It's only been a few weeks since the cyberattack suffered by the European Space Agency (ESA) over the Christmas period was made public, and the situation has already worsened.
See also: ESA confirms breach of "external servers"
When the ESA revealed that it had been breached over the Christmas period by a hacker known as “888”, it was quick to reassure the public that the impact was “limited” to external servers containing unclassified engineering data.

However, the hacker claimed to have extracted around 200GB of data, including source code, APIs and access tokens, hardcoded credentials, and SQL files. Some of the stolen documents are reportedly related to the Ariel space telescope mission, which aims to launch in 2029 to determine the composition of exoplanet atmospheres.
After the latest data breach affecting the ESA, the December 2025 incident doesn’t seem so bad. This month, the cybercrime group Scattered Lapsus$ Hunters exploited what they claim was an unpatched vulnerability to steal an additional 500GB of data—more than double the original amount.
See also: Europe: Simulation of a catastrophic solar storm – Dangers
Additionally, this latest breach reportedly includes data that may be more concerning, such as operating procedures, spacecraft and mission details, subsystem documentation, and private contractor data from ESA partners, including SpaceX, Airbus Group , and Thales Alenia Space.

As a result of this latest incident, ESA has confirmed that a criminal investigation is underway. Some have suggested that poor cybersecurity practices at ESA may have helped the hacking group gain unauthorized access to systems.
Cybersecurity researcher Clémence Poirier told Space.com that she often comes across ESA (as well as NASA) staff email credentials for sale on Dark Web forums.
Unfortunately for the ESA, it has suffered a history of cybersecurity incidents. These range from the breach of its official merchandise online store with payment card collection code just days before Christmas 2024 to a breach linked to Anonymous that exposed employee and subscriber passwords and other data in 2015.
See also: Eurocert.pl company victim of ransomware attack

The high visibility of organizations working in space means they are common targets for both bug hunters and malicious hackers, with vulnerabilities being disclosed “almost every day” on BugCrowd for NASA, for example.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
