European Space Agency confirms data breach


MILAN — The European Space Agency has confirmed a security breach of unclassified material from science servers following reports on social media.

A threat actor claimed to have compromised ESA systems and to have leaked roughly 200 gigabytes of data. According to screenshots shared on X by French cybersecurity professional Seb Latom, the actor alleges they were able to steal source code, API tokens, access tokens for multiple ESA systems, confidential documents, system and application configuration files and hardcoded credentials such as embedded passwords and authentication secrets.

Read more…
Source: Space News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Meta fined €265m over data protection breach that hit more than 500m users

    November 28, 2022

    Facebook’s owner has been fined €265m (£230m) by the Irish data watchdog after a breach that resulted in the details of more than 500 million users being published online. The Data Protection Commission (DPC) said Meta had infringed two articles of the EU’s data protection laws after details of Facebook users from around the world were ...

  • Ransomware gang targets Belgian municipality, hits police instead

    November 26, 2022

    The Ragnar Locker ransomware gang has published stolen data from what they thought was the municipality of Zwijndrecht, but turned out to be stolen from Zwijndrecht police, a local police unit in Antwerp, Belgium. The leaked data reportedly exposed thousands of car number plates, fines, crime report files, personnel details, investigation reports, and more. This type of ...

  • New ransomware attacks in Ukraine linked to Russian Sandworm hackers

    November 25, 2022

    New ransomware attacks targeting organizations in Ukraine first detected this Monday have been linked to the notorious Russian military threat group Sandworm. Slovak software company ESET who first spotted this wave of attacks, says the ransomware they named RansomBoggs has been found on the networks of multiple Ukrainian organizations. “While the malware written in .NET is new, ...

  • UK: Government departments ordered to stop installing cameras made by Chinese firms in ‘sensitive sites’

    November 24, 2022

    Government departments have been told to stop installing cameras made by Chinese firms in “sensitive sites”. They have also been urged to disconnect Chinese-made devices from core computer networks and to consider removing them altogether, amid security concerns. The Government Security Group has said that since companies in China have to comply with the country’s national intelligence ...

  • European Parliament Putin things back together after cyber attack

    November 24, 2022

    The European Parliament has experienced a cyber attack that started not long after it declared Russia to be a state sponsor of terrorism. The attack appears to have made part of the Parliament’s website inoperable and made access impossible for a few hours. A pro-Russian group called KILLNET appears to have claimed responsibility for the attack in ...

  • Sweden boosts cyber, defense spending with NATO in mind

    November 22, 2022

    Sweden’s newly elected center-right government has prioritized spending on defense-strengthening measures in its draft budget bill for 2023, eying to edge the country closer to NATO’s target quota. Sweden, along with fellow unaligned Nordic nation Finland, is currently awaiting unanimous consent from NATO members to join the alliance, a process that could reach its conclusion in ...