Early on February 24, 2022, before Russian tanks rolled into Ukraine, a different kind of assault occurred thousands of kilometers above Earth. Satellite modems that powered communications across Ukraine and Europe fell silent, wind farms lost telemetry, emergency services went dark and military units were cut off from command networks. The culprit was not a missile or laser but malicious code embedded deep within the ground network of the Viasat KA-SAT satellite system, an attack meticulously prepared to coincide with the outbreak of war on the ground.
That event, now etched into cyber and space warfare history, marked a turning point: Space, long thought to be a sanctuary above the contested terrain of Earth, had become a battlefield, but the first shots weren’t fired with kinetic force. They came through invisible lines of code, exploiting vulnerabilities in interconnected networks that span orbital spacecraft and cloud-based mission control systems on Earth.
As space systems have grown more central to military operations, economic stability and daily civilian life, the threat landscape has expanded with them. Cyber operations are now core components of modern counterspace arsenals, alongside jamming, directed energy and anti-satellite missiles, according to the 2025 Space Threat Assessment by the Center for Strategic and International Studies (CSIS). In other words, software has joined the front lines of space warfare.
Satellites don’t operate in isolation. They’re embedded in sprawling digital ecosystems that involve global ground stations, cloud service providers hosting command and control software, radio-frequency uplinks and downlinks, and hybrid commercial-military systems with intertwined data streams. Every link in this chain represents a potential vulnerability.

“Satellites in space are not useful if the linkages to them and the ground network that moves the information around and communicates with the satellites is not assured, is not capable, is not accessible,” U.S. Space Force Gen. B. Chance Saltzman, chief of space operations, told reporters in January 2023.
The threat to satellites, both public and private, has been quietly building for years, accelerating after the 2022 Viasat breach and fueled by a combustible blend of state actors, criminal groups and government proxies. A report from the Space Information Sharing and Analysis Center (Space ISAC) found a 118% surge in space-related cyber incidents in the first nine months of 2025 compared with 2024, documenting at least 117 publicly disclosed events between January and August alone.
Those figures capture only a fraction of the activity. As CSIS warned in its 2025 Space Threat Assessment, most cyber operations targeting space systems remain classified, unattributed or undisclosed, obscuring the true scale of the campaign unfolding on orbit and on the ground.
The Viasat incident remains the most vivid example of how a cyber operation can shape a war without creating debris in space. Russian operators spent months probing the terrestrial networks supporting KA-SAT before deploying malware that affected tens of thousands of satellite modems across Europe, disrupting Ukrainian military communications and civilian broadband internet service. Some areas of the Middle East also were affected.
“It was more of a tactical exercise in preparation for combat operations,” Ron Bushar, managing director and chief information security officer at Google Public Sector, told SpaceNews in November 2025. “They didn’t need to take down the satellite itself. They just targeted the modems and the downlinks. It was precise and effective.”
The message to defense planners was unmistakable: Controlling the ground network can mean controlling the satellite. CSIS now classifies cyber operations not as a supporting capability but as a primary category of counterspace weaponry, on par with jamming and anti-satellite missiles.

“I think [this] speaks to the fact that cyber touches every single thing that we do. Cyber is an entry point for a threat vector that cuts across every physical domain, including space,” Clayton Swope, deputy director of the Aerospace Security Project and a senior fellow in the Defense and Security Department at CSIS, told Apogee.
The Chinese Communist Party (CCP) and Russia integrate cyber into their military space doctrines. Rather than relying solely on dramatic anti-satellite missile strikes, both countries emphasize:
- Pre-positioned access to adversary space networks
- Persistent cyber reconnaissance of satellite ground systems
- Supply chain infiltration of space hardware and software
CSIS describes this as “pre-conflict shaping,” a strategy in which adversaries infiltrate digital infrastructure years in advance, embedding access points that can be activated at a moment of crisis. From a strategic standpoint, cyber offers the highest return on investment of any counterspace weapon. It is cheaper than kinetic systems, easier to conceal, less likely to provoke escalation and capable of achieving comparable strategic effects.
“Cybersecurity is key to space superiority,” Col. Nathan Iven, deputy for science, technology and research within the U.S. Space Force Chief Technology and Innovation Office, said during a July 2025 podcast with the Mitchell Institute for Aerospace Studies, a nonpartisan research organization.
“If we don’t have secure, reliable access between our weapon systems to complete those long-range kill chains, then we’re not going to be mission effective,” Iven said.

To blunt the threat, the Space Force has expanded specialized cyber units under Space Delta 6, which oversees the Satellite Control Network linking more than 190 satellites. New cyberspace operations squadrons established in Colorado in late 2022 and early 2023 reflect how rapidly the mission has grown as digitization accelerates worldwide.
Chinese hackers are linked to major attacks globally, including the reported acquisition of F-35 fighter jet blueprints and theft of personal data of 22 million Americans. Russia and Iran also have carried out numerous cyberattacks, targeting among others pharmaceutical companies, water treatment plants and oil pipelines.
A June 2025 White House executive order to increase focus on cybersecurity described the CCP as “the most active and persistent cyber threat to U.S. government, private sector, and critical infrastructure networks.”
Space ISAC’s space cybersecurity report flags two additional emerging organizations for threats: Void Blizzard, a Russia-linked actor that focuses on aerospace and defense contractors, and Bitter APT, believed to be a South Asian group that uses cyber espionage to extract state and trade secrets. “Bitter APT targeted Pakistan’s largest telecommunications company, which operates satellite communications infrastructure,” the report said.
The shift toward space is stirring concern well beyond the Department of War (DOW). The global space economy, valued at $630 billion in 2023 and projected to reach $1.8 trillion by the mid-2030s, is increasingly driven by private firms that were not designed with prolonged cyber conflict in mind.
“Satellites, at their core, are just computers with solar panels on them, and yet they lack the cyber protections of even your phone or laptop,” Ryan Roberts, a principal at the Deloitte business services network and leader in its cyber risk practice, said during the Air & Space Forces Association’s Air, Space & Cyber Conference in September 2025.
That vulnerability creates strategic gray zones. Moscow has warned that Western commercial satellites aiding Ukraine could be considered legitimate military targets. Meanwhile, CCP-linked operations such as Salt Typhoon have expanded from telecom networks to satellite communications providers. As civilian and military systems mesh, the line between protected infrastructure and targetable assets grows thinner.
At its core, the cyber contest in space is asymmetric. “Defenders have to be perfect everywhere,” retired Air Force Maj. Gen. Bradley Pyburn, now a managing director at Deloitte, told SpaceNews. “The offensive team only has to get it right once.”
Compliance frameworks such as the National Institute of Standards and Technology’s (NIST) Risk Management Framework (RMF) provide baseline safeguards, but experts warn they are insufficient against adversaries wielding AI-enhanced tactics across sprawling satellite constellations and supply chains.
“This expanding attack surface offers adversaries more opportunities to exploit vulnerabilities across satellite constellations, ground stations and the complex supply chain supporting these systems,” Timothy Zentz, a vice president at Virginia-based cybersecurity and intelligence services company Nightwing, told Apogee.
“While compliance frameworks like NIST’s RMF and the Department of War’s CSRMC [Cybersecurity Risk Management Construct] establish critical baseline protections, they alone are insufficient against the advanced capabilities of well-funded adversaries employing AI-augmented and innovative attack techniques,” Zentz said. “Addressing these challenges demands a shift toward full-spectrum cyber, a holistic approach that integrates offensive cyber TTPs [tactics, techniques and procedures] with defensive cyber measures, electronic warfare and space-based countermeasures.”
Federal investigators are tracking the evolution of these threats. In August 2025, the FBI warned 600 organizations about malware linked to Salt Typhoon, which has targeted global telecommunications networks and satellite communications firms. “These actors mounted a major cyber espionage effort, violating privacy and security standards in telecommunications worldwide. Beijing’s broad targeting of private communications highlights the need for even closer cooperation with our partners to detect and counter these actions as early as possible,” Brett Leatherman, head of the FBI’s Cyber Division, said in a video message.

To intelligence leaders, the conclusion is unavoidable. “For the NRO [National Reconnaissance Office], my No. 1 concern is cyber,” NRO Director Chris Scolese said at the Intelligence & National Security Summit in September 2025.
“The fact that we have a proliferated architecture, that we go off and do what we can to protect our architecture … or enhance our capabilities is really critical,” he said. “But the one area where any adversary [can pose a threat], because the cost of admission is relatively cheap, is in the cyber area. So, we remain very much concerned about that.”
Artificial intelligence is now central to defense. The DOW has tightened cybersecurity requirements for satellites since 2020, while industry has begun deploying onboard AI systems that can detect spoofing, anomalous telemetry and network intrusions. The aim is to move protection from distant ground stations directly onto spacecraft.
“Even the most cutting-edge, mission-critical technologies are only as effective as their ability to operate securely in the face of cyber threats,” Zentz said.
In the coming decade, satellites that can defend themselves may prove as decisive as those that can see or communicate. The next conflict in space may not begin with an explosion. It may start with corrupted data, a spoofed signal or an alert from an AI sentinel far above Earth.
“AI-enabled attacks can potentially find vulnerabilities faster than a human,” the CSIS’ Swope said. “In the cyber domain, it really does not matter if the network node is in space or on Earth. It all looks the same in cyberspace.”
