The European Space Agency got hacked, and now we own the domain used!

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

The European Space Agency's online shop was compromised by a Magecart attack that injected malicious JavaScript to steal payment card data. The attack followed a typical pattern: checking for checkout pages, loading a fake jQuery payload, cloning the payment button, displaying a fraudulent Stripe payment form, and exfiltrating complete card details plus personal information to attacker-controlled servers. The attack could have been prevented at multiple stages using Content Security Policy and monitoring solutions that detect unauthorized script execution, new domain dependencies, or data exfiltration attempts. The attacker's lookalike domain (esaspaceshop.pics) has since been acquired and repurposed to point to a security case study.

10m read timeFrom scotthelme.ghost.io
Post cover image

Sort: