THE SIGN
← Back to Media

Space Cyber Threats Are Mostly Seen From the Ground. The Orbit Is a Blind Spot

How much cyber activity really targets the space sector? The Center for Security Studies (CSS) at ETH Zurich set out to answer that in its new study, Space Cyber Threat Intelligence: Threat Landscape Report 2025 by Clémence Poirier. The open-source assessment documents 407 cyber incidents in 2025, hitting 183 space-related organisations. A total of 139 threat actors were behind them.

Space Cyber Threats Are Mostly Seen From the Ground. The Orbit Is a Blind Spot

A wide target set

The victims span the whole ecosystem: commercial, governmental, civilian and scientific. Companies made up 72% of targets and space agencies 21%. The most hit were Israeli defence and space firms Elbit Systems and Rafael, Ukraine's Antonov, and NASA.

Activity followed conflict closely. The peaks were tied to the war in Ukraine, India-Pakistan tensions, and the conflicts involving Iran and in Gaza.

Noisy hacktivists, quieter heavy hitters

Most identified actors were hacktivist groups. DDoS attacks were 61% of all incidents (247 cases). They were mostly short website disruptions that did not affect space operations. No group focuses only on space. Many firms appear on target lists simply because a campaign is aimed at their country.

The report warns against reading this as proof that hacktivists are the main danger. Stakeholders interviewed for the study see state actors as the real concern. Those operations rarely become public. The study also notes that hacktivist groups increasingly coordinate with states, which makes attribution harder.

Ransomware, data and people

Ransomware accounted for 52 incidents (12.8%) from 29 groups. None touched an actual satellite. The hardest hit were suppliers of components, materials and services, not space operators. Data breaches, leaks and sales made up nearly 15% of incidents.

Personal data of staff and customers is leaking more often. At least 15 incidents exposed personnel data, sometimes with threats against employees. As ICEYE's CISO Andrew Newson put it, an attacker wanting to damage a space company would probably go after key people rather than a satellite.

The blind spot above us

Here is the study's most important finding. About 93% of incidents hit the IT environment of space organisations on the ground. Almost none were reported against satellites in orbit. That does not mean the space segment is safe.

Most satellites carry no on-board detection sensors, so attacks against them are largely invisible. No telemetry means no indicators of compromise, and no space-specific intelligence to feed back into defence. The 407 incidents are a fraction of what actually happens.

From obscurity to transparency

The sector once relied on secrecy. New Space, with commercial off-the-shelf components, open-source software and public filings, has ended that model. Openness has not been matched by better visibility.

The study points to emerging fixes: the SPARTA threat framework for spacecraft, on-board detection systems, and better information sharing through bodies such as Space ISAC. That group reported a 118% rise in publicly reported space incidents in 2025 compared with 2024.

Conclusion: Space needs its own threat intelligence, from on-board sensors to trusted sharing. Until then, the quiet in orbit says little about safety.

Author: Clémence Poirier

Source: "Space Cyber Threat Intelligence: Threat Landscape Report 2025." CSS Study No. 6, Center for Security Studies, ETH Zurich, September 2026.

Every month, THE SIGN and CyberInflight bring you 10 to 20 standout stories shaping the cyber space landscape — from emerging threats and geopolitical shifts to market moves, breakthrough technologies, conferences, trainings, and the latest regulations. Whether you're a threat hunter, strategist, tech enthusiast, or simply cyber-curious, you'll find the insights that matter most. Read September 2026 overview. Exclusively for THE SIGN.

Read the original →

The SIGN Newsletter

Trusted space
cybersecurity ping,
direct to your inbox.

No noise. Field analysis, expert op-eds and sector signal — once a week.

GDPR-compliant. We never share your data.