Iranian hackers are getting scarily personal. Top space industry CISOs say they’re seeing a surge in attacks that weaponize AI-cloned voices, fake SMS messages, and social engineering so precise it mimics internal company memos. The threat isn’t just to satellites—it’s to the people who control them.
The AI Voice Clone Nightmare
Vantor CISO Norm Laudermilch describes a new breed of attack: threat actors scrape public websites, build fake versions, then target suppliers with voice notes generated by AI. “Hi, this is Norm—we need to escalate privileges immediately,” the fake message says, mimicking a real executive’s voice. This isn’t sci-fi. It’s happening now, on WhatsApp, Signal, and SMS.
The attacks have jumped “100 times more prevalent since the war started,” Laudermilch says. Iranian actors are known for this. They listen to conference talks, capture audio, feed it into AI, and produce convincing fake commands. The goal? Trick employees into granting system access before anyone can verify.
Small, Silent Attacks Keep CISOs Up at Night
Telesat’s Asit Tandon says it’s not the big, dramatic breach that worries him—it’s the quiet ones. “Small, low-impact events that keep happening,” he notes. Meanwhile, the window between discovering a vulnerability and seeing it exploited has shrunk to almost nothing. Companies now need real-time intelligence partnerships just to keep pace.
Viasat’s Phil Mar adds that every new global conflict triggers an immediate spike in activity. The Viasat hack four years ago was an industry wake-up call. Since then, the focus has shifted from pure prevention to resilience—because, as Laudermilch puts it, “No security system is perfect.”
AI Opens a New Attack Surface—Inside the Code
AI isn’t just a tool for attackers. It’s also a new vulnerability. Tandon warns that AI models can be subtly manipulated. “Somebody can change the policy, and the model thinks it’s doing the right thing while giving wrong results,” he says. Space companies now have to protect not just their infrastructure, but the decision loops those AI systems run on.
SES’s Vinit Duggal sums it up: “Threat actors move at light speed. We’re all getting a little bit behind.” Engineering itself is being transformed—software engineers now spend more time running prompts than writing code. Cyber defense systems must become “AI aware,” says Mar, with clear escalation paths and no blind automation.
What This Means for the Future of Space Security
The industry is building smaller, more connected constellations—Telesat’s Lightspeed, for example. That brings built-in redundancy but also more interfaces, more software, and more attack surfaces. The solution? Cybersecurity by design, right from the start. No more bolting it on later.
Laudermilch sees an upside: mesh networks of smallsats can adapt in real time. If a threat actor on the ground launches RF attacks, the network can simply stop listening over that region and route commands through neighboring satellites. The next major incident is a matter of time, he admits. But the community is better prepared—and the best defense may be the network itself.
—
*Originally reported by [SatelliteToday Cyber](https://www.satellitetoday.com/cybersecurity/2026/04/12/top-space-cyber-execs-talk-increased-iranian-cyber-attacks/). Adapted and republished with editorial context for SpaceSecurityNews.*