Just after three in the morning on February 24, 2022, satellite modems began to fail across Ukraine. Within a narrow window, tens of thousands of modems across Europe had their internal memory overwritten and their operating instructions erased. The Russian ground invasion of Ukraine began later that morning. The attack on Ukrainian satellite communications came first.
The network was KA-SAT, a broadband satellite that serves homes and businesses across Europe and parts of the Middle East. It is operated by Viasat, an American satellite communications company. In places where fibre and cable do not reach, a rural farm, an island community, an offshore platform, the small dish on the roof is the internet connection, and for many customers it is the only one there is. A dish talks to a satellite in geostationary orbit, roughly thirty-six thousand kilometres overhead. The satellite relays the signal to a ground station and back. Between the dish and the customer sits a modem about the size of a paperback book, which turns satellite signals into ordinary internet traffic. That last box is the whole connection. Cut a fibre line in a city and the traffic usually reroutes through another provider. Disable the one satellite modem in a rural area with no alternative and the connection is simply gone, with nothing left to carry it.
Every satellite network has two halves. One is the space segment, the satellite itself, a relay in geostationary orbit built to bounce signals between users on the ground and the network’s gateway stations. Everything else is the ground segment: the management servers, the customer databases, and the software that provisions and monitors every modem in the field. The satellite carries the traffic. The ground segment controls it. It works a little like a mail plane and the sorting office it flies for. The plane moves parcels between cities. The sorting office is where addresses are assigned and routing is decided. Attacking the satellite would be like shooting down the plane. Reaching the ground segment is walking into the sorting office and rewriting the address on every parcel.
The way in was a VPN appliance. A virtual private network is what operators use to reach management systems remotely without exposing them to the open internet, an encrypted corridor with a door that needs a key at each end. According to Viasat’s incident report, the VPN appliance on the KA-SAT management network was misconfigured. Through it, the attackers reached the trusted management segment, and from there the specific systems used to operate the modems in the field. The path was short. Many intrusions in the security record involve attackers spending days or weeks working through an internal network. This one moved from a single misconfigured entry point to the ability to command every modem on the network.
The commands they could now issue were not improvised. Viasat’s report describes them as “legitimate, targeted management commands,” the same instructions an operator uses to push a firmware update or reset devices across a whole fleet at once. A satellite network serving tens of thousands of customers across a continent is maintained exactly this way. You do not send a technician to each rooftop. You push the command from one place. The system was built to reach every modem at once, and that is precisely the capability the attackers took over.
The tool they pushed was a piece of malware that SentinelOne later named AcidRain. Most malware is built to steal or to hold hostage. Ransomware encrypts files and demands payment. Information stealers copy credentials and records. AcidRain did neither. It overwrote data and destroyed it, with nothing copied out and no key to reverse it. It is a wiper, and there is a logic to using one here. A criminal needs the victim to know they have been hit, because the payment depends on it. An operation aimed at communications infrastructure on the morning of an invasion needs the opposite: the infrastructure to stop working immediately, at scale, with no quick way back.
AcidRain worked by overwriting the flash memory of the modems. Flash memory is the permanent storage that holds a device’s firmware, the software that tells the modem how to start up and how to move traffic between the dish and the customer. It is the layer that makes a modem a modem. Overwrite those instructions with meaningless data and the modem does not fail in a way you can fix by turning it off and on again. It no longer knows what it is. The wiper was delivered through the same management channel the attackers had already reached, pushed out across tens of thousands of modems the way a routine firmware update would be. The system built to keep the modems running was the system used to destroy them.
Whether those modems were permanently destroyed is a question Viasat’s own account answered in two different ways. An early statement, later repeated in the UK government’s attribution release, said tens of thousands of terminals had been “damaged, made inoperable and cannot be repaired.” The fuller incident report at the end of March said the modems could be “fully restored via a factory reset,” and that Viasat shipped replacements mainly for speed. Nearly thirty thousand replacement modems went out to distributors. Both accounts are on the record, and both are Viasat’s. The practical picture sits between them. A modem on a rooftop in a rural area, with little accessible technical support, has had its firmware wiped to the point where it can no longer reach the network that would deliver a remote fix. It is recoverable in theory and dead in practice. In a field deployment during a war, the distance between “cannot be repaired” and “can be repaired but will not be” narrows to almost nothing.
The damage that reached beyond Ukraine had nothing to do with Ukrainian communications at all. KA-SAT’s coverage spans most of Europe. A modem in Kyiv and a modem in Bavaria connect to the same satellite, through the same ground infrastructure, reachable by the same management commands. The wiper did not carry a list of targets sorted by country. It was pushed to the modems within reach, and some of those modems were in Ukraine while others were not. In Germany, 5,800 wind turbines whose remote monitoring was handled by the manufacturer Enercon lost that link. The turbines kept turning, because a turbine generates electricity from wind and does not need a satellite link to do it. But the modems connecting each turbine’s monitoring system back to the central operations centre were KA-SAT terminals, and once they were wiped, no telemetry reached the control room and no one could check a turbine’s status or adjust its output without driving to the site. Wind turbines are spread out by nature, across hillsides and coastlines, often placed in remote spots on purpose, and once the link was gone, each site had to be reached on foot.
Viasat publicly disclosed the incident on March 30, 2022, about five weeks after it began. Attribution came a few months later, in two layers. In May 2022, the UK, the United States, and the European Union issued separate but coordinated statements. All three named Russia. None of them, in those official statements, named a particular agency or unit. The more specific attribution belongs to the research community. SentinelOne linked AcidRain, at medium confidence, to malware previously tied to the Russian government. MITRE ATT&CK, the reference catalogue the industry uses to track threat groups, attributes this pattern of destructive attacks to a group it designates Sandworm and maps to a unit of Russia’s military intelligence service, the GRU. Sandworm is not a name Russia uses for itself. It is the label the international security community settled on for a set of destructive operations linked to the GRU across several countries and several years.
The way in was specific and well documented: a misconfiguration in a single VPN appliance that gave access to the management infrastructure of a satellite network serving a continent. There is no published record of pre-breach security guidance specific to this system, so this was not a failure to meet a known public standard the way a retail or banking breach might be. It was a state intelligence operation carried out during an armed conflict, and it turned on a single configuration error at the point of entry. Configuration errors are common, and they are fixable. The deeper problem shows up when civilian infrastructure that spans a continent is run as a single system, managed from one ground segment, behind one set of access points, with no boundary inside it between the countries it serves, and a state decides to use it as a weapon.
That problem outlived the incident. In November 2023, roughly twenty months later, the Council of the EU approved conclusions on an EU Space Strategy for Security and Defence. The conclusions cited the Viasat attack by name, as a reason to treat space infrastructure and cybersecurity as connected rather than separate. Before February 2022, European defence policy had largely handled space assets and cyber threats as different domains. The attack showed they were not, and that a cyberattack delivered through ground-based network infrastructure could take down space-based communications across a continent. A military cyberattack on a commercial satellite operator, during a war, helped produce a new strand of European defence policy, one that treats satellite communications as critical infrastructure needing coordinated protection at the continental level. Beyond that, no specific legal outcome tied to the attack has been publicly documented.
Viasat recovered. The network was largely stable within hours and fully stable within several days. For the company, this was a serious incident that it came back from. The people whose internet connection vanished on the morning of the invasion do not appear in the recovery figures at all, and the German control room reading nothing from 5,800 turbines was never the target of anything. When one machine serves a continent through one set of doors, an attack meant for one country travels to everyone the operator reaches.
**Sources & further reading:**
- Viasat, “KA-SAT Network cyber attack overview” (incident report, March 30, 2022)
- UK Government / NCSC, “Russia behind cyber attack with Europe-wide impact an hour before Ukraine invasion” (May 10, 2022)
- Council of the EU / EU statement attributing the KA-SAT attack to the Russian Federation (May 10, 2022)
- U.S. Department of State, Secretary Blinken statement on the KA-SAT cyberattack (May 10, 2022)
- SentinelOne (Guerrero-Saade and van Amerongen), “AcidRain: A Modem Wiper Rains Down on Europe” (March 31, 2022)
- MITRE ATT&CK, Sandworm Team (G0034)
- Council of the EU, conclusions on an EU Space Strategy for Security and Defence (November 14, 2023)
- Contemporaneous reporting on the 5,800 Enercon wind turbines that lost their remote-monitoring link
