BroadbandMilitary

WaPo: US Has Privately Attributed Hack of Viasat KA-SAT Ground Infrastructure to GRU

Viasat KA-SAT satellite. The satellite provides "internet coverage over much of Europe," per Viasat. Graphic via Viasat.
Viasat KA-SAT satellite. The satellite provides “internet coverage over much of Europe,” per Viasat. Graphic via Viasat.

US intelligence officials have attributed the hack of a satellite broadband service to the GRU, Russia’s largest military spy agency, the Washington Post reported Thursday. While its spooks may have reached a determination, the US government has not publicly attributed to Russian military hackers.


“We are concerned about the apparent use of cyber operations to disrupt communications systems in Ukraine and across Europe and affect businesses and individuals’ access to the Internet,” a National Security Council spokesperson told WaPo.


The FBI and US cyber agency CISA recently warned US SATCOM operators to step up their security posture and lower their threshold for incident reporting, due to elevated threat levels.

What say Ukraine?

Viktor Zhora, a senior Ukrainian cyber official, flatly told WaPo: “We don’t need to attribute it since we have obvious evidence that it was organized by Russian hackers to disrupt the connection between customers that use this satellite system.” Zhora pointed to the timing of the attack, which knocked satellite receivers offline shortly before Russian missiles started flying into Ukraine and forces started pouring over the Belarussian border. “It was a really huge loss in communications in the very beginning of war,” Zhora told Wired.

New details emerge

The attack on Viasat KA-SAT receivers likely disrupted Ukrainian military comms at the beginning of the war. Elite units of the Ukrainian military are using satellite networks to steer drones, among other things. And Zelenskyy is reportedly using a satphone to stay connected and communicate with the outside world.


Viasat, which has repeatedly referred to the incident as a “deliberate, isolated, and external cyber event,” is still working to restore connectivity in affected areas. The satellite operator is in the process of shipping new product to distribution partners so that customers can replace bricked hardware.

Size, scope, and scale

The attack has collateral damage far beyond Ukraine or the country’s armed forces. To wit: Thousands of wind turbines are still offline in Germany. Western intelligence agencies are probing the attack, and without elaborating, the NSA has confirmed it’s also looking into the breach.

Related Stories
Military

We Have Some Space Questions About The Golden Dome

President Donald Trump’s executive order calling for a new, satellite-based missile defense architecture around the continental US has defense contractors salivating, but questions about the cost, capabilities, and requirement for such a system remain unanswered. Are we already doing it? The executive order calling for the “Iron Dome” (now Golden Dome) system expected the Pentagon […]

Military

The Space Force Outlines Its Guide to Space Warfare

Space is the ultimate high ground, and like a modern-day Sun Tzu, Space Force chief Gen. Chance Saltzman has issued his Art of Space War.

InternationalMilitaryPolaris

NATO Considers Reopening Space Policy Ahead of Schedule

“It’s not supposed to be even touched until 2027. Now they’re saying that’s probably too long. So let’s talk about—is now the time, based on what’s happening in the world,” Col. Jonathan Whitaker told Payload on the sidelines of Space Symposium. 

Military

Derek Tournear Will Return to the SDA’s Helm

Dust off that nameplate: Derek Tournear is taking his corner office back. The former leader of the Space Development Agency (SDA) will return to his old job on April 17, following three months of administrative leave.