Researchers used $800 of off-the-shelf hardware to collect data sent by satellites unencrypted, like T-Mobile users' calls and texts and some US military comms
With just $800 in basic equipment, researchers found a stunning variety of data—including thousands of T-Mobile users' calls …
The reported intercepts matter because they put consumer communications and some military traffic within reach of low-cost receiving equipment when transmissions lack encryption, rather than requiring access to a carrier or data broker.
First-order effects
T-Mobile users whose calls and texts crossed the affected unencrypted satellite links face potential exposure of communications content; the reported sample also includes some US military communications.
The carriers, satellite-link operators, and relevant military users must identify which transmissions were sent without encryption and assess the affected communications paths.
Second-order effects
The finding raises the security bar for satellite-enabled mobile offerings: service partners will face pressure to demonstrate that new coverage features do not create a less-protected path than terrestrial networks.
Security researchers and attackers alike gain a clearer incentive to scrutinize inexpensive satellite-reception setups, making configuration and encryption practices a competitive and operational concern.
Third-order effects
If satellite connectivity becomes a routine extension of mobile service, transport security will need to be treated as an end-to-end property across terrestrial and satellite links, not a feature assumed from the handset or carrier brand.
The episode reinforces a broader shift in which communications risk is shaped by the weakest data path; whether it drives durable standards or oversight depends on providers' remediation and disclosure practices.
The trend: As mobile networks extend into satellite coverage, low-cost interception risks are making encryption across every transport layer a core trust requirement.
Rough summary: it turns out that many companies, ranging operators of in-flight WiFi to cellular towers to military data, are just sending plaintext to geostationary satellites. The downlinks are available to anyone with an inexpensive dish.
This work really helps to illustrate the role of public and academic security research. Yesterday there were people at satcos who knew these unencrypted links were dangerous, but weren't empowered to do anything about it. Now they will be.
Some genuinely weird corporate security speak here. These downlinks are broadcasting your WiFi data across the entire northern hemisphere. It is not equivalent to a coffee shop! [image]
With just $800 in basic equipment, researchers found a stunning variety of data—including thousands of T-Mobile users' calls and texts and even US military communications—sent by satellites unencrypted. https://www.wired.com/...
Time to un-embargo our @acm_ccs paper. We discovered that GEO satellites have been broadcasting a whole host of different kinds of traffic in the clear, including SMS and unencrypted calls from cellphones, military data, critical infrastructure, and more. https://www.wired.com/..…
New from @agreenberg.bsky.social and me: For three years, security researchers pointed a satellite at the sky and found highly sensitive data being sent unencrypted — They found: calls and texts on T-Mobile's network; military info from the US and Mexico; in-flight Wi-Fi browsi…
An absolutely terrifying SCOOP from @mattburgess1.bsky.social and @agreenberg.bsky.social revealing that everything from inflight browsing data to military communications are being beamed unencrypted from satellites all the time — www.wired.com/story/satell...
Geostationary satellites are leaking critical data, transmitting sensitive communications in the clear. With just $800 of consumer hardware, researchers intercepted military, telecom, retail, and infrastructure traffic. satcom.sysnet.ucsd.edu/docs/ dontloo... [image]
Academic researchers discover that about half of geostationary satellite signals, many carrying sensitive consumer, corporate and government communications, have been left entirely vulnerable to eavesdropping. www.wired.com/story/satellite...
The study captured an estimated 15% of all geostationary satellites, which raised the prospect that as much as 85% of the world's satellite communications remain insecure—subject to surveillance by anyone with $800 in equipment www.wired.com/story/satell...
https://www.wired.com/... Researchers from UC San Diego and U. of Maryland showed how a modest, ~$800 satellite‐receiver setup can intercept sensitive unencrypted data from geostationary satellites. — They recovered T-Mobile calls and texts, airline WiFi sessions, industrial n…