The Ground Segment Is the Sovereignty Question
On 13 August 2026, New Zealand's security intelligence agency did something it has not done before in four years of public threat reporting: it put a name to an attempt to install intelligence-gathering hardware on New Zealand soil, and named a Chinese state-linked institute as the party behind it.
The New Zealand Security Intelligence Service's Security Threat Environment 2026 report disclosed that Purple Mountain Observatory, an institute of the Chinese Academy of Sciences, sought to install ground-based space infrastructure in New Zealand through a local company NZSIS says was "likely unaware" the equipment could collect intelligence of military value. NZSIS worked with partner agencies to disrupt the attempt. It says this was not the institute's first try, and further attempts are likely.
This series has tracked the vulnerability of the ground segment, the antennas, receivers and processing hardware that connect orbital infrastructure to Earth, since a ground-segment attack disabled roughly 80,000 satellite modems across Europe in February 2022 without a single satellite being touched. Every ground-segment instance this series has reported since has been international. This is the first domestic one, named by a New Zealand intelligence agency rather than a cybersecurity vendor or a trade publication. The location has changed. The category has not.
NZSIS describes Purple Mountain Observatory as having close ties to the government in Beijing. Director-General Andrew Hampton framed the finding in terms of geography: New Zealand's South Pacific location makes the country "attractive to threat actors who are unsentimental in their pursuit of our information," useful for tracking satellites over the Asia-Pacific and filling coverage gaps other locations cannot. Separately, Hampton described the current threat environment as the most challenging of recent times. NZSIS names China as the only country New Zealand has detected conducting espionage at scale.
The finding was independently corroborated within 24 to 48 hours across NZ Herald, ABC News, The Japan Times and The Epoch Times, each carrying a different emphasis rather than repeating a single wire text. NZ Herald centred Hampton's own words. The Epoch Times drew on RAND's China Aerospace Studies Institute, which its reporting says classifies Purple Mountain Observatory as a "limited defence partner" with a substantial record of publications co-authored alongside Chinese defence entities. That classification rests on a single outlet's characterisation of RAND's own data; a direct attempt to read RAND's page this week returned an access error, so the figure is reported here as reported, not independently verified, and should be read with that qualification attached.
The Chinese Embassy in New Zealand denied the characterisation, calling the allegations "entirely groundless and fabricated out of thin air." NZSIS's finding is its own agency assessment. The Embassy's response is the named party's own account. Neither is adjudicated here; both are reported as what each party said.
Neither NZSIS nor any outlet reporting on the finding named the New Zealand company involved, the method of disruption, or the specific location. Those details remain undisclosed.
The ground segment, finally at home
Space Mafia maps the orbital threat surface across five segments: Space (the satellites themselves), Ground (the antennas and stations that talk to them), User (the terminals and devices), Communications Links (the signal path between them), and Supply Chain (everything that builds and maintains the rest). This series introduced that architecture in May, using the ViaSat KA-SAT attack as the canonical Ground-segment case: a cyberattack on ground equipment already in service, executed from outside New Zealand, reported by a cybersecurity vendor months after the fact.
The Purple Mountain Observatory finding is a different kind of Ground-segment event. It is not a breach of equipment already operating. It is an attempt to install the equipment in the first place, through what NZSIS describes as an arrangement concealed from the local company that hosted it. Read against the five-segment architecture, this is the User and Supply Chain seams doing the work a direct technical attack did in 2022: the party behind this attempt did not need to breach a network. It needed a willing, unwitting counterparty.
That distinction matters for how this series has tracked adversarial state behaviour in orbit. The Adversarial Kardashev framework, introduced earlier this year to track coercive or intelligence-driven state orbital strategy, has so far described direct action against infrastructure an attacker does not control. This finding gives the framework its first domestic instance of something structurally different: an approach that worked through a commercial relationship a New Zealand company entered in good faith, where the equipment's true purpose was concealed from the host rather than extracted from it by force.
A jurisdiction, not a vacuum
The Pirate Radio Parallel that runs through Space Mafia describes orbital jurisdiction as a governance gap: activity that sits beyond the reach of any single national court, the way 1960s radio ships broadcast from international waters until regulation caught up. Every prior use of that parallel in this series has concerned altitude. Ground-based space infrastructure sits inside New Zealand's own jurisdiction, in principle fully governable from the moment the first antenna goes into the ground.
What the Government Communications Security Bureau, the GCSB, disclosed in March complicates the "in principle" part. Five months before NZSIS named Purple Mountain Observatory, the GCSB told the NZ Herald there had been several deceptive efforts by unnamed foreign entities over the previous five years to establish or use similar ground-based infrastructure, at locations it would identify only as being in the South Island. It declined to name any entity, give dates, or release the underlying intelligence, on the basis that disclosure would be likely to harm national security and could hand an advantage to whoever attempts it next.
Those two disclosures should not be read as one story. NZSIS's August finding concerns a specific institute. The GCSB's March statement described a pattern, plural and unnamed, that may or may not include the same activity. New Zealand's own record does not say. What the two disclosures do show, read together, is a shift in posture between the country's two principal intelligence agencies within a single year: GCSB, asked directly in March, chose not to name anything more specific than a region. NZSIS, in its own annual public report five months later, named an institution. That is an observed institutional fact, not evidence that either agency judged correctly or incorrectly, and not a basis for guessing why either made the choice it did.
Two readings of the same disclosure
Space Mafia's Heaven Vector and Skynet Vector framework asks the same question of every development in this space: who benefits from the way this was handled, and who is left exposed? Applied to an act of public disclosure rather than a piece of hardware, both readings are available from the same set of facts.
The Heaven Vector: an intelligence agency naming a specific threat, rather than managing it entirely out of public view, gives citizens, companies and allied governments the information needed to recognise and decline a similar approach themselves. That is a genuine transparency dividend, and one the GCSB's March non-naming did not provide.
The Skynet Vector: the same disclosure, without independent verification of the underlying intelligence, asks the public to accept a state security agency's account of a foreign institution's intent on the agency's word. That gap, between what an intelligence service knows and what it can prove to an outside observer, is exactly what Space Mafia's governance argument interrogates at orbital altitude. This week, it shows up at ground level instead.
The same coastline, two kinds of ground segment
New Zealand already hosts a ground segment it built in the open. The Awarua Satellite Ground Station, run by SpaceOps NZ between Invercargill and Bluff, is the country's most strategically significant commercial ground-based space infrastructure, valued for its southern Pacific location and low electromagnetic interference. It is installing two eleven-metre antennas this year for satellite positioning work with Lockheed Martin Australia, and its existence, ownership and purpose are a matter of public record.
NZSIS did not disclose where the Purple Mountain Observatory attempt took place. This article draws no connection between it and Awarua; none exists in the public record. The two sit as a contrast rather than a link: the same country, quite possibly the same coastline, hosting one ground segment New Zealand chose to build in daylight and, per this week's finding, at least one attempt to build another in the dark.
New Zealand's Ground-Based Space Infrastructure regime, the GBSI Act, established under the Outer Space and High Altitude Activities Act, requires operators of ground-based space infrastructure to hold authorisation and file annual security reporting. Its transitional automatic-authorisation period closed on 29 July 2026, so the regime is now the enforced default for anyone operating this kind of equipment. NZSIS has not stated whether the company involved in the Purple Mountain Observatory attempt held, needed, or should have needed authorisation under that regime, or whether the attempt predates the closure of the transitional period. That is an explicit gap in the public record, not a conclusion this article can reach by inference, and not evidence for or against the regime's adequacy either way.
What the finding does offer New Zealand organisations is a template for the question worth asking before, not after, hosting equipment on someone else's behalf. NZSIS's own language is instructive here: the company involved was "likely unaware" of what it was hosting, which means the arrangement looked, from the inside, like an ordinary commercial one. Four questions travel well beyond this specific case, and none of them requires suspicion of any particular country. What, precisely, does the counterparty say the equipment does, in writing, in enough technical detail to check against what actually gets installed? Who owns and operates the equipment once it is running, and does that answer match who signed the contract? Is there an independent technical assessment of what the equipment can actually do, separate from the vendor's own description of it? And does installing it trigger a licensing or authorisation obligation, under the GBSI Act or otherwise, that the counterparty has not raised. A board asking a fifth question, whether anyone has checked the answers to the first four since the equipment was installed rather than only before, closes the loop the Purple Mountain Observatory case shows can otherwise stay open indefinitely.
What the record does not yet say
Three things about this finding remain open, and this series will not fill them by inference. First, NZSIS's account that this was not the institute's first attempt and the GCSB's several deceptive efforts over five years describe what may be the same underlying pattern, overlapping activity, or two distinct sets of incidents. No source reconciles the two, and this article treats them as related but analytically separate rather than combining them into a single count. Second, no equivalent 2026 disclosure has surfaced from another Five Eyes partner describing a similar attempt on ground-based space infrastructure. That may mean New Zealand's experience is unusual, that an equivalent has occurred elsewhere without public disclosure, or simply that this week's research did not find it; the absence is stated, not explained. Third, whether the GBSI Act's authorisation regime applied to, or would have caught, this specific attempt is not stated anywhere in the public record, and this series will not answer that question by inference from the regime's own mechanics.
What is clear is that the Ground segment this series mapped in May now has a domestic instance, and the disclosure that produced it broke with five months of a partner agency's own more cautious practice. Whether NZSIS's shift toward naming becomes the standard for this pattern of activity, or for others, is the question worth watching heading into next year's threat assessment cycle.
The question this leaves standing
Every ground station is, in the end, a decision someone made to trust a counterparty they could not fully verify. Most of those decisions are unremarkable. This one, NZSIS says, was not. The gap between an ordinary commercial arrangement and one that quietly routes intelligence of military value offshore is not always visible from inside the arrangement, which is exactly why the New Zealand company involved is described as having been unaware.
The ground segment does not have to be a black box, even when it sits inside contested territory. The Consultative Committee for Space Data Systems, the international standards body whose open, publicly published protocols already govern how most of the world's ground stations talk to orbiting hardware, exists precisely so that no single vendor or government controls the specification. Universities, small agencies and amateur operators build and audit their own ground infrastructure against those same open standards, the opposite of what NZSIS describes this week: equipment installed without the host company understanding what it was built to do. Open standards will not stop a determined state actor on their own. They remove one excuse for a host organisation not knowing what a piece of ground infrastructure actually does.
New Zealand already sits inside one allied framework built for this kind of coordination problem. The Combined Space Operations Initiative, a multinational military space information-sharing framework whose members include New Zealand, the United States, the United Kingdom, Australia, Canada and several other allied states, exists to give member states a shared operating picture of threats to space-related infrastructure, the ground segment included. This week's finding is a reminder of why that coordination matters at ground level, not only in orbit: a state-linked actor seeking physical access to infrastructure that talks to orbiting hardware, through channels ordinary enough that the host does not see what it has agreed to, is exactly the category of threat a shared operating picture exists to catch earlier. Whether this attempt was flagged through that channel, through another, or independently by NZSIS is not stated in the public record, and this series does not claim otherwise.
Has your organisation ever had to make a judgement call about a piece of infrastructure, a vendor relationship, or a partner you could not fully verify, without knowing at the time whether you were being careful enough? What made you decide to ask more questions, or what made you decide the questions were not necessary?
This is one of seven weekly series in The Hamberger Report. Subscribe on LinkedIn and the next one arrives in your feed.
• • •
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. I write as director of Te Pono Limited; the views are personal and do not represent the position of any client, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance, and it is politically neutral.
• • •
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. Space Mafia examines the sovereignty implications of orbital compute infrastructure.
• • •
This article was produced with AI assistance under my direction. Research, drafting and images pass through a pipeline I built and govern: automated gates for source verification, forbidden language and political neutrality, and my own review before anything is published. The tools include Claude, Gemini and Openart. The frameworks, arguments and editorial judgements are mine and are the same discipline I apply to the AI systems I audit for clients. AI accelerated the work; the thinking, and the responsibility for it, are mine.
• • •
[1] New Zealand Security Intelligence Service. "Security Threat Environment 2026." 13 August 2026. https://www.nzsis.govt.nz/our-work/new-zealands-security-threat-environment/security-threat-environment-2026
[2] NZ Herald, David Fisher. "NZSIS report reveals Chinese space tracking bid in New Zealand." 12 August 2026. https://www.nzherald.co.nz/nz/nzsis-report-reveals-chinese-space-tracking-bid-in-new-zealand/SVCASYKHPVCPBH5H4FTEVH466U/
[3] ABC News. "Chinese state-linked observatory sought NZ site, spy agency says." 13 August 2026. https://www.abc.net.au/news/2026-08-13/chinese-state-linked-observatory-sought-nz-site-spy-agency-says/107034742
[4] The Epoch Times, Rex Widerstrom. "What we know about a Chinese attempt to install a satellite station in New Zealand." 17 to 18 August 2026. https://www.theepochtimes.com/china/what-we-know-about-a-chinese-attempt-to-install-a-satellite-station-in-new-zealand-6075921
[5] ABC News, republishing RNZ. "China denies espionage, foreign interference in New Zealand." 14 August 2026. https://www.abc.net.au/news/2026-08-14/china-denies-espionage-foreign-interference-in-new-zealand/107040130
[6] The Spinoff. "Chinese space institute tried to set up monitoring station in New Zealand." 13 August 2026. https://thespinoff.co.nz/politics/13-08-2026/chinese-space-institute-tried-to-set-up-monitoring-station-in-new-zealand
[7] Ministry of Business, Innovation and Employment. Ground-Based Space Infrastructure licensing guidance. https://www.mbie.govt.nz/science-and-technology/space/apply-for-a-licence-or-permit/ground-based-space-infrastructure
[8] Via Satellite. Ground-segment vulnerability reporting, cited in this series' prior coverage of the ViaSat KA-SAT attack, April to May 2026. No URL captured.

