A Cyberattack Has Knocked the World's Meteor-Tracking Nonprofit Offline
Key takeaways
- A nonprofit meteor-tracking organisation has been taken offline by a cyberattack described as a 'critical blow'
- The group expects to be largely out of commission for several weeks
- Small nonprofits are disproportionately vulnerable due to limited IT budgets and older infrastructure
- Scientific institutions including the British Library and major universities have faced similar prolonged ransomware disruptions in recent years
A nonprofit organisation that provides one of the most widely used systems for tracking meteors and fireballs has been taken offline by a cyberattack, and according to Ars Technica, the group expects to be largely out of commission for several weeks. The organisation described the attack as a 'critical blow' to its operations.
This is an unusual target, and that is part of what makes it worth paying attention to.
What Meteor-Tracking Networks Actually Do
Meteor-tracking networks are not glamorous infrastructure, but they serve a real scientific purpose. Networks of camera stations and sensors around the world continuously monitor the sky for incoming meteors, fireballs, and bolides. When a significant event occurs, the data from multiple stations can be triangulated to determine the trajectory of the object, its speed, and in some cases where fragments might have landed. This is how recovery teams locate meteorites after significant falls.
Beyond the scientific value, there is an early warning dimension. Networks like this contribute data to the broader effort to understand how frequently significant objects enter Earth's atmosphere and from which directions. That data feeds into planetary defence research, including the work of organisations like NASA's Planetary Defense Coordination Office and the European Space Agency's Space Safety Programme.
The specific organisation affected has not been fully named in the initial reporting, but the scale of the disruption, several weeks offline with the description of 'critical blow', suggests that the attack compromised core infrastructure rather than just taking down a website. Ransomware is the most common mechanism for this kind of prolonged takedown.
Why Would Anyone Attack a Meteor Tracker?
This is the question that almost everyone's first instinct is to ask, and the honest answer is that it probably was not specifically targeted. Most ransomware attacks are opportunistic. Attackers scan for vulnerable systems, find ones with poor patch levels or misconfigured remote access, and deploy their payload regardless of what the organisation does. Small nonprofits are consistently among the most vulnerable targets because they typically have limited IT budgets, older infrastructure, and no dedicated security staff.
Meteor-tracking networks often rely on distributed volunteer observers and academic partnerships. The technical infrastructure underlying them may not be maintained to the same standards as commercial or government systems. That makes them easy targets, even if they are not obviously valuable ones.
The ransom demand angle is worth noting. Even a relatively modest ransom demand is difficult for a small nonprofit to absorb, and the alternative, rebuilding from scratch, is exactly the kind of prolonged disruption the group described. The weeks-long recovery timeline suggests either that backups were inadequate, that the backups themselves were compromised, or that the rebuild involves significant volunteer effort without commercial IT support.
The Broader Pattern
This incident fits into a much larger trend. Scientific and academic institutions have been disproportionately hit by ransomware over the past three years. Universities, research hospitals, natural history museums, and now at least one meteor-tracking nonprofit have all found themselves dealing with attacks that disrupted genuine public-interest work. The Kronos ransomware attack in 2021 disrupted payroll systems at dozens of universities. The British Library was taken largely offline for months after a 2023 attack. The Royal British Legion was hit in 2024.
The common thread is that these organisations hold data that someone has to care enough to restore, making them viable ransom targets, while simultaneously having cybersecurity postures that lag significantly behind their commercial peers.
For meteor tracking specifically, the weeks-long gap in data is a real loss. It does not mean we are going to miss an incoming object of any significance, as there are multiple overlapping systems globally. But it does mean a period of reduced coverage for what is genuinely important scientific work.
The incident is also a reminder that critical scientific infrastructure, however unglamorous, needs the same security investment as any other system. A meteor-tracking network going offline for weeks because of an opportunistic ransomware attack is not an acceptable state of affairs, even if it does not make front-page news in the way a hospital attack would.