Special Features

Ransomware in Focus

Polish space agency confirms cyberattack

Officials vow to uncover who was behind it


The Polish Space Agency (POLSA) is currently dealing with a "cybersecurity incident," it confirmed via its X account on Sunday.

POLSA didn't reveal much in the way of details about what's going on, other than that the agency "immediately disconnected" its own network after discovering an intrusion into its systems. The social media post suggests this measure was taken to safeguard the security of its data. 

Language like this is often seen in ransomware disclosure notices, although there is no indication that the event involves ransomware at this time. Pulling systems offline suggests POLSA was trying to eradicate a rogue user in the network and/or potentially stop the flow of data out of its servers.

The agency added that regulators and authorities have been alerted to the situation and its investigation into the attack remains ongoing. 

The Register contacted POLSA for an update but it did not respond immediately. However, sources inside the agency, who asked to remain anonymous, claimed the attack appears to be related to an internal email compromise and that staff are being told to use phones for communication instead.

At the time of writing, POLSA's website is unreachable and updates are coming from its X account. 

Also confirming the attack via X, Poland's digitalization minister Krzysztof Gawkowski said "intensive operational activities" were underway to identify who was behind the attack.

Gawkowski also said CSIRT NASK and CSIRT MON, two of the three state computer security incident response teams in Poland, are helping POLSA fend off the attack. The teams belong to Poland's National Research Institute and the Ministry of National Defence respectively.

Founded in 2014, Gdańsk-based POLSA is part of the European Space Agency (ESA) and oversees the country's contribution to space exploration and development of technology such as satellites. 

It also facilitates the collaboration between academia and industry members, and helps Polish aerospace companies access funding from the ESA. ®

Send us news
1 Comment

Cybersecurity not the hiring-'em-like-hotcakes role it once was

Ghost positions, HR AI no help – biz should talk to infosec staff and create 'realistic' job outline, say experts

Los Alamos boffins slap blinkers on satellites so we know who to blame in a crash

Extremely Low Resource Optical Identifier no brighter than LED, but readable with telescopes

Rather than add a backdoor, Apple decides to kill iCloud encryption for UK peeps

Plus: SEC launches new crypto crime unit; Phishing toolkit upgraded; and more

ESA's Integral gamma-ray gazer gasps its last

After almost 23 years on the job, observations end for 2029 re-entry

Harassment allegations against DEF CON veteran detailed in court filing

More than a dozen women came forward with accusations

Einstein Probe finds two stars that have spent 40 million years taking turns eating each other

Odd X-ray flashes gave the game away, just few weeks after China-led mission launched

DARPA skips the lab, will head to orbit to test space manufacturing tech

Previous NOM4D experiments have gone so well, says project leader, that it's time to get real

First private moon lander to touch down safely starts sending selfies

Firefly Aerospace’s Blue Ghost planned to work for 14 days, should be useful for years thanks to its reflector that improves on Apollo-era tech

Ransomware criminals love CISA's KEV list – and that's a bug, not a feature

1 in 3 entries are used to extort civilians, says new paper

Wallbleed vulnerability unearths secrets of China's Great Firewall 125 bytes at a time

Boffins poked around inside censorship engines – here's what they found

Signal will withdraw from Sweden if encryption-busting laws take effect

Experts warned the UK’s recent 'victory' over Apple would kickstart something of a domino effect

MITRE Caldera security suite scores perfect 10 for insecurity

Is a trivial remote-code execution hole in every version part of the training, or?