{"id":202121,"date":"2025-10-15T15:55:16","date_gmt":"2025-10-15T15:55:16","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/202121\/"},"modified":"2025-10-15T15:55:16","modified_gmt":"2025-10-15T15:55:16","slug":"leak-from-the-sky-it-turns-out-a-lot-of-satellite-data-is-unencrypted","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/202121\/","title":{"rendered":"Leak From the Sky: It Turns Out a Lot of Satellite Data Is Unencrypted"},"content":{"rendered":"<p>A\u00a0security blind spot has been revealed in the skies above us. A team of researchers has discovered that a surprising amount of data transmitted to orbiting satellites is unencrypted, potentially paving the way for eavesdropping on communications from mobile carriers, as well as military and government users.\u00a0<\/p>\n<p>The issue doesn\u2019t affect SpaceX&#8217;s <a href=\"https:\/\/www.pcmag.com\/reviews\/starlink-dish-v4-and-router-gen-3\" target=\"_self\" rel=\"nofollow noopener\">Starlink<\/a>, but data sent to higher orbiting geostationary satellites, which can also provide communications to mobile carriers, commercial buildings, and government users in remote and rural areas. A team from the University of California, San Diego, and the University of Maryland investigated whether such satellite signals were encrypted, as the same signals can be easily intercepted over the air using consumer-grade dish equipment costing around $800.\u00a0<\/p>\n<p>It turns out that a large swath of geostationary satellite data is unencrypted over North America, the researchers wrote in a <a href=\"https:\/\/satcom.sysnet.ucsd.edu\/docs\/dontlookup_ccs25_fullpaper.pdf\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"nofollow noopener\">paper<\/a> published on Monday. \u201cWe found 50% of GEO links contained cleartext IP traffic&#8230; The severity of our findings suggests that these organizations do not routinely monitor the security of their own satellite communication links.\u201d<\/p>\n<p>The results also shocked the team of researchers, <a href=\"https:\/\/www.wired.com\/story\/satellites-are-leaking-the-worlds-secrets-calls-texts-military-and-corporate-data\/\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"nofollow noopener\">according<\/a> to Wired, which noted the surveillance gap is so glaring that it\u2019s possible foreign intelligence agencies or other bad actors might be exploiting the unencrypted satellite data for spying.\u00a0<\/p>\n<p><img decoding=\"async\" src=\"data:image\/svg+xml,%3Csvg%20xmlns=\" http:=\"\" class=\"\" data-image-loader=\"https:\/\/i.pcmag.com\/imagery\/articles\/01aqQHXlIHXHjEUxEPt2AoK-3.jpg\" data-lazy-sized=\"\" alt=\"satellite data\" data-image-path=\"articles\/01aqQHXlIHXHjEUxEPt2AoK-3.jpg\"\/><\/p>\n<p>\n    (Credit: Research paper)\n<\/p>\n<p>Researchers monitored radio signals to 39 geostationary satellites from \u201ca single vantage point\u201d in La Jolla, California, using a standard satellite dish. They saw \u201cunencrypted cellular backhaul traffic from several providers, including cleartext call and text contents, job scheduling, and industrial control systems for utility infrastructure, military asset tracking, inventory management for global retail stores, and in-flight Wi-Fi.\u201d<\/p>\n<p>The researchers traced the exposed satellite signals to companies such as T-Mobile, noting the recovered data included user SMS and voice call contents, user internet traffic, and cellular network signaling protocols. &#8220;From a 9-hour recording, we observed 2,711 users\u2019 phone numbers from metadata associated with voice calls and messages,\u201d the paper adds.\u00a0<\/p>\n<p>        <img decoding=\"async\" class=\"opacity-20 absolute right-0 top-0 z-0 hidden md:block\" src=\"https:\/\/www.pcmag.com\/images\/newsletter-envelope.svg\" alt=\"Newsletter Icon\" style=\"max-width:220px; max-height:140px; pointer-events:none;\"\/><\/p>\n<p>            <img decoding=\"async\" class=\"opacity-20 h-full w-full\" src=\"https:\/\/www.pcmag.com\/images\/newsletter-envelope.svg\" alt=\"Newsletter Icon\"\/><\/p>\n<p>\n            Get Our Best Stories!\n        <\/p>\n<p>                                    Stay Safe With the Latest Security News and Updates<\/p>\n<p>                                                    <img decoding=\"async\" class=\"h-auto w-full rounded-md object-cover md:rounded-l-md\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/07\/17707707-contextual.fit_lpad.size_250x140.v1750711966.png\" alt=\"SecurityWatch Newsletter Image\"\/><\/p>\n<p>Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.<\/p>\n<p>Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.<\/p>\n<p class=\"roboto-flex mt-2 text-xs font-normal leading-tight text-black md:whitespace-nowrap\">\n                        By clicking Sign Me Up, you confirm you are 16+ and agree to our <a class=\"underline\" href=\"https:\/\/uk.pcmag.com\/terms\" rel=\"nofollow noopener\" target=\"_blank\">Terms of Use<\/a> and <a class=\"underline\" href=\"https:\/\/uk.pcmag.com\/privacy\" rel=\"nofollow noopener\" target=\"_blank\">Privacy Policy<\/a>.\n                    <\/p>\n<p class=\"text-green-500 mt-2 text-xl font-bold\">Thanks for signing up!<\/p>\n<p class=\"mt-2\">Your subscription has been confirmed. Keep an eye on your inbox!<\/p>\n<p>In T-Mobile&#8217;s case, the carrier was likely using the geostationary satellites as &#8220;<a href=\"https:\/\/www.pcmag.com\/encyclopedia\/term\/backhaul\" target=\"_self\" rel=\"nofollow noopener\">backhaul<\/a>&#8221; for cell towers based in remote areas. <\/p>\n<p>In another alarming find, the team was able to collect unencrypted satellite data \u201cfrom sea vessels owned by the US military,\u201d along with traffic from multiple organizations within the Mexican government and military, including personnel records, narcotics activity, and military asset tracking. Other unencrypted satellite traffic was traced to\u00a0\u201cWalmart-Mexico\u201d and \u201cAT&amp;T Mexico.\u201d<\/p>\n<p>The good news is that most of the affected parties, including T-Mobile and AT&amp;T, have resolved the issue by implementing encryption. T-Mobile also told us the scale of the issue was small.&#8221;This is not network-wide \u2013 it was less than 0.10% of sites, all in very isolated, low-population areas and carry low traffic. We worked with the vendor to quickly solve the misconfiguration, and we implemented SIP encryption,&#8221; the carrier said. <\/p>\n<p>But others have yet to roll out a fix, despite warnings from the researchers, Wired reports.<\/p>\n<p>Other researchers have also examined intercepting satellite traffic, but low signal quality has been a barrier, which may have mitigated the threat in the past to some extent.\u00a0But the researchers were able to overcome this problem by developing a method that can \u201caccurately gather raw data from hundreds of transponders\u201d on board orbiting satellites. The team has since released their method on GitHub to push more satellite owners to encrypt their data.\u00a0<\/p>\n<p>Their paper adds: \u201cThe vulnerability that we found does not affect T-Mobile\u2019s new Low-Earth Orbit Starlink deployment,\u201d also known as <a href=\"https:\/\/www.pcmag.com\/news\/tmobile-cellular-starlink-tsatellite-launch-everything-you-need-to-know\" target=\"_self\" rel=\"nofollow noopener\">T-Satellite<\/a>. SpaceX says it uses the \u201cISO\/IEC 27001\u201d\u00a0 <a href=\"https:\/\/www.iso.org\/standard\/27001\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"nofollow noopener\">framework<\/a> for data security, which <a href=\"https:\/\/www.isms.online\/iso-27001\/annex-a-2022\/8-24-use-of-cryptography-2022\/#:~:text=ISO%2027001:2022%20Annex%20A%208.24%20emphasises%20that%20organisations%20should,external%20providers%20of%20cryptographic%20services.\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"nofollow noopener\">includes<\/a> using cryptography to protect data in transit.\u00a0<\/p>\n<p>        About Our Expert<\/p>\n<p>                                                            <img decoding=\"async\" class=\"size-[60px] shrink-0 overflow-hidden rounded-full bg-gray-100 ring ring-white\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/09\/06W4G6A5rmg4LxEffqKnnc6.fit_lim.size_100x100.v1560221550.png\" alt=\"Michael Kan\"\/><\/p>\n<p>Michael Kan<\/p>\n<p>Senior Reporter<\/p>\n<p>Experience<\/p>\n<p>I&#8217;ve been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I&#8217;m currently based in San Francisco, but previously spent over five years in China, covering the country&#8217;s technology sector.<\/p>\n<p>Since 2020, I&#8217;ve covered the launch and explosive growth of SpaceX&#8217;s Starlink satellite internet service, writing 600+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite-based mobile service. I&#8217;ve combed through FCC filings for the latest news and driven to remote corners of California to test Starlink&#8217;s cellular service. <\/p>\n<p>I also cover cyber threats, from ransomware gangs to the emergence of AI-based malware. Earlier this year, <a href=\"https:\/\/www.pcmag.com\/news\/did-avast-sell-your-data-heres-how-to-get-a-piece-of-the-ftc-settlement\" target=\"_self\" rel=\"nofollow noopener\">the FTC forced Avast<\/a> to pay consumers $16.5 million for secretly harvesting and selling their personal information to third-party clients, as revealed in my joint <a href=\"https:\/\/www.pcmag.com\/news\/the-cost-of-avasts-free-antivirus-companies-can-spy-on-your-clicks\" target=\"_self\" rel=\"nofollow noopener\">investigation<\/a> with Motherboard.<\/p>\n<p>I also cover the PC graphics card market. Pandemic-era shortages <a href=\"https:\/\/www.pcmag.com\/news\/i-camped-out-at-best-buy-to-get-an-rtx-3000-graphics-card-feel-my-pain\" target=\"_self\" rel=\"nofollow noopener\">led me to camp out<\/a> in front of a Best Buy to get an RTX 3000. I&#8217;m now following how President Trump&#8217;s tariffs will affect the industry. I&#8217;m always eager to learn more, so please jump in the comments with feedback and send me tips.<\/p>\n<p>                                        <a class=\"w-fit self-end text-base font-bold uppercase leading-none underline\" data-module=\"author-bio\" data-element=\"read-full-bio\" data-item=\"text_link\" data-position=\"1\" href=\"https:\/\/uk.pcmag.com\/authors\/michael-kan\" aria-label=\"Michael Kan &#039;s Full Author Bio\" x-track-ga-click=\"\" rel=\"nofollow noopener\" target=\"_blank\"><br \/>\n                        Read Full Bio<br \/>\n                    <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"A\u00a0security blind spot has been revealed in the skies above us. A team of researchers has discovered that&hellip;\n","protected":false},"author":2,"featured_media":202122,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23],"tags":[90,416,56,54,55],"class_list":{"0":"post-202121","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-space","8":"tag-science","9":"tag-space","10":"tag-uk","11":"tag-united-kingdom","12":"tag-unitedkingdom"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/202121","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=202121"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/202121\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/202122"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=202121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=202121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=202121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}