Kaspersky’s industrial security unit warns that the real weak points in space systems sit on the ground. A new report from ICS CERT argues that control networks, communication links and subscriber receivers form the fragile foundation beneath every orbital mission.
Open-source tallies count more than 100 cyberattacks on space systems from the Sputnik era through the early 2020s. Analyst Ekaterina Rudina called out the weakest links: control networks, communication channels and subscriber receivers, which she argued form the fragile operational base of any space system.
More than 3,000 GPS receivers are sitting on the internet where attackers can reach them, according to an audit Kaspersky ran with 70 equipment vendors. The check followed the spoofing surge that hit the Black Sea region in 2023, and the findings put shipping, aviation and ground logistics at risk.
Adversaries have also learned to hide inside satellite traffic. In the 2010s, groups such as Turla and Whitebear hijacked unencrypted downstream links to route their command traffic, and modern groups like Thrip now target satellite operators and geospatial databases. The 2022 hack of Viasat’s KA-SAT network remains the reference case for how one misconfigured link can take down thousands of terminals.
Kaspersky recommends keeping GNSS receivers unreachable from the outside and enforcing strong authentication across ground infrastructure.