/

Israeli Surveillance Firms Claim the Power to Map Starlink Users Worldwide

A Haaretz investigation reveals how Israeli-owned companies are commercializing tools that can locate Starlink terminals and, in some cases, identify the people behind them, raising new questions about privacy in the era of satellite internet warfare.

4 mins read
Starlink

A new frontier in global surveillance has emerged around Starlink, the satellite-based internet system developed by SpaceX under its CEO Elon Musk, according to an investigation published by Haaretz. Two Israeli-owned companies, operating partly outside Israel, are reportedly marketing technology capable of locating Starlink terminals across the globe and, in some cases, linking those devices to individual users. The findings point to a rapidly evolving intelligence market built not on hacking satellite systems, but on fusing large-scale commercial and behavioral data to reconstruct user identities.

Starlink, which has become one of the most widely deployed satellite internet systems in the world, is designed to provide connectivity independent of national telecommunications infrastructure. That feature has made it strategically significant in conflict zones and politically sensitive environments. It has been used by Ukrainian forces during the war with Russia, by protesters in Iran during government-imposed internet blackouts, and by humanitarian groups operating in disconnected regions. According to estimates cited in the investigation, the network now serves millions of subscribers across more than 150 countries, with usage ranging from civilian communication to military coordination.

The same features that make Starlink resilient also make it difficult for states to control or monitor through traditional telecom interception methods. Instead of routing through national infrastructure, Starlink relies on a constellation of thousands of low-Earth orbit satellites. This architecture has forced intelligence agencies and private surveillance firms to rethink their methods. Rather than intercepting communications directly, companies are increasingly focusing on identifying where terminals are located and correlating that data with other digital signals.

At the center of the Haaretz report is a Cyprus-based company called TargetTeam, owned by Israeli founders and reportedly composed of veterans from Israeli cyber intelligence firms such as Rayzone Group and Cognyte. The company has developed a system known as “Stargetz,” which, according to marketing materials, can track close to one million Starlink terminals globally. During a demonstration described by Haaretz, the system displayed a live map of terminals distributed across regions including the Middle East, South Asia, Russia, and China, as well as maritime clusters likely representing ships equipped with satellite connectivity.

The system, according to its own presentation, is capable of identifying patterns that go beyond simple geolocation. In some cases, it claims to “deanonymize” users, meaning it can associate a Starlink terminal with a real-world identity or at least with a broader behavioral profile. One example cited in the demonstration involved a user registered with a foreign phone number whose activity suggested movement across multiple countries, including Pakistan and Iran. While the accuracy of such claims has not been independently verified, the scale of the system reflects a broader trend in intelligence technology: the aggregation of fragmented digital traces into coherent identity profiles.

A representative from TargetTeam, as cited in the report, described how such systems are already being marketed to government clients for counterterrorism, sanctions enforcement, and maritime monitoring. The logic underpinning the tools is not new, but the application is. Instead of relying on network penetration or satellite signal interception, the systems reportedly combine advertising data, mobile device signals, and online behavioral markers. A salesman quoted in the investigation suggested that even when vessels or devices attempt to go dark, user behavior and residual digital activity can still expose them.

The investigation also highlights that TargetTeam is not alone. Rayzone Group is reported to offer a comparable system integrated into its broader intelligence suite. Unlike traditional surveillance tools focused on targeted monitoring of specific devices, these platforms are designed to operate at scale, analyzing vast datasets in real time or near-real time. Rayzone’s tools, according to the report, are overseen in part by Israel’s defense establishment and are marketed alongside advertising-based intelligence capabilities that extract location data from digital ecosystems.

The use of advertising-derived identifiers appears to be a key enabler of these systems. Modern smartphones and apps generate unique identifiers used for targeted advertising, which can inadvertently leak location and behavioral information. By combining these identifiers with network usage patterns, companies can reconstruct a user’s movements even when direct communication interception is not possible. This method, sometimes referred to in the industry as ad-tech intelligence, has raised concerns among privacy advocates who argue that commercial data markets have become an unregulated source of surveillance inputs.

According to Amnesty International’s Security Lab head Donncha Ó Cearbhaill, quoted in the Haaretz investigation, satellite services like Starlink have become essential lifelines in regions experiencing internet shutdowns, from Myanmar to Sudan and Iran. However, he warned that the parallel expansion of data-driven surveillance tools means that the same technologies enabling free communication can also expose users to state and non-state monitoring. He emphasized that the ongoing commercialization of location data in advertising ecosystems creates unintended risks for activists, journalists, and civilians alike.

The report also situates these developments within a broader evolution of the cyber intelligence industry. Rather than focusing solely on exploiting software vulnerabilities, modern firms are increasingly engaged in what analysts describe as large-scale data fusion. This approach aggregates signals from multiple sources—mobile data, online behavior, financial transactions, and advertising identifiers—to construct detailed behavioral maps. Industry observers have described this shift as the “Palantirization” of security technology, referencing the data analytics approach pioneered by Palantir Technologies.

This model represents a departure from earlier eras of digital surveillance associated with tools like spyware targeting individual devices. Instead of hacking a single phone, the new systems aim to observe entire populations of devices indirectly through their data footprints. The Haaretz investigation also references historical systems such as “Starsky,” developed by Israeli cyber intelligence firm Verint Systems, which once relied on intercepting satellite phone infrastructure before being rendered obsolete by newer decentralized satellite networks like Starlink.

SpaceX and Starlink did not respond to requests for comment included in the investigation, according to Haaretz. The companies featured in the report, including TargetTeam and Rayzone, also declined to comment. As satellite internet continues to expand globally, the findings raise broader questions about how emerging communication technologies intersect with evolving surveillance capabilities. In a world where connectivity no longer depends on national infrastructure, the ability to map and identify users through indirect data signals may become one of the defining intelligence challenges of the coming decade.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Latest from Blog