A satellite ground station
– Getty Images

The U.K. government has warned that the shift to cloud-connected satellite ground stations is opening new attack surfaces for cybersecurity adversaries.

A study by Actica Consulting for the Department for Science, Innovation, and Technology (DSIT) suggests the move toward ground station/segment-as-a-service (GSaaS) could lead to hackers stealing data from satellites and even take down essential services.

The study suggests potential intrusions could have physical consequences – including altering satellite positioning or disabling payloads – making attacks more damaging than those affecting pure IT systems.

“Space-ground systems have unique vulnerabilities, including timing attacks and command injection, which can be particularly critical during launch and other time-sensitive operations,” the study reads. “While cloud integration does not always expose these vulnerabilities, some stakeholders raised concerns during interviews that the implications of integrating satellite command and control into the cloud are not yet fully understood.”

The cloud supporting the stars

The Actica-led DSIT study was published as the U.K. looks to build out its space sector, with Amazon’s expansion into the country’s nascent low-Earth orbit (LEO) market among the major efforts. The tech giant has enlisted Vodafone, Verizon, and Vrio to support its Kuiper satellite broadband project, which is expected to go live in the U.K. later this year, having received regulatory approval from Ofcom.

To support emerging deployments like Project Kuiper, cloud computing has become increasingly tied together with ground stations, with the technology helping to manage and process the reception, processing, and distribution of satellite data.

Amazon has its own such offering, AWS Ground Station, unveiled back in 2018. The fully managed service lets ground station operators downlink data and provide satellite commands via the cloud.

AWS Ground Station map
– AWS

In a bid to expand the service, the hyperscaler has been trialing the tech for data downlinks from satellites – a process traditionally performed by each ground station before being transferred to a central station. In tests alongside NASA and the European and Japanese space agencies (ESA and JAXA), AWS processed downlink data from satellites using its cloud servers, to bring processing wait times down to near real-time.

But the advancements brought about by integrated cloud computing into ground stations are a cause for caution, according to DSIT’s study. While the technology offers gains in speeding up data processing, it could also expand operators’ attack surfaces, introducing new interfaces and dependencies that, if not properly secured, could be exploited.

The study warns that unclear lines of responsibility between cloud providers and satellite operators could create dangerous gaps in security. In a worst-case scenario of the “shared responsibility” model, a misconfiguration or compromised interface could allow malicious actors to disrupt communications, hijack command sequences, or interfere with time-critical operations.

“Legacy systems also pose persistent vulnerabilities, as many were not designed with modern cybersecurity practices in mind,” the study reads. “Integrating these systems with cloud-based GSaaS solutions requires careful consideration to avoid exposing outdated interfaces and insecure protocols.”

Stakeholders interviewed for the study called for stronger authentication, encryption, and isolation measures, alongside greater government support for smaller operators that may lack in-house cybersecurity expertise.

“Increased threat modeling, red teaming, and continuous monitoring can enhance security posture,” the findings suggest. “By fostering industry-wide awareness and best practices, stakeholders can ensure that GSaaS adoption remains secure, resilient, and aligned with mission-critical space operations.”

While there’s currently no regulatory framework governing ground station infrastructure in the U.K., the report suggests the country’s Civil Aviation Authority could impose licensing conditions that would influence cybersecurity practices, including requiring mitigations and third-party assurances.

The report also suggests ground station operations could be required to demonstrate how cybersecurity risks are being managed, “including through supply chain evaluation, data protection controls, and third-party access restrictions.”