Europe
European Space Agency (ESA)
The new year began with a major cybersecurity incident that could ripple across the aerospace and defense sectors. On January 7, the European Space Agency (ESA) confirmed a significant data breach, with more than 700 GB of data exposed across two separate cyber incidents.
Earlier this week, the hacking group Scattered Lapsus$ Hunters claimed it gained access to ESA servers as far back as September 2024 by exploiting a publicly known vulnerability. The group claims to have exfiltrated approximately 500 GB of data, including operational procedures, spacecraft and mission details, subsystem documentation and sensitive contractor information linked to ESA partners such as SpaceX, Airbus Group and Thales Alenia Space. This followed a separate incident in December, when another cybercriminal offered more than 200 GB of ESA data for sale on a dark web forum.
According to the attackers, the stolen files contain highly sensitive information tied to multiple space programs and ESA missions. More concerning, the group claimed the security flaw has not yet been remediated, potentially giving them continued access to ESA's live systems.
How it could affect your business
This incident shows how unidentified or unpatched vulnerabilities can give attackers a clear path into even well-defended environments. Once inside, threat actors can move quietly across systems and access sensitive data before they're detected. Automated penetration testing can help organizations identify these hidden weaknesses and potential attack paths early, reducing the risk of a successful breach.