logo

European Space Agency's official store hacked to steal payment cards

ID: 99b04bc0-b08d-53da-b04c-9f1ca0dfdefd

STIX ID: report--99b04bc0-b08d-53da-b04c-9f1ca0dfdefd

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-12-24

Date Updated: 2026-03-27

Author: Ionut Ilascu

...
...

The European Space Agency's official web shop was compromised by injected obfuscated JavaScript that loaded a fake Stripe payment page to skim customers' payment card data. Security researchers identified a spoofed exfiltration domain (esaspaceshop.pics) used by the script; the code has since been removed and the store's hosting relationship with ESA indicates the shop is externally managed, which may limit direct agency data exposure but introduces supply-chain and employee risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.