ISSUE 153 | September 15, 2026
The integrity flash
Analysis of Developments in the Space Domain
In This Issue
01 China Relocates TJS-15 Near US Satellite (Again)
02 China Launches 6 Yaogan Satellites
03 China: YG-50 02 Break-Up
04 Russia Launches New Glonass Satellite
05 India Launches GEO Imager
06 Ukraine Targeting Russia’s Space Launch Architecture
07 The Iran War Brings the Ground Segment Into the Counterspace Fight
08 Seven Sons: Harbin Institute of Technology
09 Inside the Satellite: Understanding the Cyber Attack Surface
10 Pics o’ the Fortnight
China Relocates TJS-15 Near US Satellite (Again)
25 Aug – 5 Sep: China relocated TJS-15 (63157) “King of the West” from 94.4°E to 88.7°E. The Chinese satellite with a stated mission of verifying “multi-band and high-speed satellite communication technology” is now located in the vicinity of the US military communications satellite WGS F4 (38070) which is located at 88.4°E. Observation data indicates China drifted TJS-15 to within 100km of WGS F4 as it headed west (graph A). China decreased TJS-15's SMA to initiate a slight eastward drift on 4 September. During this transition TJS-15 had a point of closest approach (POCA) of ~64km with WGS F4 on 4 Sep at 1250Z. At POCA the solar conditions were unfavorable for TJS-15 to observe WGS F4. China drifted TJS-15 eastward for <24hrs then increased SMA to maintain a stable position 200-400km separation from WGS F4. From this location TJS-15 could be in position to monitor WGS F4 signals.
Graph Showing TJS-15 Changing SMA & Longitude Location. (celestrak.org)
China Appears to have Maneuvered TJS-15 to <100km from WGS F4 & Then Drifted Satellite to the East to Increase Separation. We Observed this Pattern Of Behavior In Aug 2025 With TJS-15 and SBIRS GEO-5. (saberastro.com)
6 Sep 2026: TJS-15 Settles into GEO. Separation with WGS F4 Ranges from 200-400km (saberastro.com)
Per reporting from the Joint Commercial Operations Cell (JCO) SJ-23 (55131) happened to be in the area as TJS-15 was settling into its new orbital slot. On 4 Sep at 1220Z (30 minutes prior to TJS-15's POCA) SJ-23 was 132km from the US satellite with optimal solar conditions for imaging. The timing may have been more than coincidental as SJ-23 conducted 2 minor maneuvers between 7-22 Aug to slightly increase its westerly drift rate from 0.724°/day to 0.847°/day during this time period.
4 Sep 2026 1220Z: SJ-23 Has Favorable Solar Conditions to Observe WGS F4 at 132km & TJS-15 at 170km (saberastro.com)
This is TJS-15's second relocation. In August 2025 China maneuvered TJS-15 to an orbit in vicinity of USA 315 (SBIRS GEO-5, 48618). After spending a year near that satellite, China maneuvered to WGS F4. Time will tell if this becomes a pattern. Of the 4 Kings satellites (TJS-16, 17 & 19 being the other 3) only TJS-15 has maneuvered to be in vicinity of US satellites.
12 Sep 2026: Position and Inclination of China’s “Four Kings” Satellites (nasaspaceflight.com & saberastro.com)
10 Sep 2026: China launched a Long March-4B with six satellites, Yaogan-53 01-03 (100651-53) and Yaogan-56 01-03 (100654-56) from Jiuquan. According to official sources, the satellites entered the preset orbits successfully and will be “primarily used for scientific experiments, land and resources surveys, crop yield estimation and disaster prevention and reduction”. Launch Video.
Initial observations show all 6 satellites in at 518km circular orbits with an inclination of 45°. Unknown if the satellites will maneuver into a distributed formation. We will continue to monitor in the coming weeks.
LM-4B Lift Off from Jiuquan (left) and Initial YG-53/56 Grouping in 518km Orbit & 45° Inclination (nasaspaceflight.com & saberastro.com)
I figured this launch provided an adequate excuse to look at the historical trends for Chinese launching their Yaogan satellites. For those new to the Flash, the Yaogan series of satellites is believed to be used by the Chinese military for Intelligence, Surveillance and Reconnaissance (ISR) and we’ve covered their evolution extensively.
I chose to look at 2010-2026 to give us a broad look at Yaogan launch evolution. During this time launch activity divides into three distinct phases. 2010-2020 was modest and episodic, averaging roughly five payloads per year and consisting largely of single-satellite missions, with only 2014 breaking into double digits. Beginning in 2021, the program entered a sustained surge (see graphic) placing 98 satellites on orbit from 2021-2024 (inclusive), or 57 percent of every Yaogan payload launched since 2010. That surge was overwhelmingly a function of formation deployment rather than a broad increase in mission tempo: the Yaogan-30 and Yaogan-31 triplet constellations, followed by the rapid build-out of the Yaogan-35, -36, -39 and the Yaogan-43 series, meant that a single launch routinely added three or more satellites to the catalog. Activity then fell off sharply once those constellations reached their designed size, dropping to nine payloads in 2025 and eight through mid-September 2026. The character of post-2024 launches also changed: rather than replicating triplets, recent missions have been placing smaller spacecraft into unusual orbits. Examples are Yaogan-45 and -46 to MEO and the Yaogan-50 satellites into retrograde-orbit.
The decline in Yaogan volume should not be read as a reduction in Chinese space-based ISR capacity, but rather as the completion of a constellation build-out, with launch capacity redirected toward the Guowang and Qianfan low-Earth-orbit communications constellations that now dominate China's annual payload count.
Yaogan Satellites Launched 2010 – 2026 (space.skyrocket.de)
Annual Satellite Launch Totals 2010-2026. Note ISR Deployment Continued to Grow Through Decrease in Yaogan Launches in 2025 due to Gaofen, Jilin-1, Chaohu/Hongtu, and commercial SAR satellites. (space.skyrocket.de)
4 Sep 2026: Space observers are tracking 43 pieces of debris attributed to Yaogan-50 02 (68196). As noted previously YG-50 02 is in an unusual retrograde orbit and believed to be a SAR imaging satellite. China has not released any public information (standard) regarding the event. Jonathan McDowell noted the most likely cause for the shedding event/break up was “either a battery explosion or an impact by space debris.” Others noted, “the debris have been dispersing for quite some time. Backward propagation suggests a shedding event occurred around late July.” The debris field will be problematic for decades to come as pieces have been noted to range between 600-1,100km in average altitude.
24 Aug 2026: Russia launched a Soyuz 2.1b with a Glonass K satellite, designated Cosmos 2619 (100460) from Plesetsk. Cosmos 2619 is now in Medium Earth Orbit (MEO) joining ~26 other active Glonass satellites. Russia used a FREGAT M upper stage to place the satellite into its 64.77° inclined 19,147km orbit. Per our friend Bart Hendrickx, Cosmos 2619 is likely a Glonass K satellite and not the more modern K2 variant. Launch Video.
24 Aug 2026: Soyuz 2.1b Lift Off with Cosmos 2619 (russiaspaceweb.com)
Glonass Evolution (nasaspaceflight.com)
The GLONASS constellation remains at its nominal 24-satellite operational strength, distributed evenly across three circular orbital planes of eight satellites each at roughly 19,100 km altitude and 64.8° inclination. The three planes are separated by 120° in RAAN. As of mid-September 2026 Plane 1 RAAN is ~70°, Plane 2 ~190°, and Plane 3 ~310°. The constellation is a mix of aging GLONASS-M spacecraft (launched 2007–2010) and newer GLONASS-K/K2 vehicles being introduced as replacements.
Cosmos 2619 is in Plane 3 with a RAAN of 312.1° and may be intended to replace Cosmos 2460 (36402). One observer from nasaspaceflight.com noted, “Glonass-M 732 (Cosmos 2460) was recently the subject of an investigation. I suspect it is slated for replacement in near time.” Cosmos 2619 is not in an operational slot yet. Its SMA is 31.7 km above the operational orbits of other Glonass satellites and it is actively maneuvering. As a result of its SMA difference, Cosmos 2619 is drifting westward ~1.41°/day relative to the other Plane 3 satellites.
Cosmos Constellation: 3 Orbital Planes Inclined ~64.8° with 120° RAAN Offset (saberastro.com)
India Launches GEO-based Imaging Satellite
3 Sep 2026: India launched a GSLV-F17 from Satish Dhawan Space Centre carrying its first geosynchronous imaging satellite. EOS-05 (GISAT-1A, 100607) has successfully completed 3 or 4 orbit raising maneuvers to reach geosynchronous orbit. Its initial orbit had a 171km perigee and 29,000km apogee. As planned EOS-05 fired its Liquid Apogee Motor twice on 5 and 6 September to reach 20,000 × 31,129 km and then 35,786 km, with a third and final burn of 1,247 seconds on 7 September placing the spacecraft at 34,903 × 35,884 km. We are still awaiting word of EOS-05 stabilizing in GEO. EOS-05 will still need to raise its SMA ~400km to reach GEO at 35,786km. At 2,367 kg, the EOS-05 is the heaviest payload GSLV has ever carried. Launch Video. Satellite separation Video.
EOS-05 (GISAT-1A) Mission Overview (left), Launch Preparation (middle), & Satellite Separation (right) (nasaspaceflight.com)
GSLV-F17 Lift Off with EOS-05 (GISAT-1A) (right) & Orbit Raising Phases (right). As of 12 Sep 2026 EOS-05 Is In Orbit #3 (nasaspaceflight.com)
From its GEO perch EOS-05 will have full coverage of the Indian landmass and surrounding areas. EOS-05 carries a 700 mm Ritchey-Chrétien telescope derived from the Cartosat-2A design, delivering 42m multispectral resolution alongside 158-band visible & near infrared (VNIR) sensor with 318m resolution and 256-band short-wave infrared (SWIR) sensor with 191m resolution. EOS-05 can collect an image every 5 minutes which equates to full-coverage of the entire Indian landmass every 30 minutes. ISRO characterized EOS-05 as a "strategic satellite" with a seven-year expected lifetime (although ISRO is now estimating 9+ years). Indian press noted the satellite’s persistent-stare capability as being useful for both civil and military use cases.
ISRO’s EOS-05 (GISAT-1A) satellite is expected to be in service for >9 years, extended from its originally planned 7 year mission duration. (@ISROSpaceflight via X)
This was the program’s second attempt. The original GISAT-1, redesignated EOS-03, was lost on 12 August 2021 when GSLV-F10’s cryogenic upper stage failed to ignite. ISRO’s Failure Analysis Committee traced the anomaly to an abnormal pressure build-up in the liquid hydrogen tank — most likely a leak in the vent and relief valve — which starved the fuel booster turbopump and caused the onboard computer to abort the mission at 307 seconds. That launch had itself been delayed repeatedly, first scrubbed in March 2020 and pushed again in 2021 over a voltage problem. The 2026 success therefore carried weight beyond the payload: it returned GSLV’s Indian-built cryogenic stage to flight after the failure mode that had defined the program’s reputation, and delivered ISRO’s first successful mission of 2026 following a PSLV failure earlier in the year.
Ukraine Is Reaching Deeper Into Russia’s Space Launch Architecture
On August 23, Russian authorities reported Ukrainian drones operating over Arkhangelsk Oblast, home to Plesetsk Cosmodrome. Open-source reporting placed the activity in the vicinity of Plesetsk Cosmodrome less than a day before Russia successfully launched a Soyuz-2.1b/Fregat carrying a GLONASS navigation satellite. Ukraine has not publicly confirmed Plesetsk as the target, and there is no confirmed physical damage to the cosmodrome. What is significant is that Ukrainian long-range platforms were operating near one of Russia’s primary military space launch facilities during a period of active launch preparations.
All three publicly reported attempts involving Plesetsk appear to have been timed around launch activity. Anatoly Zak described three attempts occurring when a fueled rocket was on the pad or approaching launch, including the December 25, 2025 Obzor-R mission, the March 23, 2026 Rassvet launch, and the August activity preceding the GLONASS mission.
“According to local press reports, a drone attack on Plesetsk was repelled on the day of the Obzor-R launch on December 25, 2025. Local authorities later released a picture of one of the downed drones, thanking local residents for having timely warned them of the attack.” –Bart Hendrickx (nasaspaceflight.com)
The effect does not require a successful strike. The presence of drones in the vicinity of the cosmodrome could be enough to delay a launch, interrupt final preparations, force additional security measures, or hold personnel and equipment in a protective posture while the threat is assessed. Those delays matter because assured access to space depends not only on having rockets and launch pads, but on being able to use them when required. In that sense, capability can be degraded without anything being permanently destroyed.
Map Showing Targeted Locations (left); Ukranian UAV Operating Over Arkhangelsk Province (right)
(@RussianSpaceWeb via X)
By July, the pattern had become even less precise. Warnings associated with the second Rassvet mission used 24-hour windows, while additional notices with partially overlapping periods were consistent with as many as four separate launch profiles. Bart Hendrickx identified trajectories associated with Soyuz launches to roughly 63-, 82-, and 97–98-degree inclinations, along with a possible Yars ICBM flight. RussianSpaceWeb assessed that the broader and overlapping warnings were intended to complicate prediction of both the actual launch time and the fueling period.
The August GLONASS mission continued the same pattern. Restrictions matching previous GLONASS launches covered August 19 through August 30 and overlapped with separate Angara-related warnings issued as early as August 8. Local authorities in Komi and Tyumen provided only that a launch was expected during the “second half of August.” Russia ultimately launched the Soyuz on August 24 at 05:40 Moscow time.
That ambiguity becomes more consequential now that Plesetsk is held at risk by Ukrainian long-range standoff systems. Expanding and overlapping launch windows do not conceal the launch, but they make it harder to isolate the most vulnerable portions of the launch cycle and give Russia an operational-security advantage while still allowing it to issue required safety warnings. Ukraine does not have to physically damage the cosmodrome to create an effect. A long-range strike system operating near Plesetsk can force Russia to pause activity, delay fueling or launch, change procedures, reposition personnel or equipment, increase air-defense requirements, or reassess whether conditions are safe enough to proceed. The platform may be capable of kinetic effects, while the immediate result is non-kinetic disruption, delay, or behavioral change rather than destruction. This also creates a form of non-traditional deterrence. Ukraine does not need to demonstrate that it can destroy Plesetsk or eliminate Russia’s launch capability. It only needs to create enough credible risk that Russia changes how it operates. If the threat of long-range platforms forces Russia to increase operational security, alter procedures, devote more resources to protection, or accept delays, then Ukraine has imposed an operational cost regardless of whether physical damage occurs.
There is also a psychological component. Plesetsk is more than 1,800 kilometers from Ukraine and has historically benefited from geographic distance as a layer of protection. Ukrainian systems reaching Arkhangelsk Oblast challenge that assumption and force personnel conducting launch operations to account for a threat that was previously much less credible at that range.
Plesetsk is only one part of the broader terrestrial architecture Ukraine has begun holding at risk. On August 15, Ukraine struck the Progress Rocket and Space Centre in Samara, a key producer of Soyuz launch vehicles. Ukraine’s General Staff reported damage to facilities associated with Soyuz production, while subsequent imagery showed impacts and a partially collapsed roof at one of the buildings.
The significance is broader than any single strike. Space capability depends on more than the satellite in orbit. Launch vehicles have to be produced, payloads processed, launch sites kept available, spacecraft placed into orbit, and ground systems maintained to command and exploit them. Each of those functions creates a terrestrial dependency that can be affected with conventional military capabilities.
Ukraine therefore does not need to compete with Russia symmetrically in space to affect Russian space operations. Long-range standoff systems allow it to hold portions of the terrestrial architecture at risk and create effects ranging from physical damage to interruption, delay, increased force protection, changes in procedures, and greater operational-security requirements.
The broader measure of effectiveness is not whether a Ukrainian drone destroys a rocket on the pad. It is whether the threat forces Russia to change how it generates space capability. If launches are delayed, procedures altered, additional resources committed to protection, or launch timing made deliberately less predictable, then an operational effect has already been created. Assured access to space is not simply the possession of rockets and launch infrastructure; it is the ability to employ them when required. A launch architecture forced to account for disruption, uncertainty, and delay is already being degraded.
The Iran War Brings the Ground Segment Into the Counterspace Fight
Recent comments from U.S. Space Command Commander Gen. Stephen Whiting provide new insight into the role space infrastructure is playing during the war with Iran. Speaking with reporters at Redstone Arsenal and during remarks at the Space and Missile Defense Symposium, Whiting highlighted Iran’s deliberate targeting of U.S. space and missile defense assets. The attacks reinforce a broader trend increasingly evident in modern conflict: space capabilities, and the terrestrial infrastructure that enables them, are becoming part of the conventional targeting calculus.
Iran’s targeting demonstrated an alternative approach to counterspace operations by focusing on the terrestrial infrastructure enabling U.S. space and missile defense capabilities. Strikes against radar systems, satellite communications infrastructure, and other fixed facilities across the region threatened to degrade U.S. space-enabled operations while also placing pressure on the regional relationships that make those operations possible. Many of these capabilities depend on access to facilities hosted by Gulf partners. By bringing those installations into the target set, Iran was not only attacking military infrastructure, but also highlighting the risks regional states assume by hosting U.S. forces and capabilities.
Commercial satellite imagery following Iranian attacks against U.S. installations showed damage to satellite communications facilities and dishes, radomes, and missile defense radar infrastructure at bases across the region. The targeting is particularly significant given Iran’s finite inventory of missiles and one-way attack drones. Whiting emphasized that Iran was deliberately expending those weapons against space and missile defense targets, arguing that militaries take particular care in selecting targets when weapons are costly. More broadly, he pointed to the attacks as evidence of a changing threat to space operations: fixed terrestrial infrastructure within an adversary’s weapons engagement zone is increasingly part of the target set.
Iran, however, was not alone in bringing space infrastructure into the targeting cycle. During Operation Epic Fury, U.S. forces targeted Iranian facilities that enabled Tehran to move data and conduct military operations in space. Israel also directly targeted Iran’s terrestrial space architecture. On March 8, the Israeli Air Force struck the Islamic Revolutionary Guard Corps Space Force headquarters in Tehran. According to the IDF, the facility supported satellite reception, transmission, and research and contained command-and-control infrastructure associated with Khayyam (53370), Iran’s Russian-built high-resolution Earth observation satellite.
Khayyam is particularly noteworthy because its orbital behavior may provide insight into the broader effects of the conflict on Iranian space operations. Space domain awareness observations indicate Khayyam ceased its normal period of SMA station-keeping maneuvers between approximately February and August 2026 (see graphic). Beginning around August 3, observers detected a resumption of those maneuvers, resulting in an overall increase in the satellite’s orbital period.
Graph Depicting Khayyam Satellite Cessation of Orbital Maintenance Maneuvers from Feb-Aug 2026. (celestrak.org)
There is currently insufficient evidence to determine whether the interruption in Khayyam’s station keeping was related to the conflict or reflected other operational factors. The timing, however, warrants attention. The change occurred during a period in which Iranian space capabilities and supporting infrastructure were increasingly affected by the conflict. Khayyam’s return to station keeping in August therefore provides another data point in assessing how space operations may have changed during the war, without establishing a direct link to any individual strike.
Taken together, the targeting by both sides highlights the expanding role of terrestrial space infrastructure in conventional conflict. Disrupting an adversary’s ability to use space does not necessarily require attacking a satellite. Operators, command-and-control facilities, communications links, tracking infrastructure, data-processing nodes, and end users are all part of the architecture required to translate an on-orbit capability into an operational effect. Attacking vulnerable portions of that architecture can therefore degrade or disrupt the use of space without ever engaging the spacecraft itself.
The implications extend beyond the physical vulnerability of the ground segment. U.S. space-enabled operations in the region rely on access, basing, and relationships with Gulf partners. Targeting infrastructure hosted by those partners has the potential to produce both operational and strategic effects: degrading military capabilities while simultaneously increasing the political and security costs associated with hosting them.
The conflict reinforces that counterspace activity is not confined to actions occurring in orbit. The contest over access to and use of space increasingly includes terrestrial infrastructure, regional access, and the partnerships required to turn space capabilities into operational effects. For military space planners, protecting the satellite is only one part of protecting the capability. Resilience must also account for the ground segment, the networks connecting it, and the access and partnerships that allow those systems to operate.
Image from Khayyam Satellite: “Developed by Russian JSK BARL company, Khayyam has a spatial resolution of 0.7 meters. Iranian specialists have reportedly developed a super-resolution image-processing technique capable of reconstructing imagery with an effective spatial resolution of 35–45 cm.” (@HEMemarian via X)
Seven Sons: Harbin Institute of Technology
We recently dove into Nanjing University of Science and Technology, where we highlighted their contributions to China’s blossoming space program as one of the Seven Sons of National Defense. This week, we examine the Harbin Institute of Technology (HIT). HIT was established in 1920 and is known as “the cradle of engineers.” In terms of school prestige, HIT has led 11 national science and technology awards, with four projects listed among the Top 10 Scientific and Technological Advances in Chinese Universities.
Specifically for the space domain, HIT launched China’s first university-developed satellite, pioneered the country’s first space-to-ground laser communication, and developed a new, magnetic-focusing Hall-effect electric thruster. Additionally, they were instrumental in the testing of a robotic arm onboard the Tiangong-2. HIT technologies have proven to be vital towards some of the most significant accomplishments across national space missions. For example, they supported the Chang’e-5 and Chang’e-6 sample return missions. Research from HIT certainly drives the development of space capabilities for the PLA, but they also contribute directly to its workforce. Data from 2019 shows that 88 graduates directly joined the PLA upon graduation. That same year, 170 graduates went on to work for China Aerospace Science and Technology (CASC), which serves as China’s main contractor for its space program.
Graduates Who Directly Joined the PLA Upon Graduation (CSET)
One of the most notable research papers HIT produced came from authors linked to its State Key Laboratory of Robotics and Systems. The paper, titled “China's Space Robotics for On-Orbit Servicing: The State of the Art” explicitly mentions the SJ-7 and SJ-21, describing the latter as having acheived technological breakthroughs for alleviating space debris threats in GEO. More importantly, it discusses the ongoing evolution from manipulating cooperative to uncooperative satellites. Specifically, the authors state “current evolutionary trends of on-orbit servicing tasks are showing rapid progression, from elementarily clamping cooperative LEO spacecraft via a single manipulator under master-slave teleoperation, to sophisticatedly manipulating uncooperative GEO spacecraft via multiple manipulators with physical telepresence.” In particular, the mention of physical telepresense could suggest the use of virtual reality or even haptic feedback for operators on the ground. Referencing the SJ-7 and SJ-21 as benchmarks for how this technology is evolving is interesting, considering the SJ-21 notably moved a defunct satellite in GEO back in 2022.
More recently last year, “Autonomous Spacecraft Threat Avoidance via Trajectory Prediction and Deep Reinforcement Learning” was published by members of the Department of Control Science and Engineering, Harbin Institute of Technology. What makes this paper interesting is that it references adversarial threats explicitly as the basis for maturing autonomous threat avoidance. The authors state, “Non-adversarial space debris and defunct spacecrafts, as well as adversarial space targets with ambiguous intention, constitute the potential threats to on-orbit spacecrafts. Traditional decision-making strategies for spacecraft control rely on highly accurate models, which can be challenging to construct and computationally expensive under uncertain conditions in reality.”
Specifically, this paper proposes an autonomous threat avoidance decision-making strategy for use by spacecraft. Notably, it calls for the development of a Conditional Variational Autoencoder (CVAE)-based predictor to estimate future trajectories of space targets by leveraging previously collected trajectories from prior missions. Satellites today rely heavily on Kalman filters, specifically for navigation, orbit tracking, and steering. CVAEs use deep neural networks to learn complex, non-linear data patterns, while Kalman filters rely on classical probability rules with fixed mathematical assumptions. In short, a highly-complex environment with manuevering spacecraft will require an advanced predictor, such as the CVAE proposed here, to be able to avoid collisions and threats.
These are just a few examples of the work accomplished by HIT to help drive the on-orbit developments seen from China over the last decade. Given their successes, expect HIT along with the other Sons of National Defense to continue advancing China’s on-orbit capabilties.
Inside the Satellite: Understanding the Cyber Attack Surface
As space systems become more connected, software-driven, and commercially integrated, the cyber risks surrounding them are expanding as well. This article is part 1 of a series which explores where those vulnerabilities exist, how adversaries could exploit them, and—most importantly—how a cyber compromise could translate into real operational effects in space and on Earth.
When most people think about threats to satellites, they picture something physical: a missile destroying a spacecraft, a laser interfering with a sensor, or signal jamming. However, the most disruptive threats may be the ones you never see coming. Cyber threats are these less visible threats, but they can potentially affect many of the same capabilities. Modern satellites rely on computers, communications links, processors, sensors, and interconnected subsystems to perform their missions. In many ways, a satellite is a computer system operating hundreds—or thousands— of miles above Earth.
That dependence on digital technology creates a cyber-attack surface that extends well beyond the satellite itself. Space operations rely on an interconnected architecture that includes the space segment, the communications or link segment, the ground segment, and the user segment. Increasingly, commercial infrastructure, cloud services, software, and supply chains also connect these segments. Research on space cybersecurity therefore treats the problem as much broader than simply "hacking a satellite." Potential attack vectors can exist across the space, ground, user, communications, cloud, and supply-chain environments.
This article begins with the most recognizable part of that architecture: the satellite itself.
A satellite may appear to be a single system, but is part of a much larger interconnected network. Understanding how a satellite functions within that network begins with looking at the systems operating inside the spacecraft itself. Satellite systems are complex, consisting of numerous interconnected subsystems working together. For example, NASA identifies several spacecraft capabilities, to include communications, flight computing and avionics, guidance, navigation and control, power, propulsion, software and autonomous systems, and thermal management. However, the exact configuration of satellite subsystems varies according to the spacecraft and its mission, but several subsystems are common:
WGS at El Segundo, CA – AmericaSpace
Command and Data Handling (C&DH) functions as part of the satellite’s central nervous system. Onboard computers and processors receive commands, process information, store data, and coordinate activities among other spacecraft systems.
Telemetry, Tracking, and Command (TT&C) provides a critical connection between the spacecraft and operators on Earth. Telemetry tells operators about the satellite's condition, tracking helps determine its position, and command capabilities allow operators to direct spacecraft activities.
Attitude Determination and Control (ADCS) determines and controls the spacecraft's orientation. This allows a satellite to point an antenna toward Earth, orient solar arrays toward the Sun, or direct an imaging sensor toward a specific location.
Guidance, Navigation, and Control (GNC) helps determine where a spacecraft is and how it should move or maneuver. NASA describes GNC as integral to vehicle flight performance and mission requirements.
Electrical Power Systems (EPS) generate, store, regulate, and distribute the electrical power needed to operate the spacecraft. Without sufficient power, even a completely functional payload cannot perform its mission.
Thermal control systems keep spacecraft components within acceptable temperature ranges, while propulsion systems enable orbital maneuvers, station keeping, and other spacecraft movements.
Finally, the payload performs the satellite's primary mission. Depending on the spacecraft, that could mean taking images, collecting weather information, providing communications, detecting missile launches, or performing scientific observations.
Connecting these functions are onboard computers, processors, memory, firmware, software, and internal data interfaces. NASA specifically describes modern spacecraft avionics in terms of commanding and data-handling architectures and identifies mission-critical embedded software, software integration, and hardware-in-the-loop systems as important parts of spacecraft development. This interconnectedness is where cyber becomes important.
The Cyber Attack Surface
According to NIST, the increasing dependence of space systems on digital technologies has expanded the number of potential pathways through which cyber vulnerabilities may be introduced or exploited. A satellite does not operate independently; it functions as part of a broader architecture in which spacecraft, ground infrastructure, communications links, software, and users continuously exchange commands and data. Collectively, these interconnected components and interfaces constitute a cyber attack surface—the points within a system through which an adversary may attempt to gain unauthorized access, manipulate information, disrupt operations, or otherwise affect system functionality.
Within the space segment, cyber risk is closely tied to the satellite's dependence on onboard computing and communications. Modern spacecraft rely on processors, memory, flight software, firmware, and internal data buses to coordinate activities among subsystems. External communications links enable operators to transmit commands to the spacecraft and receive telemetry and mission data in return. Software and configuration updates may also provide mechanisms for modifying spacecraft functionality after launch. While these capabilities are essential to satellite operations, each interface represents a potential point of exposure that must be protected against unauthorized access or manipulation.
The relationship between these components is particularly important when considering cyber risk. A command generated by an authorized operator may pass through terrestrial networks and a ground station before being transmitted across a radio-frequency link to the spacecraft. Once received, onboard systems authenticate and process the command before directing the appropriate subsystem to perform an action. Telemetry and mission data travel through a similar chain in the opposite direction. Cybersecurity must therefore protect not only individual components but also the integrity and authenticity of the information exchanged between them.
This interconnected architecture means that a vulnerability in one component may have consequences elsewhere in the system. Compromise of a communications interface, onboard software, command-processing function, or data pathway could potentially influence the operation of another spacecraft subsystem. The cyber risk to a satellite is therefore best understood not as a single vulnerability or access point, but as a function of the interdependencies among hardware, software, communications, and spacecraft control functions.
Conceptually, the process looks like this:
Cybersecurity helps ensure that the person issuing the command is authorized, the command has not been altered, the satellite recognizes it as legitimate, and the receiving subsystem performs the intended action. If any portion of that chain is compromised, the consequences can extend beyond the compromised computer or network.
From Cyber Effect to Space Effect
This is what makes cybersecurity particularly important to space operations. For example, unauthorized access to mission data could compromise its confidentiality. Manipulated telemetry could provide operators with inaccurate information about spacecraft health. Interference with command functions could prevent operators from controlling a satellite
Compromised software could affect how an onboard computer processes commands or communicates with other spacecraft subsystems. In 2023, the European Space Agency demonstrated this risk using its OPS-SAT nanosatellite. During a controlled cybersecurity exercise, researchers exploited a vulnerability in software uploaded to the spacecraft and gained access to its control layer. The researchers were then able to manipulate imagery and change the satellite's attitude, causing the spacecraft to rotate away from its intended orientation. Although the exercise was controlled and the satellite was safely restored, it demonstrated how compromising software can move beyond a digital effect and influence the physical operation of a spacecraft.
Space Force Doctrine Note explains in more serious circumstances, manipulation of spacecraft functions could potentially affect payload operations, communications, power management, spacecraft orientation, or other mission-critical functions.
The U.S. Space Force's Space Systems Command has characterized satellite hacking as a real and growing space threat, emphasizing that cyber risk is not limited to traditional terrestrial computers. NIST similarly notes that as space capabilities become increasingly important to critical infrastructure, the potential consequences and corresponding risks associated with cyberattacks increase.
When people think about a cyberattack against a satellite, the most dramatic scenario often comes to mind: an adversary gains control of the spacecraft and begins issuing unauthorized commands. However, compromising a space system does not necessarily require taking control of the satellite itself.
An early example occurred in 1999, when 15- year-old hacker Jonathan James gained unauthorized access to NASA computer systems and downloaded proprietary software associated with supporting the International Space Station’s physical environment, including temperature and humidity control. NASA subsequently took affected systems offline for approximately three weeks while it investigated and restored operations.
James did not hijack a spacecraft, but the incident illustrates a much broader cybersecurity problem: an attacker does not need complete control of a satellite to affect the systems that support a space mission.
Jonathan James – Instagram
Cyber operations can target the computers, software, networks, communications links, ground infrastructure, and data upon which spacecraft operations depend. Focusing only on the possibility of someone “hijacking” a satellite can therefore obscure the larger issue—the space system as a whole presents a cyberattack surface.
An attacker may not need control of the satellite to affect the mission. Compromised data could undermine the information operators and decision-makers rely on. Disrupted communications may prevent information from reaching users. Interference with command links could limit an operator’s ability to control the spacecraft. Even the compromise of a single subsystem could degrade performance or prevent the satellite from accomplishing part of its mission.
In other words, the significance of a cyberattack is not determined solely by how much of the satellite an attacker controls, but by what operational effect the compromise produces. The more useful question, therefore, is not simply: “Can an adversary hack a satellite?” It is: “What part of the space system could an adversary compromise—and what mission effect could that compromise produce?”
The Satellite Is Only One Part of the Problem
Understanding the satellite's internal architecture is the first step toward understanding the larger cyber threat to space operations. But the spacecraft represents only one part of the overall attack surface.
The satellite communicates with antennas and ground stations. Ground stations connect to networks and mission systems. Operators use computers and software to create and transmit commands. Satellite data may travel through different segments before reaching the people who depend on it. This is why NIST's work on space cybersecurity extends beyond spacecraft and includes specific guidance for the satellite ground segment, including the systems responsible for command and control of satellite buses and payloads.
The challenge is becoming more important as the number and diversity of satellites increase. Commercial organizations now operate alongside governments, militaries, universities, and other organizations in space. At the same time, reduced barriers to space access have contributed to thousands of satellites operating in orbit and a much wider variety of actors participating in space activities. The result is a space environment that is increasingly interconnected—and increasingly dependent on cybersecurity.
Cyber Risk Doesn't Stop at the Atmosphere
The central point of this first article is simple: satellites are cyber-physical systems. Computers and software control physical spacecraft. Communications networks connect operators on Earth to systems in orbit. Data moves continuously between spacecraft, ground infrastructure, and users. A cyberattack against one component can therefore create effects elsewhere in the architecture.
A cyberattack does not need to seize complete control of a satellite to affect its mission. Compromising the confidentiality of sensitive information, manipulating the integrity of data, denying communications, or disrupting a critical subsystem may be enough to degrade—or even deny—the capability the satellite was designed to provide. Understanding these dependencies is therefore fundamental to understanding cyber threats to space. But the cyber story does not begin in orbit.
Long before a satellite reaches the launch pad, it has already passed through an extensive network of manufacturers, suppliers, software developers, and technology providers. Its processors, memory, firmware, communications equipment, sensors, and thousands of other components may originate from different companies and locations around the world.
As the commercial space industry expands and spacecraft increasingly incorporate commercially available technologies, that network becomes larger—and potentially more difficult to secure. So perhaps the next question is not simply, “How do we protect a satellite from a cyberattack?” But rather, “What if the vulnerability was already there before the satellite ever left Earth?”
Next in the series, we’ll follow the cyber risk back to where the satellite begins—on Earth. As commercial technology and COTS components become increasingly common in spacecraft, processors, software, firmware, and hardware may pass through complex global supply chains long before reaching the launch pad. The next cyber vulnerability may not begin in orbit—it may already be built in.
Pics o’ the Fortnight!
China Rapidly Developing Lop Nur Airbase. Lop Nur has been the landing site for previous Space Plane Landings. “The facility is used to test experimental platforms and next-generation combat aircraft, sporting one of the longest runways in the world at 16,400 feet. It has transformed from a relatively austere and remote airstrip into an increasingly sprawling PLA flight-test center over the past few years.” Watch Time Lapse Video. (@ianellisjones via X)
“After an 8-year trek to Mercury, BepiColombo will finally split into two spacecraft ready to track down the secrets of the least-explored planet in the inner solar system.” (space.com)
Possible Catch & Release Exercise On-Orbit. Per JCO Reporting China’s Shenlong Space Plane (67689) Released A Maneuvering Object, Object J (100681), on 7 Sep 2026. By 10 Sep 2026 JCO Reporting Indicated Object J may have been Captured by Shenlong. s2a Image Shows 2 Distinct Objects Earlier on 10 Sep. Watch Video. (@s2a_systems via X)
“Taiwan’s capital Taipei (left), with red lines added to show where a lot of the machinery of state is located (Presidential Office etc). Photo 2 (right) is more-or-less an exact replica of those gridlines, built in the last few years. But where? Inner Mongolian desert, China.” (@theiaincameron via X)
You must be logged in to post a comment.