Executive Summary
In early 2025, researchers from the University of Maryland and UC San Diego revealed widespread leakage of sensitive and private data—including military and telecom communications—through unencrypted transmissions sent over geostationary (GEO) satellites. By using only $600 in commercially available equipment, the team passively intercepted vast amounts of plaintext data from major organizations, government entities, and telecom users around the globe. The incident highlighted fundamental lapses in network-layer encryption practices, allowing phone calls, SMS messages, internal application data, and even military vessel information to leak with no authentication or protection. The research further demonstrated that even technically unsophisticated actors could compromise critical satellite backhaul links using minimal resources.
This event underscores the urgent need for end-to-end encryption and robust monitoring of satellite communications as reliance on these channels increases and barriers to interception continue to fall. Government and industry must now address the rapidly evolving risk landscape, especially as critical infrastructure becomes more dependent on satellite connectivity.
Why This Matters Now
Organizations increasingly rely on satellite backhaul for remote connectivity, yet this incident exposes how easily unencrypted satellite traffic can be intercepted using inexpensive tools. With the cost and technical bar for eavesdropping lower than ever, failure to secure satellite links creates urgent risks for sensitive sectors, from telecom to government and defense.
Attack Path Analysis
The adversary employed low-cost, passive satellite signal interception to compromise organizations' communications at the network level. As these transmissions were largely unencrypted, attackers were able to immediately access sensitive data without further privilege escalation. No lateral movement within cloud or enterprise environments was necessary, as the data was intercepted in transit. Command and control was not established, but monitoring of large volumes of communications was ongoing. Exfiltration consisted of direct harvesting of sensitive plaintext data, including personal and operational information. Ultimately, this resulted in data leaks and exposure of critical information impacting privacy and national security.
Kill Chain Progression
Initial Compromise
Description
Attackers used inexpensive consumer satellite equipment to passively intercept unencrypted GEO satellite communications, targeting data in transit between remote endpoints and core networks.
Related CVEs
CVE-2024-12378
CVSS 9.1A vulnerability in Arista EOS affects secure Vxlan configurations, where sensitive network packets are transmitted in cleartext upon Tunnelsec agent restart, bypassing expected encryption.
Affected Products:
Arista Networks EOS – All versions prior to the patch
Exploit Status:
no public exploitReferences:
CVE-2013-6034
CVSS 9.8Firmware in Hughes Network Systems BGAN satellite terminals contains hardcoded login credentials, allowing unauthorized access.
Affected Products:
Hughes Network Systems BGAN Satellite Terminals – All versions prior to the patch
Exploit Status:
exploited in the wildReferences:
MITRE ATT&CK® Techniques
Exfiltration Over Physical Medium
Network Sniffing
Automated Exfiltration
Application Layer Protocol: Web Protocols
Man-in-the-Middle
Exfiltration Over C2 Channel
Data Capture: Traffic Duplication
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Render PAN Unreadable Anywhere It Is Stored
Control ID: 3.4.1
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA (Digital Operational Resilience Act) – ICT Risk Management - Security Measures
Control ID: Art. 9(2)
CISA ZTMM 2.0 – Encrypt Data In Transit
Control ID: Network and Environment - Encrypt Data in Transit
NIS2 Directive – Implementation of Technical and Organizational Measures
Control ID: Article 21 (2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Satellite data interception exposes unencrypted SMS, voice calls, and user traffic via Ku-Band transponders, requiring enhanced network-layer encryption protocols.
Defense/Space
Military vessel communications intercepted via satellite links reveal ship identities and logistics data, highlighting critical infrastructure encryption gaps.
Airlines/Aviation
In-flight Wi-Fi and aviation communications vulnerable to low-cost satellite interception, compromising passenger data and operational security systems.
Government Administration
Government satellite communications lack standardized IPSec encryption, enabling unauthorized access to sensitive administrative and infrastructure management systems.
Sources
- Researchers find a startlingly cheap way to steal your secrets from spacehttps://cyberscoop.com/researchers-scan-satellites-find-massive-corporate-military-data-leaks/Verified
- Study Finds Widespread Eavesdropping Risks in Geostationary Satellite Communicationshttps://www.cs.umd.edu/article/2025/11/study-finds-widespread-eavesdropping-risks-geostationary-satellite-communicationsVerified
- Study Reveals How an $800 Satellite Dish Captured Sensitive Communicationshttps://www.umiacs.umd.edu/news-events/news/study-reveals-how-800-satellite-dish-captured-sensitive-communicationsVerified
- Researchers Warn of Global Satellite Security Crisis After Capturing Unencrypted Military, Law Enforcement and Telecom Datahttps://www.hstoday.us/subject-matter-areas/cybersecurity/researchers-warn-of-global-satellite-security-crisis-after-capturing-unencrypted-military-law-enforcement-and-telecom-data/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Enterprise-grade Zero Trust network security controls—especially encrypted traffic enforcement, east-west segmentation, and egress policy—would have prevented attackers from reading sensitive data even when intercepting satellite communications. The disciplined use of encryption and microsegmentation at all network layers is essential to defend against passive interception risks in hybrid and satellite-backed infrastructures.
Control: Encrypted Traffic (HPE)
Mitigation: Prevents attacker from reading intercepted data.
Control: Zero Trust Segmentation
Mitigation: Reduces risk of sensitive internal data traversing vulnerable routes.
Control: East-West Traffic Security
Mitigation: Prevents exposure of intra-network communication.
Control: Multicloud Visibility & Control
Mitigation: Enables detection of anomalous unencrypted traffic patterns.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks or audits suspicious data flows leaving the environment unencrypted.
Minimizes overall risk and reduces blast radius for high-impact data leaks.
Impact at a Glance
Affected Business Functions
- Telecommunications
- Military Operations
- Critical Infrastructure Management
Estimated downtime: 7 days
Estimated loss: $5,000,000
Unencrypted satellite communications have led to the exposure of sensitive data, including personal calls and messages, military communications, and critical infrastructure information, posing significant security and privacy risks.
Recommended Actions
Key Takeaways & Next Steps
- • Perform a comprehensive audit of all satellite and hybrid network backhauls to mandate network-layer encryption (e.g., IPsec) on all data in transit.
- • Enforce Zero Trust microsegmentation and least privilege principles to ensure only necessary traffic is routed over vulnerable or external links.
- • Deploy visibility and anomaly detection tools that baseline traffic and alert for cleartext or unexpected flows, especially on satellite connections.
- • Apply egress policy enforcement to block or log any outbound data that is not encrypted or explicitly authorized per business requirements.
- • Regularly review and automate compliance checks using a Cloud Native Security Fabric to close segmentation and encryption gaps across multicloud environments.



