Summary
- Environment: Satellite/Telecom
- Operational impact: Bricked tens of thousands of modems across Europe; disrupted Ukrainian military comms and remote monitoring for thousands of German wind turbines
- Financial impact: No financial figure is established by the reviewed source evidence
- Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.
What happened
In Feb 2022, Viasat experienced an incident in its satellite/telecom environment. The retained source describes the attack path as follows: Russian state-linked; AcidRain wiper, timed with the invasion of Ukraine. [1]
The documented consequence was: Bricked tens of thousands of modems across Europe; disrupted Ukrainian military comms and remote monitoring for thousands of German wind turbines. [1]
Impact
- Documented impact: Bricked tens of thousands of modems across Europe; disrupted Ukrainian military comms and remote monitoring for thousands of German wind turbines. [1]
- No financial loss, ransom amount, recovery cost, or regulatory penalty is established by the reviewed source evidence.
Threat Group & Attack Vector
The retained source describes the attack path as follows: Russian state-linked; AcidRain wiper, timed with the invasion of Ukraine. The canonical record does not add intrusion steps beyond those supported by the source. [1]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- T1561 — Disk Wipe — mapped from the cited behavior. [1]
Response
The retained source describes system restoration or operational recovery work. [1]
This account is bounded to NCSC Annual Review 2023. Details absent from that evidence are left unresolved rather than inferred. [1]
