Hundreds of scam PDFs are ranking from the European Space Agency's own domain — and Google is quoting them back
The European Space Agency’s Cosmos portal — the
mission-support site for Gaia, Euclid and XMM-Newton, fronting a science
archive past a petabyte — is serving hundreds of spam PDFs that advertise
pirate IPTV subscriptions, free-Robux generators, Coin Master spins and
Instagram followers. These are not on a lookalike domain. They download from
www.cosmos.esa.int/documents/… under ESA’s own certificate, out of Cosmos’s
document libraries. We checked three on 4 August 2026 — one IPTV ranking file
and two Roblox files, sitting in three different library IDs — and each
returned HTTP 200 application/pdf, so this is not one compromised folder.
Filenames and in-document datelines run from June to 1 August 2026: a
campaign, not a burst. Uploading to Cosmos takes site-editor access, which
leaves a compromised editor account or a weakness in the upload path; ESA had
not commented by the time TorrentFreak published. And the files perform —
they take featured snippets on IPTV queries, and Google’s AI Overview has
relayed their provider rankings as if the recommendation were ESA’s. We are
not linking the documents; the site: query in Sources reproduces the finding
in one click.
It is the second run of this playbook against a European public institution in
thirteen months — ESA is intergovernmental rather than an EU body, but the
ranking signal a spammer borrows does not care about the distinction. In July
2025 Eurostat was hosting near-identical PDFs funnelling to an
IPTV storefront at portugueseiptv[.]pt; the Commission pulled them once
alerted and the URLs left the index. Google’s spam policies name the mechanic,
and it is not the fashionable one:
hacked content
— “any content placed on a site without permission, due to vulnerabilities in
a site’s security” — as distinct from site reputation abuse, where a host
knowingly rents out ranking it earned with its own work. That distinction
decides who you write to and what you ask for.
Why it matters
The asset being stolen is institutional trust, and it now converts straight into machine answers rather than just blue links. A brand owner meets this from one of two ends: your trademark is the bait — Roblox and Coin Master are both named in these files — or your own domain is the unwitting host.
Counsel’s note
Take the first position. If your brand is named in a file like this, your counterparty is not the spammer. It is the institution whose infrastructure is serving the file, and then Google. The leverage is in the framing: the upload was unauthorised, so this is a security incident on their estate, not an editorial dispute about a third party’s content. Sent to a security or abuse contact in those words it gets escalated; sent to a general legal inbox as a trademark complaint it gets queued behind everything else.
Sequence the search side after the source, not alongside it. While the PDF still answers 200, there is nothing for Google to correct — the Refresh Outdated Content tool works on pages you do not own only once the content is gone or materially different. Removal at source first, index flush second, and if the material reached an AI Overview, expect the generated answer to lag the index it was built from. Capture the evidence before any of that: once ESA deletes the file, your proof of what a government-grade domain was telling searchers about your brand deletes with it.
Now the second position, because it is the one nobody budgets for. Any
document library that couples editor upload with public direct-URL serving is
a publishing surface, whatever your CMS calls it.
A site:yourdomain.com filetype:pdf sweep takes a minute to run. The day it returns words you never
published, you have a hacked-content problem with your own ranking as the
payload — and your brand becomes the endorsement in a stranger’s AI answer.
For our verticals the economics are the point. Affiliate commission drives
these drops, and the crews running “top 10 IPTV 2026” run “best casino 2026”
and “top broker 2026” from the same infrastructure. When your licensed brand
turns up in an unlicensed affiliate’s ranking hosted on an .int, .edu or
.gov, you are holding two problems at once: unauthorised affiliate use of
the mark, and marketing of your brand into jurisdictions where you do not hold
a licence — with an institutional domain lending it credibility you would
never have bought.
What this means for you
Run site:yourdomain.com filetype:pdf today, and set a monitor for your brand
name plus filetype:pdf on domains you do not control. If your mark is the
bait, preserve the evidence, report it to the host as a security incident, and
only then chase the index — our guides on
content feeding AI Overviews
and affiliate abuse of your brand
cover the mechanics, and our operators page sets out how we run
the monitoring that catches the next drop.