
What happened
On 24 February 2022, at roughly 03:02 UTC, hours before Russian forces entered Ukraine, tens of thousands of satellite broadband modems on Viasat's KA-SAT network stopped working across Ukraine and parts of Europe. According to Viasat's own account of the incident, an attacker exploited a misconfigured VPN appliance to reach the trusted management segment of the network, then moved from there to issue commands that overwrote key data in the flash memory of consumer-grade SurfBeam2 modems, disabling them. Viasat said it found no damage to the modems' electrical components and restored service partly by shipping roughly 30,000 replacement units. On 10 May 2022, the United Kingdom's National Cyber Security Centre stated it was 'almost certain' Russia was responsible, and CISA updated its own SATCOM security advisory the same day to reflect that attribution.
Confidence and limits
The technical account of how the intrusion reached the modems comes from Viasat, the affected operator, describing its own network. The attribution to Russia is a government assessment stated as almost certain, the UK's own standard confidence language, not a claim of absolute certainty or a court finding, and this article has not opened a corresponding Russian government response. Reported effects beyond Ukraine, including disruption to remote monitoring at wind farms in central Europe, are not independently verified here beyond what the cited government and company documents state.
Why it mattered
The attack disabled communications equipment used by Ukraine's military and government at the moment an invasion began, and its spillover into consumer and commercial terminals across unrelated European countries showed how a shared satellite network can transmit an attack's effects far beyond its intended target. The initial access point, a VPN appliance misconfiguration on a management network rather than any flaw in the satellite link itself or the encryption protecting customer traffic, is the detail defenders of any remotely managed infrastructure should note.
Defensive takeaway
Treat the management network that administers remote devices, routers, terminals, industrial controllers, as at least as sensitive as the data those devices carry, since compromising the manager can let an attacker reach every device it manages at once.
- Is your management-network VPN access restricted, monitored and kept current on patches to the same standard as your production data path?
- Could a single compromised management credential push a destructive command to your entire fleet of remote devices simultaneously?
- Do you know which of your vendors' shared infrastructure could carry an unrelated attack's effects into your own environment?
Viasat's own account and the government attribution together describe a single well-documented intrusion path exploited at a moment of clear strategic significance. Neither document claims to explain every consequence the attack had across the networks it touched.
Treat the management network administering your remote devices as at least as sensitive as the data those devices carry, since compromising the manager can reach every device it controls at once.
Viasat's technical account of the intrusion is the operator's own description of its network; the attribution to Russia is the UK government's assessment, stated at 'almost certain' confidence, not an absolute claim or a court finding.
Sources & reading trail
Viasat's own account of the 24 February 2022 attack: the VPN misconfiguration used for initial access, the modems affected, and the remediation.
company-primary · Source published: 30 March 2022 · Retrieved: 16 September 2026
The UK government's assessment, stated as almost certain, that Russia was responsible for the Viasat attack.
government-primary · Source published: 10 May 2022 · Retrieved: 16 September 2026
Advises SATCOM providers and customers on mitigations, and was updated 10 May 2022 to reflect attribution of related threat activity to Russian state-sponsored actors.
government-primary · Source published: 17 March 2022 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.