Skip to content
safemode.space
All incidents
2007-10-20
network intrusion
ground

Landsat-7 and Terra EOS AM-1 interference via a commercial ground station (2007-2008, USCC 2011 report)

Confidence in this reading:
low

What happened

The 2011 annual report of the US-China Economic and Security Review Commission described four episodes of interference with two US civil earth-observation satellites: Landsat-7, managed jointly by NASA and the US Geological Survey, on 20 October 2007 and 23 July 2008, and Terra EOS AM-1, managed by NASA, on 20 June 2008 and 22 October 2008. The durations reported were twelve or more minutes, twelve or more minutes, two or more minutes and nine or more minutes respectively. The Commission's account came from a May 2011 US Air Force briefing. The report stated that the responsible party appeared to have exploited the information systems of the Svalbard Satellite Station, a commercially operated ground station at Spitsbergen, Norway, which relies on the internet for data access and file transfers, and that in two episodes every step required to command the satellite was achieved but no commands were issued. The Commission expressly declined to attribute the events, stating it was not recounting them on the basis of specific attribution information but because the techniques appeared consistent with authoritative Chinese military writings. NASA stated that no commands were sent and no data taken or manipulated.

Low confidence is about the characterisation, not the dates. That four interference episodes occurred is attributed to a US Air Force briefing and reported in a congressional document; that they were intrusions, and that China was responsible, are both contested on the public record. The Commission itself declined to attribute them, US Strategic Command is quoted saying attribution was not possible, NASA denies any command or data effect, and the Union of Concerned Scientists published a point-by-point critique arguing the report's claims exceed its evidence. The record is carried anyway for two reasons: the undisputed structural fact is that a mission's access path ran through an internet-connected commercial ground-station operator, which is precisely the dependency NIS2 and the EU Space Act ground-segment provisions address; and the episode is routinely miscited in space-cybersecurity literature as an established Chinese intrusion, which the source document declines to say. Note especially that the report states all steps required to command were achieved but no commands issued, which is why IA-0007.02 is rejected rather than mapped.

Attack vector

Not established. The published report says only that satellites from several US government space programmes use commercially operated ground stations outside the United States, some of which rely on the public Internet for data access and file transfers, and that the interference was apparently consistent with cyber activities against the satellites' command and control systems. Reporting on an earlier draft said the hackers appeared to have exploited the information systems of the Svalbard Satellite Station, a commercially operated ground station in Spitsbergen, Norway, which the published text does not name.

Operational impact

Four episodes of interference lasting between two and twelve-plus minutes across two spacecraft. NASA states no commands were issued and no data taken or manipulated.

Affected segments

ground, link, space

Disclosed

2011-10-27

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • The vector the report describes is exploitation of the information systems of the ground station through which the satellites were accessed. IA-0007's subject is exactly that, compromising ground infrastructure as the most direct path to first execution against a spacecraft. Confidence is moderate rather than high because the report gives no detail of how the systems were exploited, and because NASA disputes that any effect on either spacecraft followed.

    https://phys.org/news/2011-10-china-satellite.html

  • IA-0009.02Vendor
    moderate
    derived
    #

    The station operator is a commercial provider holding a persistent, trusted route into mission operations, which is IA-0009.02's subject. No source frames the episode in trusted-relationship terms, so the edge is derived from the structure the report describes rather than from language it uses. It is recorded because that structure, not the disputed attribution, is what makes the episode citable for ground-segment supply-chain obligations.

    https://phys.org/news/2011-10-china-satellite.html

  • IMP-0002Disruption
    moderate
    direct
    #

    Four episodes of interference lasting from two to twelve-plus minutes are temporary impairment of the missions' use of their own satellites for a bounded period, which is IMP-0002's definition. The report's word is interference; the effect it describes is disruption. Confidence is moderate because NASA's account is that nothing was commanded and no data affected, so the impairment may have been confined to the link.

    https://phys.org/news/2011-10-china-satellite.html

  • SvalSat is a commercially operated station serving multiple missions. RD-0002.02 names commercial ground stations specifically as ready-made stepping-stones carrying vetted RF chains and trusted IP space, which is the path the report describes. This is the correct sibling; SPARTA's bibliography cites RD-0002.01, Mission-Operated Ground System, which does not fit a commercially operated station.

    https://phys.org/news/2011-10-china-satellite.html

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • Also cited in SPARTA's bibliography against this report. No source describes RF jamming; the described vector is ground-station information systems reached over the internet.

  • No source describes any change to anything aboard either spacecraft.

  • Also cited in SPARTA's bibliography here. Nothing in the report describes flooding, malformed frames, or noise injection.

  • This is the sharpest call in the record, and it goes the other way from the obvious reading. The report states that all steps required to command the satellite were achieved but that no commands were issued. IA-0007.02's defining act is transmitting commands. A technique whose terminal act did not occur is not evidenced by a report that says so explicitly. SPARTA's bibliography cites it; the report contradicts it.

  • NASA's statement is that no data were taken.

  • Cited in SPARTA's bibliography against the USCC report, and wrong. SvalSat is commercially operated, not mission-operated. RD-0002.02 is the correct sibling and is mapped.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

A source marked contradicting disputes the account above rather than supporting it. It is listed because a reader assessing this record should see it.

  • U.S.-China Economic and Security Review Commission · 2011-11-01

    Tier 1: Annual report of a US congressional commission, and the origin of every claim in this record. Tier 1 as a government document; the report itself states that its account of these episodes rests on a single US Air Force briefing and that it makes no attribution. Its PDF text layer decoded on retrieval 2026-08-20 and the Landsat-7 and Terra passages were read from it directly; the quotations used in this record were taken from the AFP report that quotes it.

  • Agence France-Presse, via Phys.org · 2011-10-27

    Tier 3: Wire-service report of a draft congressional document. Tier 3 as general news, but it is the readable carrier of the primary's own wording and every quotation in this record traces to it.

  • Union of Concerned Scientists · Laura Grego · 2011-12-01

    Tier 2: Named technical criticism by a physicist at an established policy organisation, published on its own blog rather than peer-reviewed. Authoritative on the argument it makes; an advocacy organisation on framing.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.