- FENIE Energía breachSpanish utility company data breach; 430GB database leak on cybercrime forum
ThreatNoir Weekend Brief — March 29
Morning Review in IT Security — March 29, 2026
March 29, 2026 brings critical security incidents spanning critical infrastructure, government systems, and consumer applications. Today's briefing covers major breaches affecting European institutions, energy sector vulnerabilities, and compromised software distribution channels that demand immediate attention from security teams worldwide.
Spanish Energy Company FENIE Energía Suffers Massive Data Breach
The Spanish electricity company FENIE Energía has been completely compromised in what represents a significant threat to critical infrastructure security. Following the company's failure to respond to extortion communications, threat actors released a sample of the company's database on a popular cybercrime forum. The breach encompasses 430 gigabytes of data containing over 1.7 million rows of information. Source: DarkWebInformer
This incident underscores the dangers of non-responsiveness to security threats and the vulnerability of energy sector organizations to targeted attacks. The scale of the breach and the public disclosure of samples suggest significant operational and privacy implications for the affected company and its customers.
European Commission Targeted by ShinyHunters in Major Data Breach
The European Commission has fallen victim to a substantial data breach attributed to the ShinyHunters threat group. Approximately 350 gigabytes of data from Commission systems bearing the europa.eu domain have been leaked by the attackers. Officials are currently investigating the breach, though independent verification of the claims remains pending. Source: HackRead
The breach of European Commission infrastructure represents a significant security incident at the highest levels of EU governance. The involvement of ShinyHunters, a known threat actor group, indicates a deliberate and sophisticated attack against one of Europe's most critical institutional targets.
White House Android Application Contains Dangerous Security Flaws
Security analysis of the official White House Android application has revealed multiple serious vulnerabilities and suspicious functionality embedded within the code. The application contains a cookie and paywall bypass injector, implements GPS tracking that activates every 4.5 minutes, and loads JavaScript code from an external GitHub Pages repository. Source: thereallo.dev
These findings raise substantial concerns about user privacy, application security practices, and the integrity of official government software. The presence of tracking functionality and external code loading mechanisms suggests either severe development oversights or intentional data collection practices that warrant immediate investigation and remediation.
BeamMP Gaming Mod Platform Compromised in Supply Chain Attack
BeamMP, a widely used modification platform for the BeamNG Drive racing simulator, has been compromised in what security researchers are investigating as a potential malware distribution incident. The compromise appears to have resulted in the delivery of malicious code to user machines through the mod distribution channel. Source: vxunderground
This supply chain attack demonstrates how threat actors continue to target gaming and modding communities as vectors for malware distribution. Users of the BeamMP platform should immediately assess their systems for signs of compromise and consider isolating affected machines pending further investigation.
Today's security landscape reflects persistent threats across multiple sectors, from critical infrastructure to government systems to consumer applications. Organizations and users must remain vigilant in monitoring for indicators of compromise and implementing immediate remediation measures for affected systems.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- ShinyHuntersThreat actor claiming responsibility for European Commission data breach
- ShinyHuntersThreat actor group claiming responsibility for 350GB European Commission data breach
whitehouse.govWordPress REST API backend serving app content via /wp-json/whitehouse/v1 endpointsice.govICE tip reporting form hardcoded into app
hxxps://www[.]ice[.]gov/webform/ice-tip-formDirect link to ICE tip reporting form embedded in news app
- BeamMP compromise malwareMalicious payload delivered via compromised BeamMP mod distribution