Skip to content
safemode.space
All incidents
2009-03-18 (approximate)
signal hijacking
link

Brazilian hijacking of US Navy FLTSATCOM transponders (Operation Satellite crackdown, 2009)

Confidence in this reading:
moderate

What happened

From the mid-1990s onward, radio technicians in Brazil used modified consumer equipment to transmit through the unauthenticated UHF repeater channels of the US Navy's Fleet Satellite Communications system and its UHF Follow-On successors. An ordinary amateur-radio transmitter operating in the 144 to 148 MHz band, fitted with a frequency doubler built from coils and a varactor diode, reaches the lower end of the 292 to 317 MHz uplink range; Wired reports the complete kit cost under 500 US dollars and the conversion was offered as a service for under 100. The transponders carried a large informal user base: truck drivers wanting better range than amateur radio, illegal loggers in the Amazon passing coded warnings about approaching enforcement, and drug traffickers and organised criminal groups coordinating operations. On 18 March 2009 the Brazilian Federal Police, working with the regulator Anatel and on coordinates supplied by the US Department of Defense, arrested 39 suspects across six states in an action called Operation Satellite; those charged included university professors, electricians, truckers and farmers. Nothing aboard the spacecraft was exploited or modified: an unauthenticated bent-pipe UHF repeater relays whatever reaches it at sufficient power.

A capacity-theft and unauthorised-access record, not a spacecraft-compromise record. The vulnerability is architectural rather than a defect: an unauthenticated bent-pipe UHF repeater will relay any signal that reaches it with enough power, so the vehicle behaved exactly as designed throughout. Overall confidence is moderate rather than high because effectively all reporting traces to one Wired article; the facts here come from a contemporaneous full-text repost naming Wired and Marcelo Soares as the origin, with the February 2008 FCC enforcement action separately attested.

Attack vector

Unlicensed ground transmitters built from commodity amateur-radio equipment and a varactor-diode frequency doubler, transmitting into the unauthenticated and unencrypted UHF uplink range of a bent-pipe military communications repeater.

Operational impact

Years of unauthorised third-party use of US Navy satellite communications capacity. No source reports loss of the spacecraft, denial of service to authorised users, or compromise of any on-board system.

Affected segments

link, space, ground

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • The participants built unlicensed transmit stations from modified consumer equipment and used them to reach a satellite they had no relationship with or authorisation to use. IA-0008.01 is that behaviour named, and the reporting describes it directly rather than by inference.

    https://www.wired.com/2009/04/fleetcom/

  • IMP-0006Theft
    high
    derived
    #

    The realised impact is theft of service. US Navy transponder capacity was consumed by unauthorised third parties for roughly fifteen years. Nothing was destroyed and no source reports authorised users being denied; capacity was taken, which is IMP-0006's subject. The evidence type is derived rather than direct: the edge follows from the reported facts of the record as a whole, and no verbatim excerpt was read against this technique in particular, unlike the two sibling edges on this record which each carry one.

    https://www.wired.com/2009/04/fleetcom/

  • The reporting is specific about the transmit equipment acquired and modified: an amateur-radio transmitter operating at 144 to 148 MHz, a frequency doubler built from coils and a varactor diode to reach the 292 to 317 MHz uplink range, and an antenna, for under 500 US dollars. Acquiring transmit-capable ground equipment for an unauthorised uplink is RD-0001.01.

    https://www.wired.com/2009/04/fleetcom/

  • The staging step is the identification and preparation of one specific delivery mechanism, the frequency-doubled amateur transmitter, refined and circulated as a repeatable recipe over roughly fifteen years and sold as a conversion service for under 100 US dollars. Derived rather than direct because no source frames the practice as capability staging.

    https://www.wired.com/2009/04/fleetcom/

  • Operating through an unauthenticated bent-pipe repeater necessarily means receiving its unencrypted downlink, which is how participants heard one another. The edge is derived from the mechanism the sources describe rather than from a reported act of intercepting US Navy traffic, which no source alleges.

    https://www.wired.com/2009/04/fleetcom/

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • No source reports US Navy or mission data leaving the system. The downlink carried the pirates' own voice traffic. Theft of capacity is recorded at IMP-0006; calling it exfiltration would assert a data loss no source supports.

  • Scope inversion. IA-0002 covers compromising the spacecraft's software defined radio to gain access. What the pirates modified was their own ground transmitter. Nothing aboard FLTSATCOM was reconfigured.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

  • Wired · Marcelo Soares

    Tier 2: Named reporting by a named journalist in an established technology publication, based on Brazilian Federal Police and US Department of Defense sourcing. Not a primary document. Retrieved 2026-08-20 at the stored URL, which returned HTTP 200; the repost that carried its content until then attributes it to Wired and Marcelo Soares, and the page as served today carries the byline WIRED Staff.

  • First Responder (WordPress blog) · 2009-04-22

    Tier 3: An anonymous blog reposting another publication's text. It carries no independent authority; its value is that it reproduces the Wired article verbatim and attributes it, and that it is retrievable.

  • Hacking U.S. Military Satellites
    Researcher blog
    corroborating

    Schneier on Security · Bruce Schneier · 2009-04-23

    Tier 3: A named security practitioner's blog note. It summarises and links a Wired article rather than reporting independently, so it is independent of that article in judgement and not in facts.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.