European Space Agency (ESA) External Servers Breached
The European Space Agency (ESA) confirmed a cybersecurity breach affecting a small number of external servers used for collaborative engineering activities.
Key points
- Breach affected external servers used for collaborative engineering.
- Threat actor "888" claimed to have exfiltrated over 200GB of data.
- Stolen data includes source code, CI/CD pipelines, API/access tokens, confidential documents, configuration files, Terraform files, SQL files, and private Bitbucket repositories.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Dec 29, 2025
- Updated
- Jun 25, 2026
- Confidence
- Medium
- Evidence
- 3 sources
Structured assessment
Signal analysis
This analysis groups the signal by industry, likely incident action and impacted security area.
Threat source
Watch exposure paths that could affect data, operations or third-party trust.
Business impact
- Impact area
- Unknown
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?
The European Space Agency (ESA) confirmed a cybersecurity breach affecting a small number of external servers used for collaborative engineering activities. A threat actor, "888", claimed to have exfiltrated over 200GB of data, including source code, CI/CD pipelines, API and access tokens, confidential documents, configuration files, Terraform files, SQL files, and private Bitbucket repositories. ESA stated that only unclassified data was compromised, with no impact on core mission or classified systems.
When was this signal reported?
Shadow Tier lists Dec 29, 2025 as the signal date.
Which organization is connected to this signal?
Esa is the organization connected to this public signal.
Explore Esa