Sovereignty Research
When the Whitelist Became the Attack Surface: Ukraine’s Starlink Access-Control Crisis, February–July 2026
Ukraine’s Starlink whitelist was designed to exclude unauthorised Russian terminals from the network; within six months, the central security problem had shifted towards controlling how hostile terminals entered the approved list itself.
Abstract
Russian forces had been using civilian Starlink terminals in occupied Ukrainian territory since at least late 2023, exploiting access controls built for an ordinary commercial service rather than a fluid battlefield. The problem escalated rapidly at the end of 2025 as Starlink was integrated into Russian reconnaissance and strike UAVs, culminating in January 2026 in reports of Starlink-connected drones remaining over Kyiv for hours. Ukraine responded with what appears to have been the first publicly documented national terminal-level access-control system deployed at scale over a mass-market commercial LEO network during an active war. The system initially appeared effective: publicly observable Russian Starlink use fell to isolated cases, while the first public cases of illegal registration involved isolated terminals, marginal recruits and payments measured in tens of dollars. Yet the government quietly hardened registration from 2 June, and during June and July the public enforcement record changed markedly. On 24 July the Security Service of Ukraine (SSU) reported 76 illegally registered terminals involving false passports and postal registration; a day later it reported more than 1,000 verified terminals registered through postal branches using proxy identities. The whitelist continued to function as a network-enforcement mechanism. The crisis had moved upstream, from excluding terminals outside the list to protecting the admission integrity of the list itself.
1. The Problem the Whitelist Was Built to Solve
Russian use of Starlink predated the crisis that triggered the whitelist. At least by late 2023, Russian units were already using civilian terminals in occupied Ukrainian territory. By February 2024, Ukraine’s Defence Intelligence was describing the practice as increasingly systematic. The vulnerability was inherent in the mismatch between a mass-market commercial service and an active front: equipment could circulate through third countries and intermediaries, legitimate and hostile users could operate close to one another, territorial control could change faster than commercial geofencing rules, and hardware acquired for an authorised market could be moved into a prohibited one.
For almost two years this was primarily a ground-force communications problem. At the end of 2025, however, the character of Russian adoption changed rapidly. On 29 November, Ukrainian radio-technology specialist Serhii Beskrestnov published a photograph of a UAV resembling a Russian Molniya fitted with Starlink. On 1 December he stated that Russian forces were using Starlink on reconnaissance UAVs. By mid-December he was reporting daily detection of Starlink-equipped strike Molniyas and a transition from improvised mounting to deliberate integration into the aircraft. Reports soon extended to other military platforms and to strikes beyond the immediate front line.
The escalation acquired a political dimension in late January. Starlink-connected Russian UAVs were reported to have remained over Kyiv for several hours, moving above different parts of the capital. Within days, Defence Minister Mykhailo Fedorov publicly stated that his team had contacted SpaceX within hours of Russian Starlink-equipped drones appearing over Ukrainian cities and was working with the company on countermeasures. A weakness that had long been tolerated as part of the messy geography of a civilian communications service had become a visible problem of national air defence and political security.
The immediate challenge was therefore no longer simply that Russian troops possessed commercial satellite terminals. Starlink was being incorporated into unmanned systems capable of maintaining resilient communications over long distances and operating where disruption of a conventional command link was difficult. Ukraine’s answer was to distinguish authorised from unauthorised use at the level of the individual terminal.
2. A National Whitelist for a Commercial LEO Network
On 1 February 2026 the Cabinet of Ministers adopted Resolution No. 115 governing the use of Starlink terminals during martial law; it entered into force the following day. The Ukrainian authorities would determine which users and terminals were authorised, while SpaceX would use the resulting list for network-side enforcement.
There was nothing conceptually novel about that division of responsibilities. Governments determine legal eligibility and commercial operators implement state restrictions every day. The historical significance lay in the object, scale and circumstances of the arrangement: sovereign admission decisions were being applied to individual terminals of a mass-market commercial LEO network across a country fighting a major war. As far as the public record shows, this was the first national regime of its kind deployed at such scale in active conflict.
Under the original rules, an individual could either register up to three terminals if they were physically presented or register one terminal without presenting the device. The resolution allowed several civilian registration channels where technically available, including administrative service centres, banks, post offices and other approved legal entities. Registration through Ukrposhta and Nova Poshta post offices was publicly launched on 17 February.
The architecture was straightforward. Ukraine determined eligibility; SpaceX enforced the resulting decision. Its security therefore depended on two different operations working correctly. SpaceX had to exclude terminals outside the authorised set, while the Ukrainian administrative layer had to ensure that hostile terminals could not be made to appear legitimate inside it.
3. Phase One: Apparent Control
For the first several months, the public record suggested that the arrangement was working. Publicly observable Russian Starlink use fell to isolated cases, while Ukrainian officials and military specialists repeatedly described the countermeasure as effective. Russian forces were reported to be moving towards alternative satellite communications, and previously acquired Starlink terminals were described as having become largely unusable.
The enforcement record seemed consistent with that assessment. By the end of May, the Security Service of Ukraine (SSU) had publicly disclosed seven cases involving isolated registrations or attempts, opportunistic recruits and rewards measured in tens of dollars per terminal. Even when suspects allegedly intended to involve another ten or twenty people, the underlying model remained retail: recruit one more individual, use that person’s identity for one or a few terminals, then repeat.
The full public enforcement series through 25 July is shown below. It should be read as a record of enforcement output, not as a direct measurement of the underlying volume of illegal registration. The number of people, identities and terminals is kept separate because SSU releases do not always report all three.
Table 1. Public enforcement output concerning illegal Starlink registration, February–July 2026
| Date | Case / actor | Registration pattern and channel | Reported terminal output | Additional people / identities | Procedural stage / charge |
|---|---|---|---|---|---|
| 24 Feb | Izmail: man and partner | Russian recruitment; attempted use of administrative service centre | 0 completed; 4 targeted | 2 suspects | Suspicion; Arts. 28, 111 |
| 3 Mar | Kropyvnytskyi | One registration; detained near administrative service centre while expanding scheme | 1 | +11 intended | Suspicion; Art. 111 |
| 25 Mar | Vynohradiv | Individual recruitment; UAH 1,500 per registration | ~3 targeted | 1 principal actor | Conviction, 12 May; Art. 114-1 |
| 1 Apr | Irpin | One own identity plus two identities used without informed participation; postal channel | 3 | +20 intended | Suspicion; Art. 111 |
| 3 Apr | Zhytomyr region | Recruit declined task and contacted SSU | 0 | 1 approached | No charge announced against recruit |
| 7 May | Kropyvnytskyi | One own registration; linked to 3 Mar case | 1 | +>10 intended | Conviction, 12 Jun; Art. 114-1 |
| 13 May | Kyiv | Deserter; post office; two registrations | 2 | +20 intended | Suspicion; Art. 111 |
| 12 Jun | Odesa | Cargo worker registered for himself and recruited acquaintances | 1 confirmed | +≥12 | Suspicion; Arts. 28, 111 |
| 29 Jun | Rivne / Dnipropetrovsk / Volyn | Multi-person network using own and other identities | ≥12 registrations / activations explicitly described* | Several dozen additional identities | Suspicion; Arts. 111, 111-2, 408 |
| 20 Jul | Kirovohrad / Zhytomyr / Mykolaiv | Three separate recruits; own identities plus acquaintances or relatives | ≥3 confirmed; full total undisclosed | +≥13 and relatives | Suspicion; Arts. 111, 114-1, 309 |
| 22 Jul | Mykolaiv | Starlink task secondary to terrorism case | 1 | +11 intended | Suspicion; Arts. 111, 15/258 |
| 24 Jul | Kyiv | Two suspects; false passports; repeated postal registration; postal employee allegedly used without knowing purpose | 76 | Multiple false / proxy identities | Suspicion; Art. 111 |
| 25 Jul | Dnipro | Organised verification through post offices using proxy personal data | >1,000 verified | Hundreds of person-level records necessarily implicated | Suspicion; Art. 111-2 |
*The 29 June SSU release uses different formulations for registrations and activations across the regional sub-cases. The table therefore reflects the minimum number explicitly described as completed, while keeping the additional identities separate.
Legal note. Article references are to the Criminal Code of Ukraine: Art. 28 — commission by a group of persons / prior conspiracy; Art. 111 — high treason; Art. 111-2 — aiding the aggressor state; Art. 114-1 — obstruction of the lawful activities of the Armed Forces of Ukraine and other military formations; Art. 408 — desertion; Art. 309 — unlawful handling of narcotic drugs, psychotropic substances or analogues without intent to sell; Art. 258 — terrorist act; Art. 15 — attempted criminal offence. The table records the legal qualification reported by investigators or prosecutors at the relevant procedural stage; it is not a finding of guilt unless a conviction is explicitly noted.
The first seven cases formed a strikingly homogeneous series. Their protagonists were unemployed people, a construction worker, deserters and other opportunistic recruits. Successful output was limited to one or a few terminals. Payments per device were in the tens of dollars. Nothing in this series looked like infrastructure capable of producing Russian access at strategically significant scale. On the contrary, it fitted comfortably within the public picture of a functioning whitelist whose edges were being probed by low-level and frequently unsuccessful attempts at circumvention.
4. Price as a Diagnostic Signal
A separate analysis of 40 Ukrainian criminal cases involving remotely commissioned sabotage, arson and related coercive tasks provides a useful benchmark for evaluating those payments. Even relatively simple physical assignments normally commanded sums in the hundreds of dollars. The earliest Starlink registration cases, by contrast, reported payments such as $30, roughly $36, or around $65 per terminal.
The discrepancy did not make the cases false. Cheap recruits existed, and the investigations could accurately describe the individuals involved. It did, however, make those cases poor evidence that the principal Russian registration channel had been identified and suppressed. Access to reliable Starlink connectivity had exceptional operational value, while the publicly visible work of obtaining it appeared to be priced below or at the lowest edge of much less consequential coercive tasks.
The price comparison therefore produced a testable expectation. If a scalable channel existed, it should eventually look different from a larger collection of people earning a few dozen dollars each. It should require organised access to identities, documents, registration procedures and intermediaries capable of moving significant numbers of terminals through the administrative system.
5. The Observability Problem
That inference must still be separated from what the public case series can actually prove. SSU releases are enforcement output: they show what the security service detected, investigated and decided to publish. Seven small cases do not establish that the underlying phenomenon was small, just as a limited number of publicly recovered Russian Starlink-equipped platforms does not establish the true scale of battlefield use.
Wartime conditions strengthen this limitation. Intelligence data, terminal telemetry, technical methods for detecting hostile use and many operational countermeasures are necessarily absent from the public domain. Ukraine’s wider wartime information regime also places substantial restrictions on the publication of military information. The absence of publicly reported Russian Starlink use therefore cannot be treated as evidence that such use was absent.
The source structure presents an additional problem. Much of the persistent public technical reporting about Russian Starlink use came from Serhii Beskrestnov. He was an exceptionally well-informed observer, but also an adviser to the defence minister and part of the institutional environment responsible for developing and explaining the countermeasure. His reporting is valuable evidence of what Ukrainian specialists were seeing and how the responsible institutions interpreted the situation. It is not an independent audit of the success of those institutions.
The strongest defensible description of the first phase is consequently narrow. Publicly observable Russian Starlink use fell to isolated cases; the public enforcement cases remained small; and official or institutionally affiliated communication expressed a high degree of confidence in the whitelist. None of those observations establishes that every significant Russian access channel had disappeared.
6. The Quiet Hardening of 2 June
Against that apparently favourable public background, the government changed the rules. Resolution No. 691 was adopted on 30 May and entered into force on 2 June. Its principal change for individual users removed the only route that had allowed one terminal to be registered without physical presentation. From that point, an individual could still register up to three terminals, but every device had to be physically presented.
The amendment strengthened precisely the admission layer that linked an applicant, an administrative procedure and a physical terminal. Yet the public enforcement record available at the end of May showed no obvious registration crisis comparable to the scale that would become visible later. The seven disclosed cases still depicted low-volume recruitment rather than systematic penetration of the registration infrastructure.
The change also attracted little immediate public attention. Ukraine’s Ministry of Digital Transformation, communicating the civilian verification rules through the Diia portal, publicly described the revised requirements only on 13 July, 41 days after they had entered into force. No new July amendment to Resolution No. 115 existed: the requirements presented as an update had already been legally operative since 2 June. The same July communication also stated that an ordinary legal entity needed to have existed for at least one year, although both versions of the governing resolution specified one month.
For the present analysis, the significance is chronological rather than motivational. By the time the public enforcement picture changed dramatically in late July, the state had already spent more than a month operating a stricter version of the whitelist.
7. Phase Two: Scaling Within the Old Model
The first case after the June amendment still looked much like the spring series. On 12 June, the SSU described an Odesa cargo worker who had registered a terminal in his own name and then recruited at least twelve acquaintances under false pretexts. The mechanism remained familiar: an opportunistic individual provided one valid identity and tried to scale the operation through people around him.
The 29 June release marked the first clear quantitative escalation. The SSU described eight suspects across the Rivne, Dnipropetrovsk and Volyn regions. The social profile remained broadly unchanged — deserters, previously convicted people, young recruits and other readily available intermediaries — while the operation continued to rely on identities gathered from acquaintances and other third parties. What changed was the output. The release explicitly described at least a dozen completed registrations or activations and referred to several dozen additional identities or potential participants. The mechanism had not yet changed; its output had.
The cases disclosed on 20 and 22 July remained within the same basic model. They involved individuals registering devices themselves and attempting to recruit relatives, acquaintances or vulnerable people for additional registrations. The 22 July Mykolaiv case was unusual mainly because Starlink registration was secondary to an alleged terrorism assignment; its registration pattern itself was not exceptional.
A second development was becoming visible at the same time: the growing prominence of postal infrastructure. Early attempts had included administrative service centres, arguably the most formalised and visibly state-controlled registration route. Postal registration was already present in the April Irpin case and the May Kyiv case, so there was no clean transition from one channel to another. But by summer, the distributed postal network was increasingly central to the public circumvention record, and both subsequent bulk cases were explicitly tied to registration through post offices.
This mattered because accessibility and attack surface were two sides of the same design choice. A geographically distributed civilian network made the whitelist usable at national scale for legitimate customers. The same distribution created many local points at which identity, documents and devices had to be converted into a trusted administrative record.
8. The Categorical Break: 24–25 July
On 24 July, the public object changed. The SSU reported two unemployed Kyiv residents who had allegedly registered 76 Starlink terminals for Russian special services. The number was an order of magnitude larger than anything previously visible, but the mechanism was even more significant. The release referred to false Ukrainian passports, repeated registration through post offices and a postal employee whom the suspects allegedly used without revealing the true purpose of the transactions.
For the first time, document fraud, repeated procedural access and distributed registration infrastructure appeared together in a bulk-scale case. The visible problem was no longer simply that a marginal recruit could sell the use of his or her identity for several dozen dollars. The registration process itself had become operational infrastructure.
A day later, the scale changed again. On 25 July the SSU reported that an organiser in Dnipro had arranged the verification of more than 1,000 terminals through post offices using personal data belonging to proxy individuals. This figure remains an investigative claim rather than a judicially established count. Taken on its own terms, however, it has unavoidable structural implications.
An individual could register no more than three terminals. More than 1,000 verified devices therefore require at least 334 person-level identity records even before any other procedural requirement is considered. After 2 June, every terminal registered by an individual also had to be physically presented. The SSU did not disclose how the registrations were distributed over time, so the public record does not establish how many occurred before or after that amendment, how many post offices processed them, how many individuals physically appeared or how the operation was organised locally.
Those unknowns matter, but they do not restore the early retail model. A result measured in more than 1,000 verified terminals requires an enabling layer capable of bringing together large quantities of personal data, documents or document substitutes, physical devices and repeated administrative actions. The SSU named an organiser and described the use of proxy identities. Its public account did not fully explain the wider layer required to produce that output.
The sequence must not be converted into a false growth curve. Public releases do not show that illegal registration itself rose smoothly from one terminal in March to more than 1,000 in July. Larger channels may have existed earlier; investigations may have matured at different times; disclosure policy may have changed; or the phenomenon itself may genuinely have scaled. What can be established is narrower and more important: the publicly visible object changed category.
The early cases concerned attempts to circumvent the whitelist one identity at a time. The bulk cases showed the administrative machinery of admission becoming part of the operation.
9. Admission Integrity: What the Crisis Means Beyond Ukraine
The whitelist crisis was not a collapse of network enforcement. There is no public evidence that SpaceX systematically failed to deny service to terminals that Ukraine identified as unauthorised. The problem moved upstream.
The original logic was straightforward: identify legitimate terminals, approve them, and deny service to everything else. Once an adversary can cause hostile terminals to acquire apparently legitimate entries, however, the decisive security property becomes admission integrity — confidence that the authorised set contains what the system believes it contains.
That turns several ordinary administrative questions into security questions. Is the person presenting a credential actually its owner? Is the physical terminal being presented the terminal whose identifiers enter the registry? Can repeated use of proxy identities or documents be detected before it becomes bulk processing? Can a distributed registration network preserve adequate assurance without making legitimate use prohibitively difficult?
These are not Starlink-specific problems. Any future arrangement in which a state relies on a commercial LEO operator to implement sovereign access decisions will face the same structural tension. Strong network enforcement raises the value of attacking the admission process. The more consequential an authorised-list entry becomes, the more attractive identity systems, registrars, documents and local verification procedures become as adversarial targets.
The Ukrainian case therefore demonstrates two things at once. Terminal-level sovereign access control over a mass-market commercial LEO service can be operationalised during a major war. But once it is operationalised, the security perimeter expands beyond satellites, accounts and network rules into the mundane administrative machinery that determines who is allowed onto the network in the first place.
Conclusion
Ukraine’s whitelist produced a real form of control over Starlink access. The early public record was consistent with a system in which publicly observable Russian Starlink use had fallen to isolated cases and attempts at circumvention remained low-volume. By late July, however, the public enforcement record exposed a different scale and a different layer of vulnerability: false or proxy identities, distributed registration infrastructure and bulk verification.
The historical significance of the case therefore lies not in a simple verdict that the whitelist “worked” or “failed”. It lies in the movement of the security problem. Once exclusion at network level became effective, admission itself became valuable enough to attack.
The whitelist was built to keep the adversary out of the network. Within six months, getting onto the whitelist had itself become the attack surface.
References
Beskrestnov, Serhii. 2025–2026. Public communications on Russian military use of Starlink, November 2025–July 2026.
Cabinet of Ministers of Ukraine. 2026a. Resolution No. 115, Certain Issues Concerning the Use of Starlink Satellite Communication Terminals During Martial Law, 1 February 2026.
Cabinet of Ministers of Ukraine. 2026b. Resolution No. 691 amending Resolution No. 115, 30 May 2026.
Defence Intelligence of Ukraine. 2024. russians Have Starlink – Defence Intelligence of Ukraine Confirms Using of Satellite Communication Terminals by Occupants, 11 February 2024.
Diia. 2026a. Starlink for individuals: verify terminals at Ukrposhta or Nova Poshta, 17 February 2026.
Diia. 2026b. Updating Starlink verification: new conditions and Diia services, 13 July 2026.
Khimich, Roman. 2026a. Sabotage Has a Price Floor: Remote Coercive Tasking in Wartime Ukraine.
Khimich, Roman. 2026b. Starlink Was Blocked. Russian Access Was Not.
Khimich, Roman and Aleksandr Turkhanov. 2026. Why Civil Control of Dual-Use Connectivity Will Fail in UK Waters.
Ministry of Defence of Ukraine. 2026a. The Ministry of Defence of Ukraine and SpaceX are resolving the issue of Starlink use on russian UAVs, 29 January 2026.
Ministry of Defence of Ukraine. 2026b. Ukraine and Starlink to roll out terminal authorization system, 1 February 2026.
Ministry of Defence of Ukraine. 2026c. Starlink terminals on the whitelist remain operational, while russian terminals have already been blocked, 5 February 2026.
Security Service of Ukraine (SSU). 2026. Public releases concerning illegal Starlink registration, 24 February–25 July 2026.
Verkhovna Rada of Ukraine. The Criminal Code of Ukraine.