ESA subdomain credential and collaborator-directory leak (2015)
What happened
In mid-December 2015 attackers operating under the Anonymous banner published data taken from three European Space Agency subdomains, sci.esa.int, exploration.esa.int and due.esrin.esa.int, having exploited a blind SQL injection vulnerability to reach the database behind them. The published material was divided into three parts: registered users, database schemas, and an ESA collaborator directory. It comprised more than 8,000 subscriber records with names, email addresses and passwords, of which 52 were internal ESA users, together with hundreds of collaborator entries carrying full names, fax and telephone numbers, addresses, email addresses and the name of the organisation or employer each person belonged to. The published passwords showed weak practice, with 39 per cent of three characters. The attackers gave no objective beyond amusement, stating that Christmas was coming, that they had to do something for fun, and that they did it for the lulz. No cited source reports that mission systems, spacecraft or operational data were reached.
One edge, and it is not the obvious one. The eye-catching part of this leak is the 8,000 subscriber credentials, but those are public-website newsletter accounts and they map to nothing: they authenticate nobody to anything ESA operates. The part that does map is the collaborator directory, which is a named, role-attributed, contactable list of the people and organisations around ESA's missions, and that is the material REC-0002.02 is written about. Both of SPARTA's citing techniques are rejected. Overall confidence is moderate rather than high because neither retrieved source carries an ESA statement: the record rests entirely on the attackers' own dump as described by two independent trade-press accounts, which agree with each other. Note also that SPARTA's bibliography entry dates this to December 2014; the article it cites is dated 14 December 2015 and the event is 2015.
Attack vector
Blind SQL injection against three ESA subdomains, giving access to the database behind them.
Operational impact
None reported against missions or spacecraft. No official ESA response is recorded in either cited source.
Data compromised
More than 8,000 subscriber records (names, email addresses, passwords), 52 of them internal ESA users; database schemas; and a collaborator directory of full names, fax and telephone numbers, addresses, email addresses and organisational affiliations.
Disclosed
2015-12-14
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
One of the three parts of the published dump was an ESA collaborator directory carrying, for each entry, the full name, telephone and fax numbers, address, email address and the organisation or employer the person belonged to. REC-0002.02's subject is mapping the human and institutional terrain around a mission to find leverage for phishing, credential theft or supply-chain compromise, and it names distribution lists, organisational charts and the identification of prime and subcontractors among its targets. A name-and-affiliation directory of an agency's collaborators is that material, published. Confidence is moderate because neither source characterises which missions or programmes the collaborators were attached to, and because no ESA statement corroborates the dump's contents.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
SPARTA's IMP-0006 is theft of data gathered, processed and sent from the victim spacecraft. Newsletter subscriber records and a contact directory are neither. The material taken is carried by the REC-0002.02 edge.
Considered as a sibling of the accepted edge. REC-0002.03 is about operational rhythms: pass schedules, network windows, calibration and maintenance timelines, anomaly playbooks. The dump contained a contact directory, not a schedule.
Accepted on the 2011 ESA record and deliberately not accepted here: the distinction is worth stating. In 2011 the leaked credentials were FTP, database, administrator and editor accounts on ESA-operated servers. Here they are public-website subscriber accounts: 8,000 people who registered for ESA web content, with 52 internal users among them. REC-0003.04 requires a credential that authenticates the holder as a legitimate actor in a space, ground or supporting cloud network. A newsletter login is not that, and neither source says what the 52 internal accounts could reach.
REC-0008.03 is about correlating discovered component and software versions against CVE and advisory sources to assemble an exploit catalogue against the supply chain. What happened here is that attackers exploited one blind SQL injection flaw in an ESA web application. Exploiting a vulnerability is not cataloguing known vulnerabilities in a supply chain, and the parent technique REC-0008 is about the supply chain, which nothing here touches.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
Tier 3: Established technology publication, named author, security column. Reports the attackers' dump; carries no ESA statement. This is the URL SPARTA's own bibliography cites for this incident at two techniques.
Tier 3: Established technology publication, named author, reporting independently of Computerworld the following day. Also carries no ESA statement.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.