Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Maxar Space Systems disclosed that an attacker accessed a system containing files with employee personal information in October 2024. The reported breach date was October 4; Maxar said it discovered the intrusion on October 11. The company described the incident as limited to one external-network host, but the publicly available account does not establish how many people were affected or why the attacker accessed the files.

What happened in the Maxar breach?

State notices record October 4, 2024, as the breach date for Maxar Space LLC and Maxar Space Robotics LLC. Maxar told SecurityWeek it discovered the intrusion on October 11 and took immediate action to prevent further unauthorized access. The company said the actor likely had access to the files for approximately a week; that is an estimate, not a precisely measured period. Massachusetts’ November 15, 2024 notice and the California Attorney General’s breach listing document the reported date. SecurityWeek published its account on November 19, 2024.

What employee information may have been exposed?

SecurityWeek reported that some files on the accessed system contained employee personal information. Potentially affected details included names, physical addresses, gender, Social Security numbers, business phone numbers and other business contact information, employment status, employee numbers, job titles, supervisors, departments, and related employment information. The public notices do not provide a confirmed person-by-person inventory, so these details should be understood as potentially compromised, not as confirmed for every affected person.

Maxar’s notice, as quoted by SecurityWeek, said: “These files did not contain any bank account information or dates of birth.” Massachusetts’ notice says the company notified affected people, informed law enforcement, and retained an outside third party to investigate and confirm that the circumstances enabling unauthorized access had been eliminated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which Maxar systems were reportedly involved?

Maxar told SecurityWeek that the incident was limited to Maxar Space Systems, its satellite-manufacturing business in Palo Alto, California. The company said the attacker accessed a single host on an external demilitarized network, which was not connected to the internal network, and that Maxar Intelligence employees were not affected. These are company-reported boundaries; the public sources do not independently audit the network or verify them technically.

That reported scope does not establish that Maxar’s satellite operations or Maxar Intelligence were compromised. Nor does it establish that the attacker tried to reach those systems. CSIS’s Space Threat Assessment 2025 says the public record does not show whether employee information was the attacker’s objective or whether accessing it was an initial step toward other Maxar systems. The available sources do not establish espionage, a sale of the data, ransomware, or an attempted satellite-system compromise.

How many employees were affected?

Maxar had not disclosed an affected-employee count in TechCrunch’s November 18, 2024 report. The state notices and other cited accounts do not establish a total, so no reliable public figure can be given here.

TechCrunch also reported that the IP address used in the attack was associated with Hong Kong, while cautioning that it could belong to a server used to obscure the attacker’s location. That detail does not prove the attacker was physically in Hong Kong.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What was the Maxar data-breach settlement?

In Re: Maxar Data Security Litigation, Case No. 24CV452108, is a proposed class settlement in the Superior Court of California, County of Santa Clara. The settlement materials describe allegations that a targeted cyberattack occurred in October 2024 and files containing private information were accessed. They also state that Maxar denies wrongdoing and the Court had not decided who was right. A proposed settlement is not a court finding that Maxar was liable.

The settlement site described the proposed class as living U.S. residents whose personally identifiable information was potentially compromised, including people who received a breach notice, subject to exclusions listed on the official site. Its stated claim deadline was July 16, 2026, which has passed. The official settlement FAQ and claim form page described these proposed benefits and conditions:

  • Three years of credit monitoring with $1 million in identity-theft protection for eligible claimants.
  • Up to $3,500 for qualifying documented expenses.
  • Up to four hours of lost-time compensation at $20 per hour, subject to the settlement’s stated combined cap.
  • An expected $100 CCPA payment for eligible California residents, potentially reduced pro rata.

These were proposed settlement terms, not guaranteed payments. The settlement site’s search result listed a final approval hearing for September 24, 2026, and said the Court still had to decide whether to approve the agreement. That information predates the hearing; the sources available here do not establish whether approval was granted afterward or whether benefits are being distributed. Consult the official settlement site for any later administrator or court update.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.