Kaspersky warns space systems face growing cyberattack risk
Kaspersky has used this week's GISEC 2026 conference in Dubai to release a detailed threat intelligence report arguing that space infrastructure has become a high-value and systematically under-secured attack surface. The report, produced by the company's ICS CERT team, draws on publicly available incident data spanning from 1957 to the early 2020s, during which period more than 100 cyber incidents targeting space systems were recorded.
The central argument of the report is that a "space system" is no longer simply a satellite in orbit. Ground control stations, terrestrial communication links, user terminals and third-party software suppliers each represent a link in the chain, and attackers frequently target whichever link is most accessible rather than the most strategically obvious one.
Exposed receivers and APT activity
Among the most concrete findings, Kaspersky researchers audited internet-exposed Global Navigation Satellite System (GNSS) hardware in collaboration with 70 equipment vendors following a spike in GPS spoofing incidents in the Black Sea region in 2023. The audit identified more than 3,000 GNSS receivers that are directly reachable over the public internet and actively vulnerable to attack. The company identifies maritime, aviation and land logistics operators as carrying the greatest exposure.
The report also documents the sustained use of satellite infrastructure by Advanced Persistent Threat groups as a covert communications channel. APT clusters including Turla and Whitebear are cited as having hijacked unencrypted downstream satellite traffic throughout the 2010s to mask command-and-control activity. A more recent variant, AcidPour, discovered in 2024 and attributed to the Sandworm group, extends the reach of an earlier wiper malware to target Linux routers, satellite modems and data storage systems at scale. The 2022 AcidRain attack on Viasat's KA-SAT network illustrates the real-world cost: roughly 30,000 satellite terminals were disabled across Europe, and more than 5,800 wind turbines lost remote management connectivity as a secondary consequence.
Ekaterina Rudina, Security Analysis Expert at Kaspersky, said: "As satellite technology becomes deeper integrated into civilian life, from navigation systems to energy grids, securing these connections, enforcing encryption on downstream links, and patching vulnerable internet-exposed receivers is of highest importance."
Market and regulatory context
The report lands at a moment of significant commercial and geopolitical attention on satellite infrastructure. The proliferation of low Earth orbit constellations has expanded the attack surface considerably, introducing tens of thousands of user terminals globally, many running commodity hardware and firmware that receives infrequent updates. Critical national infrastructure operators in energy, transport and defence increasingly rely on satellite-based timing and positioning signals, making GNSS integrity a systemic risk rather than a niche concern.
From a regulatory standpoint, the EU's NIS2 Directive, which took effect in October 2024, explicitly includes space operators among entities subject to enhanced cyber resilience obligations in member states that designate them as critical infrastructure. In the UK, the National Cyber Security Centre has published guidance on operational technology security that applies to ground-segment control systems, though space-specific mandates remain less prescriptive than their counterparts in the energy or financial sectors. The US has moved further with Space Policy Directive 5, which establishes cybersecurity principles for space systems and has informed procurement requirements for government satellite programmes.
For enterprise buyers, particularly those in logistics, financial services and energy that depend on GNSS-derived timing, the practical near-term steps are consistent across frameworks: network-isolate receivers where possible, enforce encrypted communication links end-to-end, and apply vendor patches on a prioritised schedule. Kaspersky's recommendation to treat internet-accessible GNSS hardware as equivalent to any other internet-facing OT asset is well-aligned with zero-trust segmentation principles already widely adopted in industrial control system security.