Our satellites are in danger. As pieces of critical infrastructure, they support connectivity over vast distances, covering everything from remote wind farm monitoring to ensuring GPS connectivity for even the most isolated locations.

Amidst it all is data. Data so critical that nation-states fear for the resilience of their satellite networks, as the sort of data that is transmitted—such as military asset positioning—invites the undue attention of bad actors, especially nation-aligned attackers.

So why, then, have researchers from UC San Diego and the University of Maryland found satellites with unencrypted communications, easily recorded by terrestrial devices? Are our satellites that unsecure, or is there more to it? Let’s find out.

Key points of this article:

  • Satellites augment the way people live their lives. GPS, remote connectivity, and imaging are the modern trifecta of useful satellite tech.
  • Satellites are also useful for more covert agendas as a source of intelligence, all without requiring expensive equipment, as demonstrated by researchers from UC San Diego and the University of Maryland.
  • Unsecure satellite networks could expose critical datasets such as defense monitoring and equipment status, calls, texts, or even communications by and to critical infrastructure such as gas or oil platforms.
  • The exposure of these comms could prove to undermine national security and play a role in further cyber or physical attacks, with large-scale consequences.
  • Therefore, security should be applied at three levels: satellite hardware, the link layer, and ground infrastructure.

Satellites: The all-seeing eyes

To what degree do we really depend on satellite connectivity? The answer is right there in our pockets. Most modern phones use a form of location-tracking for various purposes, which is enabled by the Global Positioning System (GPS) and cell signal reception. Both of those depend on satellites. Yes, even cellular networks, in remote locations, use satellites to enhance coverage. This also includes functionality for everything from location-based marketing and city maps to sports watch integrations and performance analysis.

We probably don’t need to expound on GPS, the basis of which is satellite-supported tracking, so that Joe won’t get lost while visiting the Ardennes during his European holiday…which he might have selected based on a quick glance on Google Earth/Maps. And those crisp overhead views? Provided by NASA’s Landsat or ESA’s Sentinel satellites.

Communication, tracking, and imaging…a surveillance trinity, wouldn’t you agree? All part of “all-source intelligence”—an umbrella term for the fusion of multiple intelligence disciplines to create a comprehensive picture. While it’s one thing when your respective intelligence agency has access to these sources (another Pandora’s box), it’s completely different when a malicious actor does.

Critical lines exposed

What researchers from UCSD and UMD found with just $800 worth of off-the-shelf equipment underscores the appealing nature of our “all-seeing eyes.” By pointing their own receivers at the Southern Californian sky, they caught alarmingly sensitive transmission of data: everything from samples of call and text comms to airline Wi-Fi browsing data, and on to communications from critical infrastructure (electric utilities, offshore oil and gas platforms)—and even extremely sensitive military data, such as asset tracking or maintenance records.

No catch here—all this data was being transmitted over the air and unencrypted. Just from a small number of satellites around San Diego. Who knows what more lies out there?

Man in the middle

What the researchers employed in their experiment is a known quantity in the cybersecurity world, also understood as an adversary-in-the-middle (AitM) or man-in-the-middle (MitM) attack technique. In short, an attacker stands between a sender of some data points (let’s say a person browsing the internet on public Wi-Fi) and the Wi-Fi router, or they pretend to be a public hotspot.

The result is the capture of any outgoing connections from a victim’s device, unless they’re being masked by an encrypted VPN tunnel, for example. Hence the researchers highlighting the freely flowing nature of the observed satellite traffic, without any measures to mask it.

Satellite in the middle?

Recently, ARS Technica reported on a story by European security officials, who claimed that two Russian space vehicles had intercepted the communications of multiple significant satellites. Officials say that this poses an inherent risk to sensitive data being transmitted via these satellites, but also to other relevant hardware-specific data that could potentially enable sabotage.

Compared to scientists, bad actors use AitM attacks for espionage or credential collection, later to be used in other criminal schemes such as account theft and resultant internal spearphishing and the like. What does this have to do with satellites? Quite a lot, in fact.

Satellites, APTs, and nation states

When, on the eve of the Russian aggression against Ukraine in February 2022, multiple internet connection-providing Viasat satellites were disrupted, knocking out satellite internet across Europe, experts voiced a stark warning: war’s no longer just an earthly phenomenon, as cyber and space were now in play as well.

Putting a stamp on this new reality was the U.S.’s establishment of its Space Force and NATO’s aim to designate space as a new frontier in defense. The European Union also sees space security as key to ensuring its freedoms.

Despite this, with around 18,614 active satellites (that we know of) around the world, are those that ensure critical connectivity up for grabs? The researchers in the referenced study were also baffled by this, as well as by the continued inaction of some of the companies and organizations they had contacted to close this apparent security gap.

It’s all out there

Now, what precludes other, friendly or less friendly actors from having the same, if not more advanced, setup to snoop on unencrypted over-the-air data? Not much. In fact, since spy satellites are a thing, we can be sure that the researchers were already late to the party.

For a threat actor, data is gold. Therefore, having free access to data comms is worth any initial investment. It’s not unlikely that exploiting said comms could give an adversary a leg up during a conflict, or help to enhance covert ops.

Defending satellites’ most wanted

So how can this particular vulnerability be addressed? The answer, by now, should be obvious: encryption. This simple but powerful security method can mask long-distance comms, since in the case of satellites, their downlinks’ wide geographic exposure, despite a limited directional feeder/laser link scope, exacerbates problems with both AitM and MitM, or similar data capture methods.

A good example to follow regarding concrete satellite security steps would be NIST IR 8401.

In simpler terms, you can catch public radio almost anywhere, but you still need the right equipment and frequencies to tune in. However, encryption might not solve everything, as there are other most wanted items to consider and protect:

1. The satellite itself

The most immediate consideration is that satellites have a service life of several years (five to 30 on average), meaning that the underlying technology can be described as legacy. From a cybersecurity perspective, this presents ripe ground for vulnerabilities, as while the surface below develops new adversarial tactics, the old hardware remains stagnant and unsecured, unless it’s a) pulled from orbit, or b) upgraded in flight, which is unlikely.

2. The link segment (uplink & downlink)

This really doesn’t need much explanation. Uplinks (data to satellites) and downlinks (data from satellites), the latter of which is heavily featured in this blog, should be enough of a warning why these signals need to always be secured. Uplinks could be abused to issue commands; jamming can endanger critical activities (such as battlefield movement) while downlinks could be snooped on. In all cases, encryption would be the main protective method.

3. Ground infrastructure

Uplinks and downlinks are maintained by hardware and personnel on the ground. This includes mission control centers, antennas, radio frequency (RF) terminals, network infrastructure, and facilities, as well as the software they use.

What we’re discussing is a complex mix of interconnected systems that are the primary points of contact for satellites, the compromise of which could have catastrophic consequences, such as power disruptions due to the outage of satellite-connected wind turbines, for instance. And since at this point we’ve got the human angle involved as well, the attack surface considerably expands, as the human element is the leading cause of a majority (62%)1  of data breaches.

Problematically, there’s not a one-size-fits-all approach that could be applied. Instead, look for custom, private security solutions that can be designed with such a scattered, yet centralized (through command centers) infrastructure in mind.

What about the users?

An easily overlooked variable would be the users enjoying the benefits of satellite connectivity. Again, these could be just regular people browsing the internet, but also the means by which they connect: via satellite dishes, modems, phones, and more.

Manipulation at this level could distort their output even if ground facilities are secure—leading to unlawful eavesdropping, for example, or in the case of critical systems, their potential disruption. But this area is incredibly broad, and overall, most topics on the ESET Blog address it, one way or another.

Orbit secured

Satellites make a thousand miles look like a hundred feet. Or less. Their usefulness works both ways, though, giving space for malicious agendas. Moreover, the complexity of their infrastructure and an M.O. that can’t shake the bonds of software and related hardware plus operational technology that (largely) becomes legacy upon launch just worsens the situation.

However, human ingenuity knows no bounds, and simple solutions like encryption to protect uplink/downlink comms, as well as proprietary cybersecurity solutions on the ground, might be just what the doctor ordered.

FAQ: Satellite security

Why is satellite cybersecurity important?

Satellite cybersecurity matters because satellites support services we rely on every day, from GPS and remote connectivity to critical infrastructure monitoring. If those systems transmit sensitive data without proper protection, attackers may be able to intercept communications that were never meant to be public.

Can satellite communications be intercepted?

Yes. As recent research has shown, some satellite communications can be passively recorded with relatively inexpensive equipment if the transmissions are unencrypted. That makes satellite downlinks especially attractive to spies, cybercriminals, and nation-aligned threat actors looking for exposed data.

What kind of data can be exposed through insecure satellite links?

Insecure satellite links can expose far more than casual internet traffic. Depending on the system, leaked data may include calls, texts, browsing activity, corporate communications, industrial control traffic, equipment status, and even military or government-related information.

How can satellite communications be protected?

Encryption is the clearest first step, especially for uplinks and downlinks carrying sensitive data. But satellite security also depends on protecting onboard systems, hardening ground stations, authenticating commands, monitoring for anomalies, and securing the people and devices connected to the wider satellite ecosystem.

Are satellites part of critical infrastructure?

Yes. Satellites support navigation, communications, emergency response, energy operations, transport, defense, and remote industrial systems. That makes satellite security a national resilience issue, not just a space-sector concern.

1Verizon. (2026). 2026 Data Breach Investigations Report (p. 20). Verizon Business. Retrieved from: https://www.verizon.com/business/resources/reports/dbir/.