Back to news

SWF 2026 Report: Cyber Is the Counterspace Weapon in Use

Share:
SWF 2026 Report: Cyber Is the Counterspace Weapon in Use

The Secure World Foundation's 2026 Global Counterspace Capabilities Report, published in May, concludes that cyber operations and electronic warfare are the only two categories of counterspace weapon that nations use against real adversaries, even as several governments continue to pledge moratoriums on destructive anti-satellite testing.

Thirteen countries, five categories

The report, edited by Victoria Samson and Kathleen Brett, assesses open-source information on counterspace capabilities across five categories: co-orbital, direct-ascent anti-satellite weapons, electronic warfare, directed energy, and cyber. It now covers thirteen countries, with Germany added for the first time this year to reflect Berlin's new military space strategy and its stated interest in electromagnetic-spectrum operations and cyber capability in orbit. The other twelve are the United States, Russia, China, India, Australia, France, Iran, Israel, Japan, North Korea, South Korea, and the United Kingdom.

Samson previewed the methodology at the Quad Nations Security Dialogue in Sydney on September 28, 2025, months before publication, describing the project as a running public tally of observable activity rather than a classified threat assessment.

The ground segment is already a battlefield

The report treats the February 2022 attack on Viasat's KA-SAT network as the clearest evidence that cyber counterspace activity moved from theory to routine military practice. Russian operators disabled modems serving Ukrainian military communications at the start of the invasion, and the same attack also knocked remote monitoring offline for about 5,800 Enercon wind turbines across central Europe, representing more than 10 gigawatts of generating capacity that operators could no longer control from a distance. Enercon needed weeks to replace damaged modems and restore service. The report cites the incident as the template for modern counterspace cyber operations: the satellite bus itself is rarely the target, while the ground terminals and network infrastructure around it remain exposed.

Open-source flight software is a new front

The report also flags software supply chains as an emerging cyber counterspace vector. At Black Hat USA and DEF CON in August 2025, researchers Milenko Starcik and Andrzej Olchawa of VisionSpace Technologies disclosed 37 vulnerabilities across open-source space software, including four critical flaws in NASA's Core Flight System, the framework flown on the James Webb Space Telescope and Intuitive Machines' Odysseus lunar lander. One bug let an unauthenticated attacker crash all onboard software with a single message; another allowed a simulated command to fire a spacecraft's thrusters without the maneuver appearing immediately on a ground controller's screen. The researchers found further flaws in the CryptoLib encryption library and in OpenC3 Cosmos, a widely used ground station platform, before all of them were patched.

Europe's space agency keeps getting breached

The vulnerability of ground infrastructure extends to the agencies running it. In December 2025, a hacker using the handle 888 claimed on a cybercrime forum to have stolen roughly 200 gigabytes of data from European Space Agency engineering servers, including source code and hardcoded credentials; ESA said the affected systems were external, non-classified collaboration tools and called the impact "very limited." The reassurance did not hold for long. By January 2026, a group calling itself Scattered Lapsus$ Hunters claimed it had been inside ESA networks since September 2025 after exploiting a public vulnerability, and said it had exfiltrated 500 gigabytes covering spacecraft operational procedures, subsystem documentation, and environmental test reports. The report treats the pair of incidents as evidence that even a well-resourced government space agency struggles to keep attackers out of its engineering supply chain.

Half the signals in the sky are still unencrypted

Cyber counterspace is not only about hacking; the report also points to passive interception as an unresolved problem. A team from the University of California San Diego and the University of Maryland, in a paper titled "Don't Look Up", pointed about 800 dollars of commercial satellite dish and tuner hardware at the sky and scanned traffic on 39 geostationary satellites across 25 orbital positions. They found cleartext IP traffic on roughly half of the 411 transponders they examined, including cellular backhaul voice and text content later traced to T-Mobile, in-flight Wi-Fi sessions, VoIP calls, and operational data belonging to a police force and a coastal vessel-tracking system. T-Mobile enabled encryption once the researchers notified it. The finding undercuts an assumption the report says many satellite operators still make, that a signal reaching the ground from geostationary orbit is too obscure for anyone to bother intercepting.

The tempo is picking up

The report's publication coincided with a separate count from the Center for Strategic and International Studies, which said Space ISAC analysts tracked approximately 105 publicly reported cyber incidents affecting space-related organizations between January and July of 2026 alone, a pace that outstrips prior years and reflects what the report calls expanding adversary interest in a sector that was until recently a minor target.

A test for buyers, not just operators

The counterspace assessment is aimed at militaries and policymakers rather than satellite operators directly, so the clearest near-term consequence may land on defense procurement. Canada does not field offensive counterspace weapons, but a review published by SpaceQ argued that the country's deep integration into allied space architecture, combined with a growing commercial space-defense sector, puts the vulnerabilities the report describes squarely in front of Canada's new Defence Industrial Strategy and the Defence Investment Agency responsible for executing it. The same question now faces any government buying satellite services built on the ground infrastructure, open-source flight software, and unencrypted downlinks the report spends four chapters describing.

Secure World Foundation published the 2026 Global Counterspace Capabilities Report findings summarized here in May 2026.