TRAFEED

Satellites and the Military: How Starlink Changed War, and How Satellite Data Now Drives Counterparty Investigation and Dual-Use Screening

Published2026-07-19Updated2026-07-30Ryuta Hamamoto

On February 24, 2022, the same day the invasion of Ukraine began, KA-SAT went dark under a cyberattack and Starlink filled the gap.

Satellites and the Military: How Starlink Changed War, and How Satellite Data Now Drives Counterparty Investigation and Dual-Use Screening
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

On February 24, 2022, the very day Russia began its invasion of Ukraine, space quietly became a battlefield. The commercial satellite broadband network "KA-SAT," which delivered communications across a wide swath of Europe, fell silent under a coordinated cyberattack. Behind the physical combat of the invasion, infrastructure high above the ground was being targeted at the same moment. That fact drove home that space is no longer "a distant matter of technology" but the very ground of economic security.

In this article, taking that day as the starting point, we look at how satellites changed war and how the data derived from satellites is turning corporate "counterparty investigation" into routine work. Space technology is one of the domains where the line between civilian and military use is thinnest, and it is also the front line of dual-use (civil-military) technology. For companies on the exporting side, understanding this structure is not someone else's problem.

Let me summarize the key points of this article up front.

  • Commercial satellites have become security infrastructure. The cyberattack on KA-SAT and the Starlink that filled the gap are the symbols of that shift.
  • Counterparty investigation using commercial satellite imagery has come down from specialized intelligence work to the everyday due diligence of ordinary companies.
  • In the scale of space assets, the United States is in a class of its own, China is closing in fast, and Japan sits in a structure of overseas dependence.
  • Space technology is a dense concentration of dual-use items, and the classification and counterparty-screening burden on exporting companies has grown heavier still.

If you want to quickly gauge whether your own products or parts fall under export control, one place to start is the diagnostic tool that lets you experience export control classification.

KA-SAT was operated by Viasat, a major U.S. satellite communications company. According to the company's official incident report, the attackers exploited a misconfigured VPN device to break into the management segment and pushed through destructive commands1. The tool used was a wiper-type malware called "AcidRain," which overwrote the boot-critical data in the modems' flash memory and rendered the terminals unusable. The malicious activity began around 0302 UTC that same day, and mass disconnections of modems occurred around 0415 UTC.

The damage spread across borders. Thousands of customers inside Ukraine and tens of thousands of fixed-broadband customers across Europe were affected, and tens of thousands of modems that had been online dropped out. Viasat shipped roughly 30,000 modems to distributors to restore service1. The aftershocks of a military operation reached all the way into civilian infrastructure far from the fighting.

The attack was later named as a state operation. On May 10, 2022, the EU, the United States, and the United Kingdom condemned the attack on the KA-SAT network as a Russian operation2. SentinelLabs, the team that discovered and named the wiper, assessed with medium confidence that AcidRain shares non-trivial developmental similarities with a VPNFilter stage-3 destructive plugin ("dstr") from 2018 — while stating explicitly that it cannot definitively tie the two together3. A state attacked commercial satellite communications infrastructure as part of a military operation. This one point alone makes clear that space is an object of national security.

With communications severed, SpaceX moved in response to a request from the Ukrainian government. It activated Starlink, its low-Earth-orbit satellite constellation, and Ukraine's military and government rapidly came to rely on Starlink to keep internet connectivity alive. The role did not stop at securing communications. In addition to maintaining external contact and keeping energy infrastructure running, Starlink was reportedly used to connect combat drones, maritime drones (unmanned surface vessels), and targeting systems that correct artillery fire, supporting attacks on Russian positions. At the same time, SpaceX balked at offensive use against weapons systems and restricted access in some cases. In other words, the private company providing the technology tried to draw a line around how war was waged with it.

The cost side cannot be ignored either. The U.S. Department of Defense has been reported to have contracted with SpaceX to fund Starlink use in Ukraine, but we could not confirm the contract terms, the monthly operating cost, or SpaceX's own contribution against primary sources this time, so no figures are given here. Even so, what matters is that a private company's service came to be publicly positioned as part of a nation's security.

What this chain of events shows is, I believe, a single clear fact. Space infrastructure built for civilian use has come to decide military outcomes directly. A commercial satellite is no longer merely a "convenient means of communication"; it is "security infrastructure." Handling space-related technology or parts without holding this perspective now feels precarious to me.

Counterparty Investigation Advances with Satellite Data

Space did not change only war. The technology of looking down at the ground from satellites has quietly changed how companies conduct "counterparty investigation" as well.

The key is two kinds of eyes: optical and SAR (synthetic-aperture radar). Optical satellites capture images that look like the photographs we are used to, but clouds block the ground and nighttime is a weak point. SAR, by contrast, beams radio waves at the ground and captures the reflections, so it penetrates clouds and can image at night. Because it can observe the same location repeatedly regardless of weather or time of day, it is suited to round-the-clock monitoring. Combine the two, and you can continuously track "what is actually happening at that facility."

Beyond that, other data fills in what satellite imagery alone cannot cover. Vessel position data broadcast by AIS (Automatic Identification System), trade data, and each country's corporate registry records are cross-referenced. In this way a method took hold that draws a three-dimensional picture of a facility's activity, its supply chain, and the movement of warships and cargo vessels. Technically it is called GEOINT (geospatial intelligence), but in essence it is "an investigation of a counterparty's true state that combines the satellite's eye with open-source information."

A leading example that demonstrates the power of this method is the Royal United Services Institute's (RUSI) Project Sandstone. Launched in 2019, this effort has systematically gathered and analyzed open-source information to produce reproducible findings on North Korea's proliferation and smuggling networks4. Using commercial satellite imagery, it visualized the construction of three storage tanks and related facilities at the port of Nampo, and it pinned down coal and oil ship-to-ship transfers, that is, cargo swaps from vessel to vessel at sea, carried out using AIS spoofing (falsification of position data). It brought front companies (nominal firms set up to hide the true operator), smuggling routes, and the procurement of dual-use items out into the open. The same kind of analysis is also used to track entities and transactions that appear on sanctions lists. For how to read sanctions lists, we lay out the details in the Complete Guide to Sanctions Lists, so please refer to it as well.

The point I want to emphasize here is that this kind of investigation no longer belongs solely to "a state's special intelligence." Commercial satellite imagery has improved in resolution and imaging frequency, and prices have become realistic. As a result, it is becoming a standard means of verifying the facilities and activities of counterparties and end users in corporate due diligence, supply-chain audits, and export control reviews. Undeclared facility expansion, and gaps between what is publicly stated and the actual situation, can be checked with the satellite's eye. What would have been hard to imagine a few years ago is now done routinely.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

The Japan-U.S.-China Gap in Space Assets

Even in an era when you can view your counterparty by satellite, who holds how many of those "eyes" differs greatly from country to country. The gap in the scale of space assets is a point that cannot be sidestepped when thinking about economic security. The figures shift daily with launches and retirements, and different sources use different aggregation criteria (active, in-orbit, or planned). Here I will note the point in time and the basis while conveying a sense of scale.

Start with the United States. In the statistics of astrophysicist Jonathan McDowell (planet4589), Starlink alone had 8,872 active satellites as of July 18, 2026, with a total of 10,844 in orbit5. The same tracker's constellation list puts cumulative Starlink launches at 12,680 against 34,864 planned across its filings, as of July 25, 20266. This is the scale of a single private constellation on its own. The United States holds the world's largest satellite fleet, anchored by privately led low-Earth-orbit constellations.

To grasp the structure, it helps to look at slightly older data too. The Union of Concerned Scientists (UCS) Satellite Database (as of May 2023) recorded 7,560 active satellites in total, of which the United States had 5,184, China 628, Russia 181, and others 1,5727. Japan had no standalone line item and was included under "others." Since that point, the total has grown much larger with Starlink and the like, so treat these figures purely as "the 2023 breakdown" for reading the structure. Even so, the order-of-magnitude difference between the United States and everyone else comes through clearly.

China is closing in fast. It is running several giant constellations aimed at countering U.S. Starlink. In the same tracking data (as of July 25, 2026), the Xingwang constellation of the Guowang lineage has 216 satellites launched against 960 planned, while a second filing, Xingwang2 (GW), accounts for a further 12,992 planned with none launched so far. "Qianfan" (G60), developed in Shanghai, has 239 launched against 16,000 planned6. The current number actually deployed lags far behind the United States, but the planned scale rivals it, and China is narrowing the gap on a multi-year horizon.

And then there is Japan. Its core national-security asset is the Information Gathering Satellites (IGS), operated by the Cabinet Satellite Intelligence Center of the Cabinet Secretariat. Their introduction was decided by the Cabinet on December 22, 1998, and the Center's published overview sets out the design: optical satellites and radar satellites, with two optical and two radar maintained so that a given point on Earth can be imaged at least once a day (that four-satellite posture was established in April 2013), and a buildout target of four optical and four radar plus data-relay satellites, described as a ten-spacecraft posture8. Sensor resolution is not disclosed, so we give no figure for it. The capability is by no means low, but the number of spacecraft is in a different order of magnitude. Starlink alone has more than twelve thousand satellites launched and China's constellation filings run into the ten thousands, while Japan's national fleet is designed around roughly ten spacecraft. Without a giant low-Earth-orbit constellation of its own, the reality is that it has no choice but to depend heavily on overseas satellite services, especially those of the United States.

This dependence structure connects directly to the story of communications infrastructure. Japan too is moving forward with the adoption of commercial low-Earth-orbit satellite communications, and we dig into its national-security implications in Rakuten, Japan's Satellites and Starlink: The Security of Communications Infrastructure. How a country at a disadvantage in space assets uses overseas satellites, and where it secures its autonomy, is Japan's homework.

Japan's Path Forward and Dual-Use

So where is Japan headed? The backbone of the government's space policy is the "Basic Plan on Space Policy," adopted by the Cabinet on June 13, 2023 (Reiwa 5), with its process chart updated by the Strategic Headquarters for Space Development on December 23, 2025 (Reiwa 7)9. The direction is toward actively leveraging commercial satellites in the national-security context and advancing the buildout of satellite constellations. In other words, the dual use of civilian and defense assets is advancing at the level of policy. The Ministry of Defense is also reported to be considering the construction of a constellation of small satellites for missions such as missile detection and tracking, but I refrain from asserting this here, since the text of the official document and the specific number of spacecraft or timing of any decision could not be fully confirmed from primary sources this time. Any detailed treatment of space security needs to be re-verified against the original documents of the Cabinet Office and the Ministry of Defense.

Policy tailwinds translate directly into corporate burden. The more the military diversion of civilian technology advances, the heavier the responsibility that falls on companies in the space and defense supply chains to confirm "whose hands, and what kind of facility, their technology or parts end up in, and how they are used." For why dual-use becomes a practical corporate issue, we lay out the details in Dual-Use Technology and Military Diversion Risk.

Let me pin down concretely which parts of satellite technology tend to become subject to regulation. High-resolution optical sensors, SAR technology, satellite components, and positioning and communications payloads are themselves classic dual-use items. A sensor mounted on a civilian observation satellite can serve, unchanged, for military reconnaissance. That is exactly why classification (the work of judging whether an item "falls under or does not fall under" the scope of export control) is unavoidable when exporting parts. The deeper a company sits in the space or defense supply chain, the greater this burden becomes.

Japan, at a disadvantage to the United States and China in space assets, carries two simultaneous challenges on two fronts: leveraging overseas commercial satellite data while expanding domestic assets. On top of that, the military diversion of civilian technology advances too. For companies on the exporting side, the reality that "being able to see" and "being able to judge whether you may export" are two different things is finally weighing heavier.

After Visualization Comes "Judgment": TRAFEED

Satellite data and OSINT (open-source intelligence investigation) have made it possible, even for those who are not specialized institutions, to visualize the facilities and activities of counterparties and end users. Up to this point, it is good news. The problem lies beyond it.

Even if satellite imagery lets you notice that "this facility looks different from what was declared" or "this counterparty is suspicious," that alone does not amount to an export control decision. Beyond that point, at least three specialized tasks await. The first is classification, discerning whether your own product or technology being exported is subject to regulation. The second is screening, confirming whether the counterparty or end user falls under a sanctions list, a foreign-user list, or a military end user. For the concrete process of counterparty screening, we explain it in End-User Screening and Counterparty Investigation (Customer Due Diligence). The third is assessing how much military-diversion (dual-use) risk exists. And then, keeping a record of these judgments in a form that can withstand a later audit. Only when all of this is done is the practical work of export control complete.

Frankly, this downstream work is the greatest difficulty. The lists you must reference keep growing in every country, and regulations are revised frequently. If a person cross-checks one case at a time by hand, there are limits to both volume and speed. This is exactly where an AI agent proves effective.

TRAFEED is an export control AI agent that handles precisely this "downstream of investigation." It is said to be the world's first in Japan's security export control domain (as of March 2026, per our own research), it complies with the standards of the Ministry of Economy, Trade and Industry, and it supports multiple languages. It automates classification and supports the screening of counterparties and end users as well as the investigation of military-diversion risk. We have confirmed an AI classification accuracy of 95% or higher (joint verification with Okayama University, on roughly 30,000 past review records, per our own research). Even in domains where dual-use items are concentrated and regulations are tightly interwoven, such as space and defense, it is designed to let you run operations while curbing gaps and omissions. Of course, the final classification is premised on being made by your company's export control officer. AI is a tool for making judgments faster and more reliable; it is not something that takes over responsibility.

You can check concretely how far TRAFEED can automate and how it fits into your own operations on the TRAFEED service page.

Conclusion

Space has, before we knew it, become the front line of economic security. Let me organize the key points at the end.

  • As the cyberattack on KA-SAT and the activation of Starlink showed, commercial satellites are already security infrastructure.
  • Counterparty investigation using commercial satellite imagery and OSINT has come down from intelligence work to the everyday due diligence of companies.
  • Space assets are vastly larger for the United States, China is closing in at planned scale, and Japan sits in a structure of overseas dependence.
  • Satellite sensors and components are classic dual-use items, and the classification and counterparty-screening burden on exporting companies is increasing.
  • "Being able to see" and "being able to judge whether you may transact" are two different things, and TRAFEED is what supports that judgment and its recordkeeping with AI.

In an era when satellites make the world visible, what is asked next is the ability to discern "whether you may actually transact with the counterparty you have seen." You do not have to shoulder alone what comes after you notice something suspicious in a counterparty investigation. If you face export control in a field where dual-use runs deep, such as space and defense, please tell us about your current challenges from our individual export control consultation. Let's design together the "judgment" that comes after visualization.

References

  1. Viasat, "KA-SAT Network cyber attack overview" (official incident report) — https://www.viasat.com/perspectives/corporate/2022/ka-sat-network-cyber-attack-overview/
  2. Council of the EU, High Representative declaration, "Russian cyber operations against Ukraine" (May 10, 2022; attribution of the KA-SAT attack to Russia) — https://www.consilium.europa.eu/en/press/press-releases/2022/05/10/russian-cyber-operations-against-ukraine-declaration-by-the-high-representative-on-behalf-of-the-european-union/
  3. planet4589 (Jonathan McDowell), Starlink Statistics (updated July 18, 2026) — https://planet4589.org/space/con/star/stats.html
  4. Union of Concerned Scientists (UCS), Satellite Database (data as of May 2023) — https://www.ucs.org/resources/satellite-database
  5. Cabinet Office, Space Policy, "Basic Plan on Space Policy" (adopted by the Cabinet June 13, 2023; process chart updated December 2025) — https://www8.cao.go.jp/space/plan/keikaku.html
  6. RUSI, "Project Sandstone" (proliferation-network investigation via commercial satellite imagery x OSINT) — https://www.rusi.org/explore-our-research/projects/project-sandstone
  7. SentinelLabs, "AcidRain | A Modem Wiper Rains Down on Europe" (March 31, 2022; the original analysis of the wiper used against KA-SAT modems) — https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/
  8. planet4589 (Jonathan McDowell), "Constellation List" (updated July 25, 2026; launched and planned counts for Starlink, Qianfan and the Xingwang / Guowang lineage) — https://planet4589.org/space/con/conlist.html
  9. Cabinet Secretariat, Cabinet Satellite Intelligence Center, "Overview of the Information Gathering Satellites" (official PDF; Cabinet decision of December 22, 1998, the optical/radar composition, and the ten-spacecraft buildout target) — https://www.cas.go.jp/jp/gaiyou/jimu/pdf/csice2.pdf

Footnotes

  1. Viasat, "KA-SAT Network cyber attack overview" (official incident report). The attackers exploited a misconfigured VPN device to break into the management segment and overwrote data in the modems' flash memory with the wiper-type malware AcidRain. Malicious activity began around 0302 UTC on February 24, 2022, and mass disconnections of modems occurred around 0415 UTC. Thousands (Ukraine) to tens of thousands (Europe) of customers were affected, and about 30,000 modems were shipped to restore service. https://www.viasat.com/perspectives/corporate/2022/ka-sat-network-cyber-attack-overview/ 2

  2. Council of the EU, High Representative declaration, "Russian cyber operations against Ukraine" (May 10, 2022). The EU, the United States, and the United Kingdom condemned the attack on the KA-SAT network as a Russian operation. https://www.consilium.europa.eu/en/press/press-releases/2022/05/10/russian-cyber-operations-against-ukraine-declaration-by-the-high-representative-on-behalf-of-the-european-union/

  3. SentinelLabs (Juan Andrés Guerrero-Saade and Max van Amerongen), "AcidRain | A Modem Wiper Rains Down on Europe" (March 31, 2022) — the original research report on the wiper used against KA-SAT modems. It records developmental similarities with VPNFilter's stage-3 "dstr" plugin (identical Section Headers Strings Tables, the same MEMGETINFO / MEMUNLOCK / MEMERASE ioctls used to erase mtd devices, shared compiler characteristics, and a 55% TLSH fuzzy-hash similarity) at medium confidence, while stating that "we cannot definitively tie AcidRain to VPNFilter (or the larger Sandworm threat cluster)." https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/

  4. RUSI, "Project Sandstone" (established 2019). Analyzes North Korea's proliferation and smuggling networks using commercial satellite imagery and OSINT. Visualized the construction of three storage tanks and related facilities at the port of Nampo (completed 2020) and exposed ship-to-ship transfers using AIS spoofing. https://www.rusi.org/explore-our-research/projects/project-sandstone

  5. planet4589 (Jonathan McDowell), Starlink Statistics (as of July 18, 2026). Starlink alone had 8,872 active satellites and a total of 10,844 in orbit. https://planet4589.org/space/con/star/stats.html

  6. planet4589 (Jonathan McDowell), "Constellation List" (page updated July 25, 2026). The figures cited here are the site's own columns, "Total Sats Launched" (cumulative launches, including satellites since deorbited) and "Total Sats Planned" (the totals of the FCC/ITU filings). Starlink: 12,680 launched, 34,864 planned (the sum of the SG1, SG2, SG3D and SG3 filings). Qianfan (G60): 239 launched, 16,000 planned. Xingwang: 216 launched, 960 planned. Xingwang2 / Guowang (GW): 0 launched, 12,992 planned. https://planet4589.org/space/con/conlist.html 2

  7. Union of Concerned Scientists (UCS), Satellite Database (data as of May 2023). Total active satellites 7,560, of which the United States 5,184, China 628, Russia 181, and others 1,572. Japan had no standalone line item and was included under "others." Since then, totals have grown substantially with Starlink and the like. https://www.ucs.org/resources/satellite-database

  8. Cabinet Secretariat, Cabinet Satellite Intelligence Center, "Overview of the Information Gathering Satellites" (official PDF). The introduction of the Information Gathering Satellites was decided by the Cabinet on December 22, 1998. The system comprises optical satellites and radar satellites; two optical and two radar are maintained so that a given point on Earth can be imaged at least once a day (that four-satellite posture was established in April 2013), and the plan is to expand to four optical and four radar plus data-relay satellites, described as a ten-spacecraft posture. The document does not disclose sensor resolution. https://www.cas.go.jp/jp/gaiyou/jimu/pdf/csice2.pdf

  9. Cabinet Office, Space Policy, "Basic Plan on Space Policy." The Basic Plan on Space Policy was adopted by the Cabinet on June 13, 2023 (Reiwa 5), and its process chart was updated by the Strategic Headquarters for Space Development on December 23, 2025 (Reiwa 7). https://www8.cao.go.jp/space/plan/keikaku.html

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Aerospace Parts Classification Checklist (Japan Appended Table 1 Row 13 etc. / US EAR & ITAR / MTCR & Wassenaar, 2026)

A fill-in working sheet to classify aircraft, spacecraft, rockets, engines and their parts — from Japan's Export Trade Control Order Appended Table 1 (Row 13 = aerospace & propulsion, Row 4 = missiles) and the goods-ordinance thresholds, through the ITAR (USML) vs EAR (CCL Category 9 / EAR99) jurisdiction triage, to the MTCR and Wassenaar. With a plain-language intro, based on primary sources (e-Gov, 15 CFR, 22 CFR). A starting point for export-control staff; controls change frequently, so treat the authorities' latest guidance and your export-control officer as authoritative. Listing is a regulatory category, not a judgment about any company or country.

China Business Travel: Technology Pre-Departure Worksheet (fill-in, 2026)

A fill-in worksheet for engineers, sales and researchers travelling to China, and for the teams that send them. Under Japan's Foreign Exchange and Foreign Trade Act, taking technical information on a trip can amount to providing technology in a foreign country (Art. 25(1)), and carrying it on a laptop or opening it from abroad can fall within Art. 25(3)(i). Most trips stay within the exemptions in Article 9 of the Ordinance on Trade Relations Invisible Trade (publicly available technology, basic scientific research, patent filings, technology incidental to exported goods). This worksheet shows where the line sits, situation by situation, with fill-in sections for before, during and after the trip. The China side reflects State Council Order No. 841 (in force 15 September 2026) Arts. 3 and 5, the Exit and Entry Administration Law Art. 28, and Japan's MOFA overseas safety advisory. Classification and licensing decisions rest with your export-control officer.

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles