The Weaponization of Starlink: How Threat Actors Are Exploiting Commercial LEO Connectivity

The deployment of SpaceX’s Starlink constellation, consisting of thousands of Low Earth Orbit (LEO) satellites, has transformed satellite internet by providing high-speed, low-latency connectivity in remote and poorly connected areas. Its portable terminals support legitimate applications ranging from civilian broadband and maritime connectivity to emergency communications.
However, the same capabilities that make Starlink valuable also create security challenges. Portable terminals, satellite-based connectivity and reduced dependence on terrestrial networks can provide alternative communications for criminal networks, armed groups and other threat actors.
Authorities have reported Starlink terminals in cyber-scam compounds in Southeast Asia, illegal mining operations in Brazil, conflict zones in Sudan and Ukraine, and illicit maritime activity. In India, authorities recovered a Starlink Mini terminal from a vessel carrying approximately 6,000 kilograms of methamphetamine during a major narcotics seizure in the Andaman Sea in November 2024. In Nigeria, troops have also reported recovering more than 400 Starlink devices allegedly linked to Boko Haram and ISWAP operations in the country’s northeast.
These cases highlight the dual-use nature of commercial LEO satellite connectivity. Technology designed for legitimate civilian use can also be appropriated, smuggled or repurposed by threat actors seeking communications outside conventional telecommunications networks.
This article examines the weaponization of Starlink, focusing on how criminal networks, armed groups and other threat actors acquire and exploit commercial LEO connectivity, and the challenges this creates for law enforcement, national security and regulation.
Southeast Asia and Cyber-Scam Compounds:
In Southeast Asia, particularly along the porous borders of Myanmar, Cambodia and Laos, massive cyber-scam compounds have emerged. These heavily fortified enclaves, often guarded by local ethnic militias and corrupt military officials, conduct industrial-scale cyber-enabled fraud, human trafficking for forced criminality and cryptocurrency theft. According to a 2024 United Nations Office on Drugs and Crime (UNODC) report on Transnational Organized Crime Convergence, these operations generate estimated financial losses of US18billiontoUS37 billion annually.
Because these compounds, including the notorious KK Park complex in Myanmar, often operate in remote areas far from reliable fiber-optic infrastructure, transnational criminal syndicates rely on Starlink to maintain continuous, high-speed connectivity for their operations. The infrastructure supports complex “crime-as-a-service” models, fake liquidity-mining schemes, underground banking and the deployment of infostealer malware through Telegram. The use of Starlink extends beyond individual scam compounds. In April 2024, Thai authorities in Chiang Rai seized 10 Starlink terminals alongside 4,998 pre-registered U.K. SIM cards, 94 computers, 347 mobile phones and fraudulent bank cards and bank books. Authorities believed the equipment was destined for a transnational cyber-enabled fraud syndicate operating in the Golden Triangle Special Economic Zone in Laos.

simboxes, 6,000 SIM cards and Starlink satellites
Authorities in the region recorded further Starlink seizures in 2024. In Lashio, Myanmar, authorities dismantled a cyber-enabled fraud group in April and seized a Starlink device alongside mobile phones and computers. Meanwhile, authorities in Saraburi, Thailand, seized four Starlink terminals along with SIM boxes and thousands of pre-registered SIM cards. In June 2024, authorities in Chanthaburi seized 58 Starlink terminals reportedly destined for cyber-enabled fraud syndicates operating in neighboring countries. Thai authorities also seized another six Starlink terminals in Chanthaburi during a separate operation.
These seizures demonstrate how criminal networks can combine Starlink connectivity with large-scale SIM infrastructure, computers, mobile devices and financial accounts to build transnational cyber-fraud operations. The repeated recovery of Starlink terminals across the Mekong region also highlights the difficulty of controlling portable satellite communications equipment once criminal networks obtain and move the hardware across borders.
In October 2024, a raid on KK Park in Myanmar resulted in the seizure of hundreds of active Starlink terminals, alongside the rescue of hundreds of trafficked foreign nationals, including Indian citizens. The UNODC report has highlighted the wider convergence of technological innovation, underground financial networks and cyber-enabled fraud in the Mekong region. Starlink adds another layer to this ecosystem by providing high-speed connectivity in remote locations where conventional telecommunications infrastructure remains limited.
In March 2025, Thai authorities intercepted 38 Starlink terminals allegedly destined for scam compounds in Myanmar, following another seizure earlier that month. In October 2025, Myanmar authorities claimed to have seized 30 Starlink receiver sets and accessories during an operation near the KK Park scam complex, although subsequent investigations raised questions about the exact location and circumstances of the raid. Around the same period, SpaceX said it had disabled more than 2,500 Starlink terminals in Myanmar over suspected violations. Separately, U.S. investigators identified at least 105 Starlink dishes across scam compounds near the Myanmar–Thailand border and obtained a warrant seeking the seizure of nine terminals and two associated Starlink accounts
Environmental Crime in the Amazon Basin:
Authorities have also documented Starlink terminals at illegal mining operations in Brazil’s Amazon region, including areas associated with illegal gold mining in or around Indigenous territories. Satellite internet provides mining groups with connectivity in remote locations where conventional telecommunications infrastructure remains limited.
The technology can support communications between remote mining sites and contacts outside the area, including the coordination of logistics and supplies. Reports have also described illegal miners using Starlink connectivity to monitor the activities of authorities and receive warnings about enforcement operations.
LEO connectivity can extend reliable communications into remote areas where conventional networks cannot easily reach. This capability makes the technology useful not only for legitimate users but also for criminal operations operating far from established infrastructure.
Insurgency, Terrorism, and Asymmetric Warfare
The proliferation of portable LEO satellite terminals has introduced another potential communications layer for insurgent and terrorist organizations operating in areas with weak telecommunications infrastructure, difficult terrain and porous borders. Unlike conventional terrestrial networks, satellite connectivity can provide communications without requiring local cellular towers or fixed broadband infrastructure. This makes the technology particularly relevant to security agencies monitoring armed groups operating in remote or contested environments.
The Sudan Crisis
A secondary, yet equally significant, exploitation of LEO technology is occurring in Sudan. According to media reports, Since the outbreak of civil conflict in April 2023 between the Sudanese Armed Forces (SAF) and the paramilitary Rapid Support Forces (RSF), the internet has become another battleground. The RSF has systematically targeted and occupied the data centers of domestic Internet Service Providers (ISPs), including Sudatel, MTN and Zain, in the capital city of Khartoum. By controlling these physical hubs, the RSF intentionally plunged vast areas of the country into digital darkness, creating extreme informational blackouts to hide atrocities and human rights violations.
After disrupting connectivity for civilians and elements of the SAF, the RSF circumvented the blackout by importing thousands of Starlink terminals through smuggling routes across Chad and Libya. The RSF uses these terminals to coordinate artillery barrages, manage logistics and maintain an aggressive propaganda output.
Furthermore, the RSF exercises control over civilian access to Starlink in territories it occupies, including Darfur. As per reports, with more than 50,000 civilians trapped in cities such as El Fasher under severe siege conditions, many depend on connectivity to contact relatives or access digital banking applications for life-saving remittances. RSF commanders force civilians to pay extortionate fees to access Starlink-generated Wi-Fi hotspots on the black market, effectively turning illicit satellite terminals into a lucrative terror-financing mechanism, with reported margins reaching millions of dollars.
This dynamic highlights the dual-use nature of LEO satellite internet: the same technology can provide a critical communications lifeline for civilians while also serving as a tool for military operations, economic exploitation and information control.
The Andaman Sea Methamphetamine Interdiction
The most high-profile incident highlighting this vulnerability occurred in November 2024 during a major maritime narcotics interdiction. As per PTI, Acting on precise intelligence, the Indian Coast Guard, operating in the remote waters of the Andaman and Nicobar Islands, intercepted a fishing trawler carrying six Myanmarese nationals. Upon searching the vessel, authorities discovered an unprecedented 6,000 kilograms of methamphetamine, with an estimated illicit market value of ₹36,000 crore.

During the subsequent forensic analysis of the vessel’s navigational and communications equipment, investigators recovered a SpaceX Starlink Mini dish. Interrogations and technical exploitation revealed that the smugglers had used the Starlink terminal to establish a localized Wi-Fi hotspot at sea. This enabled them to navigate using precise, internet-connected maritime mapping tools, inputting coordinates for Neil Island and Rangat, and to communicate via encrypted messaging applications with international cartel handlers in Southeast Asia, as well as local contacts within India.
Intelligence authorities suspect that the consignment was linked to notorious international cartels, such as Tse Chi Lop (often referred to as the Asian El Chapo) or Nemesio Oseguera Cervantes (El Mencho).
When the Andaman and Nicobar Police and central intelligence agencies contacted SpaceX to obtain the ownership, procurement and activation details of the seized terminal and trace the broader cartel network, Starlink refused to provide the data, citing restrictive international data privacy laws.
Starlink and Armed Groups in Manipur
Simultaneously, the northeastern state of Manipur has witnessed the integration of Starlink technology into asymmetric warfare. Manipur, which shares a highly porous 398-kilometer border with Myanmar, has experienced protracted ethnic conflict and a resurgence of armed militant groups. In late 2024, joint counter-insurgency operations conducted by the Indian Army’s Spear Corps and the Assam Rifles targeted militant hideouts in the Keirao Khunou area of Imphal East.

During these specialized raids, security forces recovered advanced weaponry, explosive materials, and a fully functional Starlink satellite antenna and router. Intelligence assessments indicated that Kuki militant factions and elements of the People’s Liberation Army (PLA) of Manipur were utilizing smuggled Starlink terminals to deliberately bypass local, state-mandated internet shutdowns.
By leveraging terminals smuggled across the Myanmar border, insurgent commanders could maintain unfettered communications with cross-border safe havens, coordinate ambushes against state security forces, and orchestrate logistics without fear of interception by traditional Indian signals intelligence (SIGINT) platforms.
Nigeria: Starlink and Terrorist Communications
Nigeria provides another example of Starlink terminals being used by terrorist organizations. As per Premium Times, in May 2026, troops from Operation HADIN KAI reported intercepting more than 400 Starlink communication devices allegedly used by Boko Haram and the Islamic State West Africa Province (ISWAP) across northeastern Nigeria. The terminals were recovered during operations targeting terrorist logistics and communication networks in areas including Sambisa Forest and the Timbuktu Triangle. Nigerian military authorities said the seizures were intended to disrupt the communications and logistics networks supporting terrorist operations. In July 2026, Nigerian troops detained a suspected ISWAP member in Borno State and recovered a Starlink satellite terminal, a Wi-Fi router with six access points, and a mobile phone from his possession.
Authorities transferred the suspect and equipment to the 7 Military Intelligence Brigade for further investigation into possible links to ISWAP and the potential use of the Starlink equipment for terrorist communications or logistics.
The Transnational Black Market and Financial Subterfuge
Threat actors can acquire Starlink terminals through a transnational black market that exploits differences between countries where Starlink is authorized and jurisdictions where its use remains restricted. Investigations have documented intermediaries purchasing or activating terminals in authorized markets and then moving them to unauthorized users. Once activated, middlemen smuggle the terminals across porous borders and deliver them to unauthorized users.
Starlink’s focus on rapid civilian adoption and global connectivity creates challenges for Know Your Customer (KYC) and other compliance mechanisms. Threat actors can exploit legitimate accounts, corporate identities and service plans to move terminals from authorized markets into areas where authorities restrict or prohibit their use. This model creates a significant challenge for law enforcement and satellite-communications regulators because the physical terminal, customer account and actual service location can exist in different jurisdictions. As a result, commercially available LEO satellite connectivity can reach users who would otherwise face regulatory or infrastructure barriers.
The Russo-Ukrainian War: From Lifeline to Contested Asset
As reported, in February 2022, hours before Russia launched its full-scale invasion of Ukraine, Russian military intelligence carried out a highly sophisticated cyberattack against the Viasat satellite network. The attack disrupted a key communications system used by the Armed Forces of Ukraine (AFU). In response, the Ukrainian government urgently requested assistance from SpaceX. Elon Musk authorized the activation of Starlink in Ukraine, and thousands of terminals were subsequently delivered to the country.
Starlink quickly became a critical communications system for Ukrainian forces. Its resilience on the battlefield supported decentralized command and control (C2), artillery coordination, and widespread unmanned aerial vehicle (UAV) operations. Recognizing Starlink’s battlefield advantages, Russian forces sought to obtain terminals despite SpaceX stating that it did not sell or provide Starlink services to the Russian government or military. In February 2024, Ukrainian military intelligence confirmed that Russian forces were using Starlink terminals on the front, including units from the 83rd Air Assault Brigade operating in Donetsk Oblast.
Subsequent investigations by Western and Ukrainian media documented a black and gray market for Starlink terminals in Russia. Sellers advertised Starlink terminals through online channels. The supply chain reportedly involved terminals acquired outside Russia, including in Europe, and transported through intermediary countries such as the United Arab Emirates before reaching Russian-controlled territory.
The issue continued to evolve in 2026, as Ukrainian authorities reported further Russian use of Starlink terminals and efforts to restrict unauthorized access. Ukrainian intelligence also reported Starlink-equipped Russian drones, indicating that Russian forces have expanded their use of commercial LEO satellite technology beyond conventional battlefield communications.
Potential Implications for India
For India, the security implications are particularly relevant in Jammu & Kashmir and other areas along India’s international borders, where terror networks have historically operated in difficult terrain and where communications infrastructure can be disrupted during security operations. If unauthorized Starlink terminals were to become available to Pakistan-based or Pakistan-supported terror organizations operating in or infiltrating Jammu & Kashmir, the technology could potentially provide an alternative communications channel independent of local cellular and broadband networks.
This could complicate traditional communications monitoring and allow connectivity to be maintained in areas where terrestrial networks have been restricted or disrupted. The same risk could extend to maritime routes, where criminal and narco-terror networks could potentially use portable Starlink terminals to maintain communications during offshore drug-trafficking and weapons-smuggling operations beyond the reach of conventional terrestrial networks. The documented recovery of Starlink equipment in the Andaman Sea demonstrates that unauthorized terminals can reach Indian territory and be used by actors involved in illicit activities.
At the same time, the unauthorized operational presence of Starlink in India has complicated the company’s efforts to enter the Indian telecommunications market legally. The Ministry of Home Affairs (MHA) has expressed concerns regarding an “alien” and untraceable communications channel operating within Indian sovereign territory, utilized exclusively by insurgents and cartels outside the purview of domestic intelligence agencies.
The Department of Telecommunications (DoT) imposes strict security and regulatory requirements on satellite internet operators in India. Under the GMPCS framework, operators must comply with lawful interception requirements and route Indian traffic through authorized satellite gateways established in India. These requirements allow Indian authorities to apply lawful monitoring and security measures to satellite communications operating within the country. As of October 2026, Starlink has not yet launched commercial services in India, despite holding a GMPCS authorization and receiving authorization from IN-SPACe. Starlink has also built around 20 gateway sites in India and says it has implemented India-specific security and data-control measures.
The remaining regulatory process includes spectrum allocation and security clearances. The Digital Communications Commission approved the proposed satellite-spectrum framework in September 2026, but operators still require the remaining approvals before they can begin commercial services. Importantly, Starlink, Eutelsat OneWeb and Jio Satellite Communications are currently at broadly the same regulatory stage, according to the Indian government.