The Sky Is Full of Secrets

US$800. That is what a team of UC San Diego researchers spent on off-the-shelf radio equipment before intercepting unencrypted data from nearly half of 39 geostationary satellites they monitored over seven months. The intercepted traffic included cellular phone calls and text messages, military vessel communications, corporate banking transactions, critical infrastructure operational data, and in-flight Wi-Fi activity [1].

While those researchers were scanning the sky with equipment cheaper than a decent laptop, three of the world's wealthiest companies were racing to fill that same sky with compute infrastructure on a scale the satellite industry has never attempted.

Last week, a security leader at a logistics company reached out after reading our piece on New Zealand's 1,000-launch expansion. "Andreas," she said, "we did the Hidden Space Operator assessment you recommended. But it led us somewhere we didn't expect. We started mapping which of our data flows transit satellite links, and we found seventeen dependencies we didn't know about. Maritime tracking, remote site connectivity, even some of our disaster recovery failover paths. None of them use end-to-end encryption at the satellite layer. We're essentially broadcasting in the clear."

That conversation captured something I have been tracking for weeks. The orbital economy is scaling at extraordinary speed. The security foundation beneath it is crumbling at equal pace. The "Don't Look Up" research from UC San Diego proves what Space Mafia argued from a governance perspective: the assumption that nobody was listening was always the weakest link in the chain [1].

The Three-Way Orbital Race

Three parallel developments in February 2026 reveal the scale of what is being built overhead.

SpaceX filed an application with the US Federal Communications Commission (FCC) on 30 January 2026 for a constellation of up to one million satellites. The FCC's Space Bureau accepted the filing for public comment within five days. FCC Chairman Brendan Carr has signalled what he calls a "Default to Yes" framework for satellite applications. SpaceX is seeking waivers from standard processing rounds (which allow competitors to comment) and from deployment milestone requirements. Industry analyst Tim Farrar characterised the filing as a strategic positioning tool ahead of SpaceX's anticipated IPO [2][3]. The public comment period closes on 6 March 2026.

Amazon's Project Kuiper (marketed as Amazon Leo) launched its LE-01 heavy-lift mission on 12 February, deploying 32 satellites via an Ariane 64 rocket. The constellation now exceeds 200 satellites. The FCC approved an additional 4,500 satellites on 10 February, bringing the planned constellation to approximately 7,700. Amazon has announced over 20 launches scheduled for 2026 and more than 30 for 2027, with commercial service rollout planned for late 2026 [4].

Blue Origin's TeraWave, announced on 21 January 2026, is a 5,408-satellite constellation using a hybrid architecture: 5,280 satellites in low Earth orbit (LEO) and 128 in medium Earth orbit (MEO). The system targets up to 6 terabits per second of throughput and is designed for enterprise and data centre connectivity, not consumer broadband. Deployment is planned from late 2027 using Blue Origin's New Glenn launch vehicle [5].

The combined ambition: more than one million new objects in orbit within a decade, each one a potential node in a distributed compute network operating above terrestrial jurisdiction. Harvard astrophysicist Jonathan McDowell has observed that a constellation of that scale would require dedicated spacecraft for debris removal to prevent cascading collisions [3].

The Pirate Radio Parallel: Proof of Concept

In Space Mafia, I drew the parallel between unregulated satellite operations and the pirate radio stations that broadcast from international waters in the 1960s. The operators assumed nobody was listening closely enough to matter. The "Don't Look Up" research demolishes that assumption.

The UC San Diego team, led by researcher Aaron Schulman, monitored 39 geostationary satellites and found that approximately 48% transmitted data without encryption. The interception required no hacking, no sophisticated intelligence capability, and no security clearances. A rooftop antenna, a software-defined radio, and seven months of patience were sufficient to capture what the researchers described as a broad cross-section of satellite-dependent communications [1].

The implications extend beyond eavesdropping. Russia's Luch-2 satellite has approached at least 17 European geostationary satellites since 2023, positioning itself within their narrow data transmission beams. The European Space Agency (ESA) briefed EU defence ministers that at least 60% of commercial geostationary satellites serving Europe lack end-to-end encryption on their command uplinks [6]. Germany's defence minister described satellite networks as a critical vulnerability for modern societies [7]. When Luch-1 fragmented on 30 January 2026, Russia launched replacement-capable spacecraft (Cosmos 2589 and 2590) with assessed similar capabilities [6].

The pattern is instructive. The UC San Diego research proves that anyone with minimal equipment can intercept satellite communications. Russia's Luch programme demonstrates that state actors have been doing exactly this for years. And the three-way orbital race will place orders of magnitude more compute overhead without addressing the foundational security deficit.

This is where the Kardashev framework, introduced in earlier Space AI Monday analysis, needs a third category. SpaceX and Amazon represent what I have called Corporate Kardashev: scaling to escape terrestrial constraints. New Zealand's approach through the Outer Space and High-altitude Activities Act 2017 (GBSI Act), with its governance-alongside-capability model, represents Sovereign Kardashev. Russia's Luch operations reveal a third vector: Adversarial Kardashev, where actors exploit the governance gap created by the race between the other two.

The FCC's "Default to Yes" framework accelerates Corporate Kardashev. Adversarial Kardashev exploits the widening gap between deployment speed and security governance. The question for every nation, including New Zealand, is whether Sovereign Kardashev can keep pace.

The Software-Defined Attack Surface

The security problem is compounding. The satellite industry is shifting from fixed-function hardware to software-defined, reprogrammable platforms. Industry analysts project the number of software-defined satellites to grow from 234 in 2024 to over 10,000 by 2031 [8]. Companies like OrbitsEdge are conducting orbital AI demonstrations on compact processing units, and Loft Orbital has launched a dedicated AI business unit for space-based computing [8].

Each software-defined satellite is a node that can be updated, reconfigured, and, if inadequately secured, compromised. The CryptoLib vulnerability case is telling: an AI system identified a security flaw in satellite communication encryption software in four days that had gone undetected by human review for three years [8]. That is simultaneously a Heaven Vector outcome (AI improving security) and a Skynet Vector concern (the same capability available to adversaries).

The "Harvest Now, Decrypt Later" dimension makes this more urgent. Unencrypted satellite traffic intercepted today, whether by a state actor or someone with US$800 of equipment, can be stored for future decryption as quantum computing matures. Forrester projects that over 90% of Asia-Pacific enterprises will make quantum security a strategic priority in 2026 [9]. But satellite infrastructure operates on replacement cycles measured in decades, not quarters.

What This Means for New Zealand

New Zealand sits at the intersection of ambition and exposure. The country is ranked third globally for launch activity. The Space Minister announced an increase from 100 to 1,000 annual launches on 13 February 2026 [10]. The GBSI Act compliance deadline of 29 July 2026 requires organisations supporting space objects to register with the New Zealand Space Agency. Information Privacy Principle 3A (IPP 3A), taking effect on 1 May 2026, extends indirect data collection notification requirements to contexts that include orbital processing.

The sovereignty paradox is this: New Zealand is building regulatory frameworks (the GBSI Act, IPP 3A) that address domestically launched infrastructure. But New Zealand organisations, including those in maritime, agricultural monitoring, and remote connectivity, depend on foreign satellite infrastructure that the "Don't Look Up" research has shown to be demonstrably insecure. The GBSI Act governs what New Zealand launches. It does not govern the orbital layer that New Zealand's economy relies upon.

The Three Clocks framework from our earlier analysis remains relevant, with an addition. The Physics Clock (the CRASH Clock, measuring orbital collision risk) continues to accelerate. The Compliance Clock now has two near-term deadlines: the FCC's comment period on the SpaceX filing closes 6 March, and the GBSI Act compliance deadline arrives 29 July. The Industry Clock tracks New Zealand's $2 billion space industry target for 2030. And the "Don't Look Up" research has started a fourth clock: the Vulnerability Clock, measuring the gap between what is deployed in orbit and what is secured.

What Practitioners Should Do

Map your satellite dependencies. Extend the Hidden Space Operator assessment from our previous article to include data transit paths. Identify which of your communications, positioning, and operational data flows transit satellite links. Many organisations will find dependencies they did not know existed.

Verify encryption end to end. Satellite operators may advertise encrypted services, but the UC San Diego research found that encryption implementation varies by provider and by satellite. "Encrypted service" at the provider level does not guarantee encrypted transit at the satellite layer. Ask your providers for specific confirmation of end-to-end encryption on the satellite segments serving your data.

Conduct an orbital supply chain audit. The Hidden Space Operator concept from Space AI Monday #1 maps organisations with undisclosed space dependencies. This article adds a parallel: the Hidden Satellite Dependency, where your data transits foreign satellite infrastructure with no contractual security guarantees. For organisations in scope for GBSI Act compliance (deadline 29 July 2026) or IPP 3A (effective 1 May 2026), this audit is not optional.

Begin post-quantum planning for satellite-dependent data. If your organisation transmits data via satellite that would retain value for five years or more (financial records, health data, infrastructure configurations), the "Harvest Now, Decrypt Later" threat is already active against you. The Brookings Institution has called for an international code of practice for AI systems operating in space, including pre-authorised decision boundaries analogous to nuclear safety systems [9]. Your organisation does not need to wait for international frameworks to begin encrypting its own satellite-dependent data streams.

The Window Is Closing

The FCC comment period on SpaceX's million-satellite application closes on 6 March 2026. The GBSI Act compliance deadline arrives on 29 July. New Zealand's IPP 3A takes effect on 1 May. Each of these dates represents a governance decision point, and governance decisions made before scale is achieved are exponentially more effective than those made after.

The proposed US Space Infrastructure Act would designate space systems as critical infrastructure with mandated cybersecurity standards. The US National Reconnaissance Office's Space Cyber Program, launched in late 2025, focuses on integrating cybersecurity into satellite design from the outset rather than retrofitting it. The emerging international consensus is clear: collective defence, where commercial operators and government agencies synchronise threat intelligence, is the only viable model for orbital cybersecurity at this scale.

The sky is full of secrets. The UC San Diego researchers proved that with US$800. Russia proved it with Luch-2. And the three-way orbital race is about to fill that sky with an unprecedented density of compute infrastructure. The question is no longer whether someone is listening. It is whether we will secure the orbital layer before the window closes.

Has your organisation mapped its satellite dependencies? Do you know whether your data transits encrypted links, or whether you are broadcasting in the clear?


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. Space Mafia examines the sovereignty implications of orbital compute infrastructure.


I acknowledge the role of AI tools, such as Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, which assisted in drafting, editing and reviewing. They accelerated the process, but the first draft, revisions, vision, voice and final decisions were mine alone.


Published 23 February 2026. (c) Andreas Hamberger 2026. All rights reserved.


References

[1] Schulman, A. et al. (2026). "Don't Look Up: Exposing Unencrypted Satellite Communications." UC San Diego Jacobs School of Engineering. Presented February 2026. Also reported: HSToday (February 2026); Space.com (November 2025).

[2] FCC Space Bureau. (2026). Public Notice: SpaceX Gen3 NGSO Application Accepted for Comment. 4 February 2026.

[3] The Register. (2026). "SpaceX files for million-satellite constellation." 5 February 2026. Also: SatNews (31 January 2026); GearMusk (5 February 2026); Tim Farrar/TMF Associates commentary.

[4] GeekWire. (2026). Amazon Project Kuiper LE-01 launch coverage. February 2026. Also: CNBC (10 February 2026); Amazon press releases.

[5] Blue Origin. (2026). TeraWave constellation announcement. 21 January 2026. Also: SpaceNews, TechCrunch (January 2026).

[6] Financial Times. (2026). "Russia's Luch satellites shadow European spacecraft." 4 February 2026. Also: SatNews (4 February 2026); Foreign Policy (February 2026).

[7] Military.com. (2026). German Defence Minister and military space command comments on satellite vulnerability. 9 February 2026. Also: TechRepublic (5 February 2026).

[8] ABI Research. (2026). Software-defined satellite market projections. Also: OrbitsEdge, Loft Orbital announcements; AISLE/CryptoLib vulnerability case study (Black Hat 2025).

[9] Brookings Institution. (2025-2026). International code of practice for AI in space. Also: Forrester Asia-Pacific quantum security projections (2026).

[10] New Zealand Government. (2026). Space Minister announcement: increase from 100 to 1,000 annual launches. 13 February 2026. Also: GBSI Act compliance guidance, New Zealand Space Agency.

Previous
Previous

When the Cloud Burns: The AWS Strikes, Kinetic Warfare, and What Every Board Needs to Ask Now

Next
Next

A Thousand Rockets and a Dying Clock