News / § Scam watch

Hundreds of scam PDFs are ranking from the European Space Agency's own domain — and Google is quoting them back

Scam watch By Ihor Makushinsky

The European Space Agency’s Cosmos portal — the mission-support site for Gaia, Euclid and XMM-Newton, fronting a science archive past a petabyte — is serving hundreds of spam PDFs that advertise pirate IPTV subscriptions, free-Robux generators, Coin Master spins and Instagram followers. These are not on a lookalike domain. They download from www.cosmos.esa.int/documents/… under ESA’s own certificate, out of Cosmos’s document libraries. We checked three on 4 August 2026 — one IPTV ranking file and two Roblox files, sitting in three different library IDs — and each returned HTTP 200 application/pdf, so this is not one compromised folder. Filenames and in-document datelines run from June to 1 August 2026: a campaign, not a burst. Uploading to Cosmos takes site-editor access, which leaves a compromised editor account or a weakness in the upload path; ESA had not commented by the time TorrentFreak published. And the files perform — they take featured snippets on IPTV queries, and Google’s AI Overview has relayed their provider rankings as if the recommendation were ESA’s. We are not linking the documents; the site: query in Sources reproduces the finding in one click.

It is the second run of this playbook against a European public institution in thirteen months — ESA is intergovernmental rather than an EU body, but the ranking signal a spammer borrows does not care about the distinction. In July 2025 Eurostat was hosting near-identical PDFs funnelling to an IPTV storefront at portugueseiptv[.]pt; the Commission pulled them once alerted and the URLs left the index. Google’s spam policies name the mechanic, and it is not the fashionable one: hacked content — “any content placed on a site without permission, due to vulnerabilities in a site’s security” — as distinct from site reputation abuse, where a host knowingly rents out ranking it earned with its own work. That distinction decides who you write to and what you ask for.

Why it matters

The asset being stolen is institutional trust, and it now converts straight into machine answers rather than just blue links. A brand owner meets this from one of two ends: your trademark is the bait — Roblox and Coin Master are both named in these files — or your own domain is the unwitting host.

Counsel’s note

Take the first position. If your brand is named in a file like this, your counterparty is not the spammer. It is the institution whose infrastructure is serving the file, and then Google. The leverage is in the framing: the upload was unauthorised, so this is a security incident on their estate, not an editorial dispute about a third party’s content. Sent to a security or abuse contact in those words it gets escalated; sent to a general legal inbox as a trademark complaint it gets queued behind everything else.

Sequence the search side after the source, not alongside it. While the PDF still answers 200, there is nothing for Google to correct — the Refresh Outdated Content tool works on pages you do not own only once the content is gone or materially different. Removal at source first, index flush second, and if the material reached an AI Overview, expect the generated answer to lag the index it was built from. Capture the evidence before any of that: once ESA deletes the file, your proof of what a government-grade domain was telling searchers about your brand deletes with it.

Now the second position, because it is the one nobody budgets for. Any document library that couples editor upload with public direct-URL serving is a publishing surface, whatever your CMS calls it. A site:yourdomain.com filetype:pdf sweep takes a minute to run. The day it returns words you never published, you have a hacked-content problem with your own ranking as the payload — and your brand becomes the endorsement in a stranger’s AI answer.

For our verticals the economics are the point. Affiliate commission drives these drops, and the crews running “top 10 IPTV 2026” run “best casino 2026” and “top broker 2026” from the same infrastructure. When your licensed brand turns up in an unlicensed affiliate’s ranking hosted on an .int, .edu or .gov, you are holding two problems at once: unauthorised affiliate use of the mark, and marketing of your brand into jurisdictions where you do not hold a licence — with an institutional domain lending it credibility you would never have bought.

What this means for you

Run site:yourdomain.com filetype:pdf today, and set a monitor for your brand name plus filetype:pdf on domains you do not control. If your mark is the bait, preserve the evidence, report it to the host as a security incident, and only then chase the index — our guides on content feeding AI Overviews and affiliate abuse of your brand cover the mechanics, and our operators page sets out how we run the monitoring that catches the next drop.

Ihor Makushinsky, senior counsel at Lawyerd
Ihor Makushinsky

Senior counsel · in IP and compliance practice since 2014. The counsel's note in every item is his own.

Full counsel profile →