European Space Agency confirms data breach


MILAN — The European Space Agency has confirmed a security breach of unclassified material from science servers following reports on social media.

A threat actor claimed to have compromised ESA systems and to have leaked roughly 200 gigabytes of data. According to screenshots shared on X by French cybersecurity professional Seb Latom, the actor alleges they were able to steal source code, API tokens, access tokens for multiple ESA systems, confidential documents, system and application configuration files and hardcoded credentials such as embedded passwords and authentication secrets.

Read more…
Source: Space News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Major telco breach sees 6.2 million users have personal info leaked

    February 13, 2026

    Dutch telecommunications company Odido has confirmed suffering a cyberattack and losing sensitive data on millions of people. In a notice published on its website, the company says it “deeply regrets” the situation and is “fully committed” to limiting its impact. “Based on investigation, the incident concerns personal data from a customer contact system used by Odido,” ...

  • Patch Tuesday – February 2026

    February 11, 2026

    Microsoft is publishing 55 vulnerabilities this February 2026 Patch Tuesday. Microsoft is aware of exploitation in the wild for six of today’s vulnerabilities, and notes public disclosure for three of those. Earlier in the month, All three of the publicly disclosed zero-day vulnerabilities published today are security feature bypasses, and Microsoft acknowledges the same cast of ...

  • Germany prepares to attack cyber enemies

    February 9, 2026

    The German government is preparing an overhaul of its intelligence and cybersecurity powers to fight back against foreign hackers and spies with offensive cyber operations of its own. Officials are drafting two pieces of legislation, one revising the powers of Germany’s foreign intelligence services to allow them to conduct cyber operations abroad, and another giving security ...

  • European Commission probes intrusion into staff mobile management backend

    February 9, 2026

    Brussels is digging into a cyber break-in that targeted the European Commission’s mobile device management systems, potentially giving intruders a peek inside the official phones carried by EU staff. Identified by CERT-EU, the bloc’s computer emergency response team responsible for defending EU institutions, the intrusion was detected on January 30 and affected infrastructure associated with centrally ...

  • UK: Welsh firms ill-prepared to meet the challenges of cyber security threats

    February 9, 2026

    Many businesses in Wales lack the readiness to meet cyber security threats while also underestimating their potential costs, shows new research. Undertaken by Bridgend-based managed services provider CSG, the research focused on firms across construction, manufacturing, professional services, retail, public services and tourism. It reveals that two-thirds of (66%) have already experienced a cyber security incident. Typically, ...

  • Approaching cyclone: Vortex Werewolf attacks Russia

    February 6, 2026

    In December 2025 and January 2026, BI.ZONE Threat Intelligence detected malicious activity by a new cluster Vortex Werewolf (SkyCloak). The attacks targeted Russian government and defense organizations. BI.ZONE researchers findings indicate that the adversary used phishing emails to deliver malware to the target systems. Victims received messages containing a download link disguised as a Telegram file‑sharing ...