ESA Says Data Breach Was Limited to Servers with Unclassified Documents

ESA has downplayed the severity of a recent data breach, stating that it affected a limited number of external science servers storing only unclassified documents.
Credit: European Spaceflight / @seblatombe (X)

The European Space Agency (ESA) has released an initial statement regarding an alleged data breach, stating that it affected a โ€œvery limited number of science servers located outside the ESA corporate network.โ€

On 26 December, reports began to emerge on X claiming that ESA had suffered a significant data breach, with a hacker using the alias โ€œ888โ€ offering more than 200 gigabytes of data for sale. According to the hackerโ€™s listing, the allegedly compromised data included source code for proprietary software, sensitive project documentation, API tokens, and hardcoded credentials.

In an initial statement issued on 29 December, the agency said it was aware of the alleged data breach and that a forensic analysis was underway. On 30 December, the European Space Agency confirmed that its initial findings indicated that a data breach had occurred, while seemingly downplaying its severity by characterising its impact as โ€œlimited.โ€

โ€œAt this stage, the forensic analysis has identified a very limited number of science servers, located outside the ESA corporate network, that may be affected,โ€ the statement said. โ€œThese servers are used for unclassified collaborative engineering solutions within the scientific community. Relevant stakeholders have been notified. Further updates will be provided once the analysis is complete.โ€

The agency added that relevant stakeholders had been notified and that โ€œshort-term remediation measuresโ€ had been implemented to secure any potentially affected devices. Further updates are expected as the forensic analysis continues.

Keep European Spaceflight Independent

Your donation will help European Spaceflight to continue digging into the stories others miss. Every euro keeps our reporting alive.

LEAVE A REPLY

Please enter your comment!
Please enter your name here