Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cyberattack hits European Space Agency’s online store, payment card data stolen #21558

Open
swidup opened this issue Dec 26, 2024 · 0 comments

Comments

@swidup
Copy link
Member

swidup commented Dec 26, 2024

https://www.techmonitor.ai/technology/cybersecurity/cyberattack-esa-online-store-payment-card-data-stolen

"The European Space Agency’s (ESA) official web shop has fallen victim to a cyberattack, resulting in the theft of customer payment card details during transactions. The breach, identified by e-commerce security firm Sansec, involved a malicious JavaScript code embedded into the store’s checkout process, redirecting customers to a counterfeit payment page.

Malicious script redirects customers to fake payment page
The fake payment page, which mimicked a legitimate Stripe interface, was served directly from ESA’s web shop, making it appear authentic to unsuspecting users. The attack exploited domain spoofing, using a near-identical domain name. While ESA’s official shop operates under “esaspaceshop.com,” the attackers employed “esaspaceshop.pics,” leveraging a different top-level domain to deceive visitors."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant