{
  "type": "bundle",
  "id": "bundle--55d76429-7af5-53d5-8ada-ebbf0431fd43",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--31cd9eb3-47f5-5c0f-8922-a6a5cfb8a315",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:5a90df16-f731-5358-a023-aa80662e934f",
      "name": "Viasat",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--5b2789d6-9ec1-5c41-8d44-92f00c0c3b28",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:034342f1-3cf0-58a7-921e-326bc77f06ac",
      "name": "Viasat KA-SAT network disruption"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--acbf7b7e-4874-53fa-86ec-65bc193653d4",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:417f59b3-089d-5f90-8e3a-4858d209cb8b",
      "name": "Viasat KA-SAT network disruption"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1531c03a-c2e2-5c8b-872b-d6f293cd95a9",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:ca5e341d-68cb-5207-9e64-62c249608a69",
      "relationship_type": "affected-organization",
      "source_ref": "incident--5b2789d6-9ec1-5c41-8d44-92f00c0c3b28",
      "target_ref": "identity--31cd9eb3-47f5-5c0f-8922-a6a5cfb8a315",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "UK National Cyber Security Centre",
          "url": "https://www.ncsc.gov.uk/files/Annual_Review_2023.pdf",
          "external_id": "cit:e734b262-0383-51ea-966b-4acf4bbb810e",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:be3e3bfa4755fa4c8d85744ce2f38263d1389b503c543c3cbc96f0840d6f85cc"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--0ca024b8-ddb0-5f60-815f-e19292d0bee6",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:3ecd7589-6c7d-566b-bc14-07601c074b13",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "UK National Cyber Security Centre",
          "url": "https://www.ncsc.gov.uk/files/Annual_Review_2023.pdf",
          "external_id": "cit:490c5f23-f5c1-5ef2-9e7f-4317f90378b5",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:be3e3bfa4755fa4c8d85744ce2f38263d1389b503c543c3cbc96f0840d6f85cc"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the viasat ka-sat network disruption involving Viasat."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--497df4f0-9f99-52d8-8d18-97793c876927",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:47ab9860-b583-5f8e-8a2d-e37d3eca2d6b",
      "confidence": 84,
      "external_references": [
        {
          "source_name": "UK National Cyber Security Centre",
          "url": "https://www.ncsc.gov.uk/files/Annual_Review_2023.pdf",
          "external_id": "cit:8b0dddb0-c51b-55b0-a688-49f585991a9f",
          "description": "Security Service of Ukraine and Five These incidents are part of a wider Eyes partners, we publicly revealed that pattern of cyber intrusions by the SVR who Russian military intelligence service have previously attempted to gain access (GRU) capabilities are targeting Ukrainian to governments across Europe and NATO battlefield information, in this case from members and who continue to exploit Android devices. vulnerabilities to this day.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:be3e3bfa4755fa4c8d85744ce2f38263d1389b503c543c3cbc96f0840d6f85cc"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Bricked tens of thousands of modems across Europe; disrupted Ukrainian military comms and remote monitoring for thousands of German wind turbines."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--5f97fff0-3f49-5c7b-8766-a472861f1bba",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:e388a5ab-017c-520b-b601-db165945c717",
      "confidence": 90,
      "external_references": [],
      "x_ally_claim_object": {
        "kind": "iri",
        "value": "https://attack.mitre.org/techniques/T1561/"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--623eca01-c5dc-5c8a-8dee-5ba01b674fbb",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:ae780bd0-5ffc-5fa0-8989-6a736a3d03d5",
      "confidence": 88,
      "external_references": [
        {
          "source_name": "UK National Cyber Security Centre",
          "url": "https://www.ncsc.gov.uk/files/Annual_Review_2023.pdf",
          "external_id": "cit:5bd3a2fa-84c0-50bd-bd4b-cecc0d83a047",
          "description": "Cyber espionage continues to be used The point here is to not assume you are as an important tactical weapon, not important enough for Russian spies strategically and operationally, in to take an interest, if it furthers their aims supporting Russian political and and objectives. economic objectives in Ukraine and An initial interaction with an individual or around the world. organisation (in the form of an unsolicited Since Russia’s further invasion of Ukraine, approach on LinkedIn or an email with a their cyber operations have expanded malicious link) is all it could take to allow to include anything or anyone with a hostile actors into your networks and connection to Ukraine which seeks to find the information they want to use for gain an information advantage on the their advantage. battlefield and geopolitically.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:be3e3bfa4755fa4c8d85744ce2f38263d1389b503c543c3cbc96f0840d6f85cc"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Russian state-linked; AcidRain wiper, timed with the invasion of Ukraine."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--cdedafe2-0b16-5552-8984-a543b36510ff",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:6d3e3194-9c02-5703-bee0-3dd11e94496f",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "UK National Cyber Security Centre",
          "url": "https://www.ncsc.gov.uk/files/Annual_Review_2023.pdf",
          "external_id": "cit:846b0162-e387-5581-ab40-419d2a1ee791",
          "description": "Effective recovering from historic and plausible regulation plays a key role so the future attacks.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:be3e3bfa4755fa4c8d85744ce2f38263d1389b503c543c3cbc96f0840d6f85cc"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source describes system restoration or operational recovery work."
      }
    }
  ]
}
