Researchers from the University of Maryland and the University of California, San Diego have demonstrated that sensitive data transmitted via geostationary satellites can be intercepted using inexpensive, commercially available equipment. By passively scanning 39 satellites across 25 longitudinal points over a period of several months, the research teams were able to collect a significant amount of unencrypted data, including communications from the U.S. military, major telecommunications firms, and large businesses. The equipment used for these experiments cost as little as $600 to $800, making the attack vector accessible to individuals without significant resources or technical expertise. The intercepted data included thousands of T-Mobile users’ calls and text messages, as well as communications from airline passengers using in-flight Wi-Fi. Additionally, the researchers were able to access data related to critical infrastructure, such as electric utilities and offshore oil platforms, highlighting the broad scope of the vulnerability. The study revealed that roughly half of all geostationary satellite signals are transmitted without encryption, leaving them open to eavesdropping by anyone with the right equipment and knowledge. The researchers’ findings challenge the assumption that satellite communications are inherently secure or protected by default. The vulnerability is not limited to consumer data; military and corporate communications were also found to be at risk, raising concerns about national security and corporate espionage. The researchers emphasized that their work was conducted passively, without any active interference or exploitation of the satellites themselves, underscoring the ease with which such data can be collected. The study’s results have significant implications for the cybersecurity industry, telecom providers, and government agencies, as they expose a critical gap in the protection of sensitive information transmitted via satellite. The findings are expected to prompt urgent reviews of satellite communication security practices and may lead to calls for mandatory encryption of all satellite-borne data. The research also demonstrates that the threat is not theoretical; real-world data was collected and analyzed, proving the feasibility of large-scale interception. The exposure of unencrypted satellite communications could facilitate a range of malicious activities, from identity theft to the compromise of critical infrastructure. The study serves as a wake-up call for organizations relying on satellite links for sensitive communications, urging them to implement robust encryption and review their security postures. The ease and affordability of the attack method mean that not only nation-state actors but also criminal groups and hobbyists could exploit these vulnerabilities. The research has already sparked discussions within the cybersecurity community about the need for industry-wide standards and regulatory oversight to address the risks associated with unencrypted satellite transmissions.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
The team publicly reported that a significant share of geostationary satellite communications remained unencrypted and vulnerable to passive interception, and they presented their paper, "Don't Look Up," at an ACM conference in Taiwan. They also said they planned to release an open-source tool to help interpret satellite data.
The researchers' disclosure discussions with affected organizations continued through July 2025, covering multiple telecom, aviation-connectivity, satellite, and military-related entities. This marked the end of the notification window described in the reporting.
After being notified by the researchers, T-Mobile and AT&T said they moved quickly to remediate the exposed communications observed in the study. At the time of reporting, some critical-infrastructure operators still had not encrypted their traffic.
Using low-cost commercial equipment costing roughly $600 to $800, the researchers spent about seven months scanning 39 geostationary satellites and 411 Ku-band transponders. They collected plaintext and metadata tied to telecom, airline, industrial, law-enforcement, and military communications, showing that passive interception was feasible at low cost.
Researchers from UC San Diego and the University of Maryland started notifying affected organizations about unencrypted geostationary satellite traffic exposures. CyberScoop reports disclosure discussions with multiple entities, including the U.S. military and telecom and satellite providers, began in December 2024.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
schneier.com
Open sourcesecurityaffairs.com
Open sourcecyberscoop.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.