All techniques
EXF-0009
ST0008Exfiltration

Compromised Partner Site

Description

The adversary leverages third-party infrastructure connected to the mission, commercial ground stations, relay networks, operations service providers, data processing partners, to capture or relay mission data outside official channels. From these footholds, the attacker can mirror TT&C and payload feeds, scrape shared repositories, and man-in-the-middle cross-organization links (e.g., between partner stations and the primary MOC). Because partner environments vary in segmentation and monitoring, exfiltration can affect multiple missions or operators simultaneously, with stolen data exiting through the partner’s routine distribution mechanisms.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    moderate
    direct

    Cross-organization links (partner stations to MOC) need authenticated boundary controls; (2)(d)'s access-management obligation mitigates man-in-the-middle on these links when paired with mutual authentication.

  • craAnnex I, Part I, (2)(e)
    addresses
    moderate
    direct

    End-to-end encryption (rather than relying on partner-segment trust) preserves confidentiality even when a partner's environment is compromised — within (2)(e)'s in-transit confidentiality obligation.

  • eu-space-actArt. 81(1)
    addresses
    moderate
    direct

    Cross-organization links (partner-to-MOC) need authenticated boundary controls; 81(1)'s IAM protocols extend to credentials issued for partner integrations.

  • eu-space-actArt. 81(4)
    addresses
    moderate
    direct

    Compromised-partner-site exfiltration (primary: Art. 81(1)) cascades to 81(4) — partner-credential lifecycle audit limits cross-organization compromise.

  • eu-space-actArt. 85(1)
    addresses
    moderate
    direct

    End-to-end encryption (rather than relying on partner-segment trust) is part of the cryptographic concept 85(1) requires — limiting partner-side compromise impact.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    Compromised-partner exfiltration (primary: Art. 85(1)) is mitigated by 85(2) — partner-segment key rotation limits cross-organization compromise impact.

  • eu-space-actArt. 92(1)
    addresses
    high
    direct

    Commercial ground stations, relay networks, and partner data-processing pipelines are third-party service providers; 92(1)'s contractual obligation directly governs these relationships.

  • nis2Art. 21(2)(d)
    addresses
    high
    direct

    Commercial ground stations, relay networks, and data-processing partners with mission feeds are direct service providers; supplier-relationship security under Art. 21(2)(d) governs the trust framework around their data flows and cross-organisation distribution mechanisms.

  • nis2Art. 21(2)(j)
    addresses
    moderate
    inferred

    Art. 21(2)(j) (MFA/secured comms within the entity) is domain-relevant to third-party access exposure but does not interdict this vector: mirroring mission data and MITM of partner-to-MOC links bypass any authenticated entity session. The operative control is secured-comms encryption of cross-org links, not MFA.

  • nis2Art. 21(3)
    addresses
    high
    direct

    The technique exploits varying segmentation and monitoring across partner sites — supplier-specific cybersecurity quality is exactly what Art. 21(3) requires entities to consider when relying on third-party infrastructure for TT&C and payload feeds.

  • nis2Art. 23(1)
    triggers obligation
    moderate
    direct

    Compromise of partner infrastructure mirrors traffic across multiple operators simultaneously; the resulting cross-border, multi-mission impact is reportable under Art. 23(1).

  • nis2Art. 23(2)
    addresses
    high
    derived

    Primary mapping to Art. 23(1) treats compromise of partner infrastructure as a significant incident. Art. 23(2) timing applies once Art. 23(1) is triggered.

  • nis2Art. 23(3)
    relates to
    moderate
    derived

    Primary mapping to Art. 23(1) treats partner-site compromise as significant. Art. 23(3) significance is met by the cross-border test directly: partner networks (commercial GS, relay, processing) routinely span Member States, so an EXF-0009 event is structurally cross-border.

  • nis2Art. 23(4)
    addresses
    high
    derived

    Primary mapping to Art. 23(1) drives Art. 23(4) deadlines. Partner-site compromise is often detected via the partner's disclosure to the operator, which sets the awareness moment for the 24-hour clock.

  • nis2-implAnnex 3.3.2
    addresses
    moderate
    derived

    Partners must communicate breaches affecting shared infrastructure back to the entity; Annex 3.3.2 requires the entity to communicate event-reporting mechanisms to those suppliers/partners.

  • nis2-implAnnex 5.1.1
    addresses
    high
    derived

    Commercial ground stations, relay networks, operations service providers and data-processing partners are direct suppliers under the supply-chain policy; the policy governs the security expectations imposed on these partner environments where multi-mission exfiltration originates.

  • nis2-implAnnex 5.1.4
    addresses
    high
    derived

    Direct-supplier security requirements (segmentation, monitoring discipline, vulnerability handling, incident-disclosure obligations) are the contractual mechanism that constrains how partner environments are operated; weak partner posture is the precondition for partner-site exfiltration.

  • nis2-implAnnex 5.1.6
    addresses
    high
    derived

    Partner-site exfiltration paths are best closed by Annex 5.1.6 ongoing monitoring of partner-side security posture, breach disclosures and policy compliance.

  • nis2-implAnnex 5.1.7
    addresses
    high
    derived

    Annex 5.1.7 reporting and follow-up are the procedural mechanism that converts partner-side monitoring signals into contract action, partner replacement or incident coordination.

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Cross-organization links (partner-station to MOC, processing partner to operator) are part of the entity's network-and-information-systems estate; network-security obligations apply to those gateways and resist man-in-the-middle exfiltration.

ENISA controls

  • Cyber supply-chain risk management of partners — commercial ground stations, relay networks, ops service providers, data processing partners — is the named control governing EXF-0009 vectors.

  • Remote-access management governs partner-side remote-administration sessions and includes possible remote-deletion when compromise is identified.

  • Supplier security management requires evidence of security posture from third-party stations and providers whose feed-mirroring or scraping enables EXF-0009.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EXF-0009 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.