Site navigation

European Space Agency Confirms 200GB Hack

Graham Turner

,

European Space Agency breach
The agency says an internal forensic investigation is ongoing and that no classified or mission-critical systems were affected.

The European Space Agency (ESA) has confirmed that a number of its external science servers were compromised during a recent security incident, triggering an ongoing internal forensic investigation.

In a statement emailed to Davey Winder, senior contributor at Forbes, an ESA spokesperson said the affected systems were “used for unclassified collaborative engineering solutions within the scientific community” and were located outside the agency’s corporate network.

The spokesperson added that, based on analysis so far, the incident has not impacted any classified or highly sensitive mission systems, although it remains unclear what specific data may have been accessed or exfiltrated.

Threat actors have claimed that up to 200GB of data was stolen during the breach. According to posts on BreachForums, the attackers alleged they compromised ESA systems on December 18 and maintained access for around a week.

“I’ve been connecting to some of their services for about a week now and have stolen over 200GB of data. Including dumping all their private Bitbucket repositories as well,” the post stated.

The alleged data haul includes source code; CI/CD pipelines; API and access tokens; confidential documents; configuration, Terraform and SQL files; and hardcoded credentials.

ESA said it is “aware” of the incident and has taken steps to contain it.

“Our analysis so far indicates that only a very small number of external servers may have been impacted,” the agency said in a separate statement. “These servers support unclassified collaborative engineering activities within the scientific community. All relevant stakeholders have been informed, and we will provide further updates as soon as additional information becomes available.”

The agency also confirmed that it has “implemented measures to secure any potentially affected devices.”

“ESA maintains a robust framework and governance structure to address such incidents effectively,” an ESA spokesperson told Forbes’ Winder, confirming that the agency “has immediately initiated an internal forensic security analysis, which is currently ongoing, and has implemented short-term remediation measures to secure any potentially affected devices.”

Headquartered in Paris, the European Space Agency is an intergovernmental organisation with around 3,000 employees and is responsible for coordinating space stuff for 23 member states, including the UK and Switzerland.

The incident comes amid growing concern over cybersecurity threats targeting the space sector, which has become an increasingly valuable commercial and strategic domain.


Recommended reading


A 2025 Space Foundation report cited in coverage of the incident valued the global space economy at $613 billion in 2024, with projections suggesting it “could cross the $1 trillion mark as soon as 2032.” With that growth has come heightened interest from threat actors seeking to exploit vulnerabilities across complex, distributed technology environments.

ESA has not confirmed the volume or nature of data allegedly accessed and has not attributed the attack. The agency said that relevant stakeholders have been notified and that further updates will be provided once the forensic analysis is complete.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data