European Space Agency confirms data breach


MILAN — The European Space Agency has confirmed a security breach of unclassified material from science servers following reports on social media.

A threat actor claimed to have compromised ESA systems and to have leaked roughly 200 gigabytes of data. According to screenshots shared on X by French cybersecurity professional Seb Latom, the actor alleges they were able to steal source code, API tokens, access tokens for multiple ESA systems, confidential documents, system and application configuration files and hardcoded credentials such as embedded passwords and authentication secrets.

Read more…
Source: Space News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Russia restricts Telegram, WhatsApp calls, citing law breaches

    August 13, 2025

    Russia has started restricting some Telegram and WhatsApp calls, accusing the foreign-owned platforms of failing to share information with law enforcement in fraud and terrorism cases, the digital development ministry said on Wednesday. The blocking measures, which extend only to calls, would be lifted should the platforms comply with Russian law, the ministry said. This includes ...

  • Bouygues Telecom data breach could affect millions of customers

    August 8, 2025

    French telco giatn Bouygues Telecom has confirmed suffering a cyberattack in which it lost sensitive customer data. In a short announcement published on its website, the company said it detected the attack on August 4, and following an investigation, determined threat actors stole people’s contact details, contract data, civil status data (or company details), and IBAN ...

  • Denmark energy cyber attack highlights infrastructure security gaps

    August 4, 2025

    November 2023 saw an unprecedented cyber attack on Denmark’s energy infrastructure. In a co-ordinated breach of 22 companies, criminal gangs gained access to industrial control systems. Investigators believe at least one of the attackers was acting on behalf of a state. Michael Murphy, who heads Fortinet’s APAC Operational Technology group from the company’s Sydney office, says ...

  • Luxembourg: Cybercriminals stole thousands from BIL customers using phishing scam

    August 2, 2025

    After cybercriminals stole thousands from BIL customers using a fake website, the banking association maintains that digital banking tools remain safe, but users must stay vigilant. In the wake of a sophisticated phishing scheme that led to major financial losses for dozens of BIL customers, The Luxembourg Banker’s Association (ABBL) is defending the security of the ...

  • Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats

    July 31, 2025

    Microsoft Threat Intelligence has uncovered a cyberespionage campaign by the Russian state actor we track as Secret Blizzard that has been targeting embassies located in Moscow using an adversary-in-the-middle (AiTM) position to deploy their custom ApolloShadow malware. ApolloShadow has the capability to install a trusted root certificate to trick devices into trusting malicious actor-controlled sites, enabling ...

  • Telecom giant Orange warns of disruption amid ongoing cyberattack

    July 29, 2025

    Orange, a French telecommunications giant and one of the largest phone providers in the world, announced on Monday that it was the victim of an unspecified cyberattack. In the announcement, the company said that it detected a cyberattack “on one of its information systems” on July 25, and that it proceeded to “isolate potentially affected services ...