Back to news

Kaspersky Finds Thousands of GNSS Receivers Still Exposed

Share:
Kaspersky Finds Thousands of GNSS Receivers Still Exposed

Kaspersky's ICS CERT research division found more than 3,000 GNSS receivers reachable directly from the open internet, according to a report published on August 6, 2026, after the company audited internet-exposed satellite navigation hardware with the cooperation of 70 receiver manufacturers worldwide. The count looks like an improvement over earlier surveys, but the underlying problem, hardware meant to sit inside a protected network answering commands from anyone who can reach its IP address, has not gone away.

A Shrinking Number, Still in the Thousands

The audit traces back to a spike in GPS and GNSS signal spoofing over the Black Sea in 2023, which disrupted aircraft and ship navigation across the region and pushed Kaspersky to measure how many receivers used for positioning, navigation, and timing sat exposed to internet scanning tools such as Shodan. It was not the first count: in March 2023, researchers found 9,775 satellite receivers from five vendors reachable on the open internet, scattered across Latin America, North America, Europe, and Asia.

Kaspersky's own Securelist team repeated the exercise in July 2024 and counted 3,937 exposed GNSS instances running on Linux- and Windows-based firmware of wildly different vintages. The August 2026 figure, more than 3,000 devices found across a sample of 70 vendors instead of five, suggests the exposed population has flattened rather than closed.

Geography skews toward wealthy, GNSS-dependent economies rather than the developing world. For one major receiver vendor alone, the largest counts of exposed units turned up in the United States, Germany, Australia, Russia, and Japan, the same markets that lean hardest on GNSS timing for finance, agriculture, and transportation networks.

Why a Receiver Left Open Matters

A GNSS receiver's control interface exists for configuration and troubleshooting, not for defense against a hostile internet. Left reachable without strong authentication, it can hand an attacker read access to the position, navigation, and timing data the device produces, or write access to reconfigure the unit outright. That matters because the same receivers sit behind systems well outside the space sector: air traffic control, marine navigation, agricultural machinery, and the timing signals banks and power grids use to keep transactions and load-balancing synchronized. Kaspersky and earlier surveys both found exposure spanning GPS, GLONASS, Galileo, and BeiDou receivers, so the problem is not confined to one country's satellite fleet or one vendor's firmware.

The Shadowserver Foundation, which runs its own daily scans for exposed infrastructure, now tracks accessible NTRIP casters, the servers that stream real-time GNSS correction data over the internet, as a standing category in its abuse reporting feeds, evidence that the exposure has outlasted several rounds of public disclosure.

Patching does not come easily to this category of hardware. Unlike a phone or a laptop, a survey-grade GNSS receiver or an NTRIP correction server is typically bought once, mounted on a rooftop or a field mast, and left running for a decade or more without a vendor support contract. Ownership is diffuse: surveying firms, farms, telecom operators, and local governments each run a handful of units with no coordinated patch cycle, part of why the same class of exposure keeps reappearing in scan after scan even as individual vendors ship fixes.

Hacktivists Got There First

The risk is not hypothetical. In May 2023, the hacktivist group SiegedSec broke into roughly 30 radio and government-linked satellite receivers in Colombia as part of a campaign it called OpColombia, launched after the arrest of a hacker linked to the group, and leaked about 6 gigabytes of data before folding the operation into a joint campaign with a second group, GhostSec.

GhostSec went further on its own, sabotaging 11 GNSS devices inside Israeli industrial networks, wiping stored positioning data and in some cases erasing archives larger than 30 gigabytes. The same group claimed an earlier attack on a Russian GNSS receiver it described as a military asset, framed as protest over the invasion of Ukraine. Neither operation required breaking cryptography or exploiting a novel software bug. Both required finding a receiver that answered on the open internet, exactly the exposure Kaspersky's audit measured three years later.

What Kaspersky Wants Fixed

As satellite technology becomes deeper integrated into civilian life, from navigation systems to energy grids, securing these connections, enforcing encryption on downstream links, and patching vulnerable internet-exposed receivers is of highest importance.

said Ekaterina Rudina, a security analysis expert at Kaspersky, in comments accompanying the report's release.

The company's recommendations are unglamorous by design: audit ground control and subscriber-side hardware for internet exposure and patch what turns up, encrypt satellite communication links end to end so traffic cannot be sniffed or spoofed in transit, and install endpoint protection on ground station terminals rather than assume physical isolation is enough. Publicly tallied incidents targeting space systems date back to 1957 and now number over 100, a reminder that the ground segment, not the satellite in orbit, has usually been where the actual break-in happens.

First reported by Kaspersky ICS CERT, with additional detail from Securelist, Shadowserver, and CyberScoop.