With $800 of off-the-shelf equipment and months’ worth of patience, a team of U.S. computer scientists set out to find out how well geostationary satellite communications are encrypted. And what they found was shocking.

Close to half of the communications beamed from satellites to the ground that the researchers were able to listen in on were not encrypted. This included sensitive data including cellular text messages, voice calls, as well as sensitive military information, data from internal corporate and bank networks, and the in-flight online activity of airline passengers.

The research team, led by Aaron Schulman and Nadia Heninger, two computer science professors at the University of California San Diego, then set out to find out which companies and government agencies were failing to encrypt data in order to contact them and disclose the vulnerabilities.

In this study, researchers focused on geosynchronous (GEO) satellites, which orbit the Earth at a fixed altitude and position around the equator.

“Given that any individual with a clear view of the sky and $800 can set up their own GEO interception station from Earth, one would expect that GEO satellite links carrying sensitive commercial and government network traffic would use standardized link and/or network layer encryption to prevent eaves-droppers,” the researchers write in a paper presented in October at the CCS 2025 conference in Taiwan.

In several cases, the researchers’ findings led to immediate action. The team disclosed to T-Mobile that some of their satellite traffic was unencrypted and left text messages, user internet traffic and the content of voice calls vulnerable to eavesdropping. The company then quickly enabled encryption. Other organizations including Walmart and KPU Telecom have also enabled encryption in response.

Communications from Specific Satellites

There are 590 geosynchronous satellites orbiting the earth, with a wide variety of uses. These satellites also carry traffic on private networks for sensitive, remote commercial and military equipment. By placing a large satellite dish on the top of the computer science and engineering building at the UC San Diego Jacobs School of Engineering, researchers were able to intercept communications from 39 satellites during a seven-month period.

GEO satellites are known to be potentially vulnerable to eavesdropping. As a result, a cottage industry has arisen to try to listen in on signals using commercially available satellite dishes. High-quality free software is available to receive satellite signals, as long as they’re not encrypted. A thriving online community of enthusiasts publishes open databases of satellite coordinates and transponders. As part of their study, researchers contributed new software that automates both scanning for satellites and decoding these signals.

But until now, no one had tested on a large scale all the different types of satellite transmissions that can be eavesdropped on. The researchers believe their study is the most comprehensive to date of GEO satellites, their communications, levels of encryption and various communications equipment they carry. Many organizations don’t seem to realize that satellite traffic is not part of their internal network and can be captured if not encrypted, the researchers write. “There is a clear mismatch between how satellite customers expect data to be secured and how it is secured in practice,” they said.

Examples of Vulnerabilities in U.S. Communications Systems

Researchers captured data from two companies that provide in-flight entertainment: Intelsat and Panasonic. They were able to determine which airlines and which flights the data was coming from, as well as metadata including which websites passengers were visiting. Researchers even were able to capture audio from news shows, sports and other programs passengers were watching in flight.

In addition, other data the team decoded allowed them to find the names of vessels owned by the U.S. military together with both encrypted and unencrypted traffic from those vessels’ communication systems.

The vulnerability for cell phone communications, such as T-Mobile’s, happens when someone places a call in a remote area where the call is connected through a cell phone tower that routes through a satellite, which then beams the call to the cellphone company.

Phone calls can be encrypted at different levels. One layer of encryption comes into play from phone to cell phone tower and another from tower to tower. These last two layers get stripped away when a call gets transmitted via satellite, leaving the content of the call or text vulnerable if it’s not encrypted. The only way to protect call and text content is to encrypt that layer of data – this happens when making calls with Signal, or from iPhone to iPhone, for example.

This article was written by Ioana Patringenaru for the University of California San Diego. For more information, contact Ioana, This email address is being protected from spambots. You need JavaScript enabled to view it..



Magazine cover
Aerospace & Defense Technology Magazine

This article first appeared in the June, 2026 issue of Aerospace & Defense Technology Magazine (Vol. 11 No. 4).

Read more articles from the archives here.