT systems were not affected by the attack.

This is not an isolated incident. In January 2026, the Commission revealed that its central mobile device management infrastructure had "identified traces of a cyber attack" which may have exposed the names and mobile numbers of some staff members.

## What Data Was Exposed

The full scope of the compromised data remains unclear. The threat actor claims to have exfiltrated over 350GB from the Commission's cloud infrastructure, though the specific types of data, whether personal records, policy documents, diplomatic communications, or internal correspondence, have not been confirmed.

What is known is that the data resided on cloud infrastructure managed through AWS accounts, meaning it was accessible via standard cloud authentication and access control mechanisms. The Commission has not yet provided a detailed breakdown of the affected data sets.

## The IAM Challenge

The breach has reignited debate about the inherent complexity of identity and access management (IAM) in cloud environments. Security experts point to the difficulty of guaranteeing that only authorised individuals have legitimate access to sensitive infrastructure.

Kellman Meghu, Chief Technology Officer of Canadian incident response firm DeepCove Cybersecurity, highlighted the risks: "This is why I force all my users to use AWS Identity Center sign on. No IAM-generated keys, and admin accounts are only activated through a 'break glass' strategy, where two people are needed to authenticate."

Meghu described storing root and admin account credentials outside of AWS entirely, on a system requiring dual authorisation from both the CEO and CTO via credentials and hardware tokens. Any unauthorised access attempt generates an immediate alert.

"I personally live in constant fear of this sort of thing happening," he said. "I create multiple separate AWS accounts using the AWS Organisations feature so accounts are completely isolated from each other. The reality is, identity access management is hard, and not just in AWS. It is the same challenge with all infrastructure. How do we guarantee the authorised person has legitimate access? It only takes one mistake."

Ilia Kolochenko, CEO of Swiss-based ImmuniWeb, warned that the attackers' intention to release data rather than seek payment points to political motivation. "The attackers behind are either hacktivists or cyber mercenaries hired by a nation state. In view of the geopolitical turbulence around the globe, such attacks will probably surge in 2026."

## Why This Matters

Kolochenko described the incident as "a grim warning that the European regulation of cybersecurity, that some experts perceive as excessive and unnecessarily complicated, is not a panacea against data breaches."

The breach raises several critical questions for any organisation storing sensitive data in cloud infrastructure:

-   **Cloud concentration risk:** When an entire platform depends on a single cloud provider's access controls, a single compromised account can expose everything.
-   **Political motivation:** Attackers who do not seek financial gain are harder to deter and may invest significant resources in persistent, sophisticated campaigns.
-   **Regulatory limitations:** Despite the EU's extensive data protection framework, including GDPR, NIS2, and DORA, regulation alone cannot prevent breaches when the underlying infrastructure remains network-connected and accessible via identity credentials.
-   **Digital sovereignty:** Kolochenko noted that some European organisations may use this incident to promote "EU-made" cloud solutions, though he cautioned that changing cloud providers alone "will quite unlikely make any material change of cloud security landscape."

The Solicitors Regulation Authority has separately warned of a rise in cyber attacks across the professional services sector, with three-quarters of firms visited in a recent investigation having been targeted.

## The Offline Alternative

The European Commission breach illustrates a fundamental limitation of cloud-dependent data storage: no matter how sophisticated the access controls, data that remains network-connected is data that can be reached by an attacker who compromises the right credentials.

As Meghu himself acknowledged, "It only takes one mistake." The break-glass strategies, multi-account isolation, and hardware token requirements he described are all valuable layers of defence, but they are all ultimately identity-based controls protecting network-accessible data.

[Physical air gap storage](/our-difference/offline-secure-storage) removes this attack surface entirely. By physically disconnecting storage from all networks, Firevault's [Vaulted, Protected, Preserved, and Private (VPPP) framework](/platform) ensures that sovereign data, whether belonging to governmental institutions, law firms, or enterprises, cannot be exfiltrated remotely, regardless of how many credentials an attacker compromises.

Had the Commission's most sensitive data been stored in a physically disconnected vault, the 350GB exfiltration simply could not have occurred. No network connection means no remote access, no lateral movement, and no bulk data theft.

## Key Takeaways

-   **Cloud IAM is inherently fragile:** Even with best-practice controls like hardware tokens, break-glass procedures, and account isolation, identity-based access remains vulnerable to a single compromised credential.
-   **Political attackers are harder to deter:** When the goal is reputational damage rather than financial gain, traditional deterrents like encryption and ransom negotiation become irrelevant.
-   **Regulation is not prevention:** The EU has some of the world's most comprehensive data protection regulations, yet the Commission itself has suffered multiple breaches in 2026 alone.
-   **Physical disconnection is the only guarantee:** [Air-gapped storage](/our-difference/offline-secure-storage) eliminates the possibility of remote exfiltration, making it the only approach that can truly protect sovereign and sensitive data from network-based attacks.
-   **Cloud provider responsibility has limits:** Amazon's statement that "AWS did not experience a security event" underscores that cloud providers are not responsible for how customers configure and secure their own accounts.

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.csoonline.com/article/4408642/european-commission-data-stolen-in-a-cyberattack-on-the-infrastructure-hosting-its-web-sites.html)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)[

![Cornelius faces legal investigation after alleged Cl0p cyber attack](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/cornelius-alleged-clop-ransomware-data-breach-1786684482605.png)

Breach Analysis 

### Cornelius faces legal investigation after alleged Cl0p cyber attack

Cornelius faces legal scrutiny following reports of a Cl0p ransomware breach in August 2026. Claims suggest thousands of gigabytes of corporate data were compromised.

14 Aug 2026 4 min 







](/news/cornelius-alleged-clop-ransomware-data-breach)[

![Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg)

Breach Analysis 

### Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust

Delta Air Lines is investigating an unauthorised Wi-Fi network broadcast aboard Flight 591 from Las Vegas to Atlanta, alongside a deauthentication attack that knocked passengers off the aircraft network. The lesson is not about aviation. It is about how easily a trusted connection can be impersonated.

13 Aug 2026 4 min 







](/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026)[

![Ransomware Attacks Spike 20% in July While AI Steals the Headlines](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg)

Breach Analysis 

### Ransomware Attacks Spike 20% in July While AI Steals the Headlines

Ransomware attacks jumped nearly 20 per cent in July, with 799 incidents logged globally. While AI dominates security headlines, finance, technology, pharmaceutical, medical billing and education organisations absorbed the sharpest increases.

12 Aug 2026 4 min 







](/news/ransomware-attacks-spike-july-2026-ai-distraction)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)