The space sector is experiencing a 400% surge in cyberattack activity following U.S. and Israel-led military operations in Iran, according to cybersecurity experts speaking on a CyberSat webinar.
Norm Laudermilch, chief information security officer at Vantor, said the tempo of attacks against the defense industrial base and adjacent aerospace sectors has intensified dramatically since the conflict began. Five Eyes cybersecurity agencies have separately warned that frontier AI models are transforming offensive cyber capabilities on a timeframe of months, not years.
Iranian state-sponsored groups have conducted a wave of operations. The IRGC-linked group Mobir claimed credit for attacks against Space42, Bayanarta, Thuraya, Yahsat, Arabsat and the UAE Space Agency. APT33, also tied to Iran’s Islamic Revolutionary Guard Corps, claimed to have stolen 375 terabytes of data from Lockheed Martin. The hacktivist group Handala, connected to Iran’s Ministry of Intelligence and Security, conducted personnel and doxxing attacks against Lockheed Martin employees in Israel.
Clémence Poirier, senior cyberdefense researcher at the Center for Security Studies at ETH Zurich, documented a shift in Iranian operations from the 2025 Israel-Iran war through Operation Epic Fury in February 2026. She described AI as a “double-edged sword” that accelerates both vulnerability discovery and exploitation.
Experts noted that while the spacecraft segment itself remains a difficult target, the ground segment and IT environments continue to be the most vulnerable entry points. The focus is shifting from prevention to containment and detection as AI-generated zero-day exploits become more common.