https://www.theregister.com/2025/12/31/european_space_agency_hacked/ # # Sign in / up The Register # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features The Future of the Datacenter AWS Re:invent SC25 Supercomputing Month Cloud Infrastructure Month Datacenter Networking Nexus The State of Storage European Supercomputing AI Infrastructure Month Spotlight on RSAC AI Software Development Week Disaster Recovery Week Nvidia GTC Ransomware in Focus Cybersecurity Month VMware Explore Vendor Voice Vendor Voice Vendor Voice All Vendor Voice Intel Core Ultra Processors: Powering business-ready AI PCs ZTE Nutanix: Scale Kubernetes. Not Chaos. Money Movement Hub The BigQuery Difference AWS Global Partner Security Initiative Amazon Web Services (AWS) New Horizon in Cloud Computing (X) Resources Resources Whitepapers Webinars & Events Newsletters [cybercrime] Cyber-crime 13 comment bubble on white European Space Agency hit again as cybercrims claim 200 GB data up for sale 13 comment bubble on white As in past incidents, ESA says the impact was limited to external systems icon Brandon Vigliarolo Wed 31 Dec 2025 // 16:55 UTC # The European Space Agency has suffered yet another security incident and, in keeping with past practice, says the impact is limited. Meanwhile, miscreants boast that they've made off with a trove of data, including what they claim are confidential documents, credentials, and source code. While ESA said it's aware of a security incident, it added in an X post on Tuesday that the breach may have impacted only "a very small number of external servers" used to support unclassified engineering and scientific collaboration. "We have initiated a forensic security analysis--currently in progress--and implemented measures to secure any potentially affected devices," ESA added. "All relevant stakeholders have been informed, and we will provide further updates as soon as additional information becomes available." [cybercrime] That's in contrast to what one cybercriminal posted in their offer of over 200 GB of ESA data for sale on the still-not-dead BreachForums the day after Christmas, according to screenshots grabbed from the seemingly impossible-to-kill cybercrime forum. [cybercrime] [cybercrime] According to the alleged attacker, they gained access to ESA-linked external servers on December 18, and were connected "for about a week," during which they claim to have stolen source code files, CI/ CD pipelines, API and access tokens, confidential documents, configuration files, Terraform files, SQL files, hardcoded credentials, and a dump of "all their private Bitbucket repositories as well." We reached out to ESA to get more information about the status of its investigation, and more specifics on what sort of servers were breached, but didn't hear back, with an automated response informing us that the Agency's offices are closed for the New Year holiday. * Canada ups its European Space Agency bet 10x with $376M * UK sinks to fifth in ESA funding league behind Spain * ESA tests bacterial powder to feed Moon and Mars crews * Why blow up satellites when you can just hack them? As noted above, this isn't the first time the ESA has experienced a security incident, nor the first time it has said the affected systems were external to its core networks. The Space Agency's online store was hit by attackers last year shortly before the Christmas holiday, with miscreants inserting a fake payment page to nab customer info while unsuspecting users were shopping for space-themed holiday gifts. ESA, naturally, said it's not in charge of its own online store. [cybercrime] A trio of ESA domains was compromised in 2015 via an SQL vulnerability, resulting in the theft and leak of information belonging to thousands of subscribers and some ESA staff. Just a few years prior to that, in 2011, the ESA was also breached, with an attacker publishing administrator, content management, FTP login credentials, and Apache server config files online for all to see. As was the case with this latest incident and last year's store attack, ESA said the 2011 breach didn't affect the Agency's internal networks. Fair enough - but this sure feels like a pattern. (r) Get our Tech Resources # Share More about * Cybersecurity * Data Breach * ESA More like these x More about * Cybersecurity * Data Breach * ESA Narrower topics * Center for Internet Security * Hubble Space Telescope * ISS * James Webb Space Telescope * RSA Conference * Zero trust Broader topics * Austria * Belgium * Czech Republic * Denmark * Estonia * Finland * France * Germany * Greece * Hungary * Ireland * Italy * Luxembourg * Netherlands * Norway * Poland * Portugal * Romania * Security * Space * Spain * Sweden * Switzerland * United Kingdom More about # Share 13 comment bubble on white COMMENTS More about * Cybersecurity * Data Breach * ESA More like these x More about * Cybersecurity * Data Breach * ESA Narrower topics * Center for Internet Security * Hubble Space Telescope * ISS * James Webb Space Telescope * RSA Conference * Zero trust Broader topics * Austria * Belgium * Czech Republic * Denmark * Estonia * Finland * France * Germany * Greece * Hungary * Ireland * Italy * Luxembourg * Netherlands * Norway * Poland * Portugal * Romania * Security * Space * Spain * Sweden * Switzerland * United Kingdom TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Defusing space 'scope photobombs and more: Mitigating pollution from satellite RF transmissions Interview 'What do we need to do better?' El Reg talks to comms boss about the problem Science1 Jan 2026 | Welcome to Wendy's! Before your order can be taken, you must first reset this kiosk Bork!Bork!Bork! Do you want bork with that? Offbeat1 Jan 2026 | 23 How Microsoft gave customers what they wanted: An audience with Bill Gates Well kinda... Your call will be transferred to the next available assistant AI + ML1 Jan 2026 | 14 Bring complexity under control with enterprise-grade Kubernetes No, it'll probably never be a doddle - but you don't have to take the hard way when deploying Kubernetes, says Nutanix Sponsored Feature [cybercrime] Nvidia DMs TSMC: please sir can I have some more? The Chinese are starved for H200s GPUzilla has reportedly received orders for more than two million units Systems31 Dec 2025 | 7 US Army seeks human AI officers to manage its battle bots What, weekend warriors from Silicon Valley not good enough? Public Sector31 Dec 2025 | 4 IPv6 just turned 30 and still hasn't taken over the world, but don't call it a failure Feature The world has passed it by in many ways, yet it remains relevant Networks31 Dec 2025 | 125 Everybody has a theory about why Nvidia dropped $20B on Groq - they're mostly wrong El Reg speculates about what GPUzilla really gets out of the deal Systems31 Dec 2025 | 17 The most durable tech is boring, old, and everywhere Opinion From COBOL and C to Linux and SQL, the unglamorous software that keeps the world running refuses to disappear Software31 Dec 2025 | 122 Hong Kong's newest anti-scam technology is over-the-counter banking Funds in 'Money Safe' accounts are only available when customers appear for face-to-face verification Cyber-crime31 Dec 2025 | 23 Cybersecurity pros admit to moonlighting as ransomware scum Pair became ALPHV affiliates to prey on US-based clients Cyber-crime31 Dec 2025 | 10 New York's incoming mayor bans Raspberry Pi at his inauguration party Zohran Mamdani appears not to understand that smartphones can be used for evil Security31 Dec 2025 | 51 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * Ts & Cs * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2025 no-js