Iridium pager-network interception demonstrated at Chaos Communication Camp 2015
What happened
At Chaos Communication Camp 2015, two researchers presenting as Sec and Schneider gave a talk titled Iridium Hacking: please don't sue us, in which they reverse-engineered the Iridium satellite constellation's pager service and demonstrated live capture and decoding of its message traffic from inside the event tent. The receiver was the rad1o badge, a standalone HackRF-derived software-defined radio distributed to about 4,500 attendees as the event's conference badge, driven by a purpose-built decoding toolchain the researchers published as the iridium-toolkit and ran on a laptop or a Raspberry Pi 2. Their central finding was that Iridium pager traffic does not use encryption by default and that the majority of it is sent in clear text, and they reported that the badge with only its onboard PCB antenna collected 22 percent of the packets obtainable with a proper Iridium antenna. Nothing was transmitted, no constellation asset was compromised, and no subscriber device was touched.
A security-research demonstration, not an adversary operation; the talk title is itself the disclosure posture. Confidence is high because the researchers demonstrated the capability live and published the tooling, which is stronger evidence than reporting. Two corrections are recorded against the brief that requested this record. First, the brief specifies 2 SPARTA references; the current version has 3 techniques citing the talk (EXF-0003.01, RD-0001.02, REC-0005). Second, SPARTA cites the talk at EXF-0003.01, Uplink Exfiltration, which appears to be a direction error: what the researchers built is a receiver decoding transmissions arriving from the constellation, and no retrieved source describes capture of subscriber-to-satellite uplink traffic. This record rejects EXF-0003.01 and substitutes EXF-0003.02.
Attack vector
Passive reception and decoding of an unencrypted satellite paging service using a commodity software-defined radio and open-source decoding software. No transmission and no compromise of any constellation or subscriber asset.
Operational impact
None. A demonstration, presented publicly with the tooling released. What it establishes is that the service's message traffic is receivable and readable by any party with commodity hardware.
Affected segments
link, user
Disclosed
2015-08-23
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
The content recovered was third-party subscriber pager messages, mostly in clear text, so message content did reach an unauthorised recipient by way of the space-to-ground transmission. Derived and held at moderate because this was a research demonstration and the source reports no retention or misuse of subscriber content. Added in place of SPARTA's EXF-0003.01 citation, which is a direction mismatch: the researchers built a receiver for transmissions arriving from the constellation.
The whole of the demonstration is passive reception and decoding of a satellite constellation's traffic by a party it was not intended for. REC-0005 is that behaviour named, and it was performed live in front of an audience with the tooling published afterwards, which is a stronger form of evidence than a description.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
Direction mismatch; see above. Substituted with
EXF-0003.02.The rad1o badge is a conference badge and a hobby SDR, and the toolchain is open source running on a laptop or a Raspberry Pi. No commercial ground station service is involved, which is rather the point of the demonstration. Accepted for the Iraq drone record, where the interception genuinely rode on commercial satellite services; not here.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- Hacking the Iridium network could be very easyResearcher blog
Tier 3: A named security practitioner's blog reporting on a conference talk he did not give. Reliable on what was presented, secondary to the presentation itself. Retrieved in full in this session.
Tier 2: Tier raised from Tier 3 to Tier 2 on 2026-08-05 by founder ruling. The artefact is the recorded talk itself: a 46-minute presentation by the two researchers at Chaos Communication Camp 2015, published on the organising body's own media archive. That is first-party evidence of what they claimed and demonstrated, which is a Tier 2 standard; the prior Tier 3 rested on the medium being a video recording rather than on the evidence it carries. RETRIEVAL: fetched 2026-08-05 by Claude Code's WebFetch, which converts the page and answers a question against it with a small model. A real retrieval, and not a person reading the page. The page shows two dates, 2015-08-15 and 2015-08-16, and labels neither, so the stored publication_date is a plausible reading rather than a confirmed one. The page states no licence. NOT ESTABLISHED by that retrieval: whether the stored retrieval_date of 2026-06-12 corresponds to an actual retrieval. The page resolving today says nothing about then; see the retrieval-date population measurement.
Tier 2: The published tooling itself, under the Munich CCC organisation account. Primary evidence of capability rather than a report of it.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.