The European Space Agency has disclosed the compromise of a "very small number of external servers" containing unclassified details on collaborative engineering efforts following attack claims on its systems and private Bitbucket repositories, which purportedly led to the exfiltration of more than 200 GB of data, reports BleepingComputer.
Allegedly pilfered in the ESA breach were data, including source code, API tokens, CI/CD pipelines, confidential documents, access tokens, SQL files, Terraform files, and hardcoded credentials, said attackers in a post on BreachForums, which also included a threat to expose the space agency's Bitbucket repositories.
"ESA is aware of a recent cybersecurity issue involving servers located outside the ESA corporate network. We have initiated a forensic security analysis currently in progress and implemented measures to secure any potentially affected devices," said the agency, which has already informed its stakeholders of the incident.
Such a development comes over a year after ESA's online store was injected with customer data and payment card information-stealing code.
Allegedly pilfered in the ESA breach were data, including source code, API tokens, CI/CD pipelines, confidential documents, access tokens, SQL files, Terraform files, and hardcoded credentials, said attackers in a post on BreachForums, which also included a threat to expose the space agency's Bitbucket repositories.
"ESA is aware of a recent cybersecurity issue involving servers located outside the ESA corporate network. We have initiated a forensic security analysis currently in progress and implemented measures to secure any potentially affected devices," said the agency, which has already informed its stakeholders of the incident.
Such a development comes over a year after ESA's online store was injected with customer data and payment card information-stealing code.




