Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Small Dish Satellite Systems Susceptible To Hacking
News & Analysis

Small Dish Satellite Systems Susceptible To Hacking

ISBuzz TeamBy ISBuzz TeamJanuary 15, 2014Updated:April 30, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Small Dish Hacking
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

LOS ANGELES—A California cyber-security firm has released a report illustrating that small-dish satellite systems are at a high risk of being hacked.

IntelCrawler’s report reveals that as many as 10,500 VSATs—very-small-aperture terminals—are open to attack in the United States alone.  Some of these are being used by critical infrastructure systems, including oil and gas industries.

VSATs function in networks that consist of three components:  a central hub (station on earth), a satellite, and VSAT earth stations/stabilized antennas.  A VSAT station sends outbound information to the satellite, whose transponder beams it back to earth to be picked up by other VSAT stations.  These, in turn, transmit the data to the hub.

VSAT networks can be hacked four ways:  jam, eavesdrop, hijack, and control.  What these four methods of infiltration have in common is tampering with the transmission in some way.  A hacker can overpower a receiver; replace a signal with another, such as by copying and altering files sent via the Internet, a.k.a. “spoofing”; or even gain control of a satellite to the extent that one can maneuver it in orbit.

It is the act of transmission which makes VSATs vulnerable.  As a result, it is very important to secure VSAT networks.

But the scan performed by InterCrawler has revealed that many owners of VSATs, from utilities industries in Australia to the Ministry of Civil Affairs of China Infrastructure, have not adequately protected their satellites.

VSATs are not intrinsically vulnerable.  Their levels of security, like most things, depend on how they are configured.  And in many instances, including in the United States, these satellites have been configured insecurely.

Specifically, many VSAT networks still have default factory password settings, which can easily be accessed from handbooks published online.  Some networks do not even require a password.

The problem is even bigger than that, however.  With the availability of search engines like SHODAN, which is known as the “Google for hackers”, not to mention geolocation technologies that can physically locate vulnerable VSATs, it is easier than ever to gain control of VSAT satellites themselves.

This fact is especially concerning given that the U.S. National Security Agency used satellites to gather information on American citizens.  A simple hack of a satellite could therefore expose this information to criminals, thereby threatening millions of individual Americans’ personal security.

Intercrawler has clearly revealed that VSATs can be vulnerable to hacking.  But its scan also indicates that much of this insecurity can be pinpointed to human error.

In addition to the various ways administrators can make critical infrastructure more secure, including taking networks off the Internet, it would appear that one can easily protect these industries’ VSAT networks by simply instituting a password.

Absent plugging these security holes, oftentimes with common-sense measures, sysadmins risk doing nothing and subsequently allowing malicious actors to steal data or even gain control of satellites that are potentially carrying sensitive information.

Dave BissonDavid Bisson | @DMBisson

Bio: David is currently a senior at Bard College, where he is studying Political Studies and writing his senior thesis on cyberwar and cross-domain escalation.  He also works at the Hannah Arendt Center for Politics and Humanities at Bard College as an Outreach intern.  Post-graduation, David would like to leverage his extensive journalism experience as well as his interest in computer coding and social media to pursue a career in cyber security, both its practice and policy.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Enhance Your Digital Crime and Security Practices Today

March 28, 20249 Mins Read

The Significance of Security Policies in Cybersecurity

February 25, 202412 Mins Read

Best Practices for Information Security Governance in the Digital Economy

February 9, 202412 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}