Incident: Satellite Internet Hack Targeting Viasat During Ukraine War

Published Date: 2022-05-10

Postmortem Analysis
Timeline 1. The software failure incident targeting American commercial satellite internet company Viasat, which caused outages for several thousand Ukrainian customers and affected windfarms and internet users in Central Europe, began about an hour before Russia invaded Ukraine on 24 February [127748].
System 1. Viasat's KA-SAT network [127748]
Responsible Organization 1. Russia - as per UK and US intelligence reports [127748]
Impacted Organization 1. Ukrainian customers, windfarms, and internet users in Central Europe were impacted by the software failure incident [127748].
Software Causes 1. Hack by Russia targeting American commercial satellite internet company Viasat, causing outages for several thousand Ukrainian customers and affecting windfarms and internet users in Central Europe [127748].
Non-software Causes 1. The cyber-attack targeting Viasat was attributed to Russia, indicating a geopolitical motive behind the incident [127748]. 2. The attack was specifically aimed at the Ukrainian military, highlighting a strategic military objective [127748]. 3. The attack caused outages for several thousand Ukrainian customers, impacting not just military operations but also civilian internet users and windfarms in Central Europe [127748].
Impacts 1. The cyber-attack on American commercial satellite internet company Viasat caused outages for several thousand Ukrainian customers and affected windfarms and internet users in Central Europe [127748]. 2. "Tens of thousands of terminals" were damaged beyond repair in the cyber-attack, although the core network infrastructure and the satellite itself remained unscathed [127748]. 3. The attack was primarily targeted at the Ukrainian military, as confirmed by a joint announcement by the EU, UK, US, and other allies [127748]. 4. The attack on satellite communications directly supported military operations and spilled over to other countries [127748]. 5. The attack had significant consequences on ordinary people and businesses in Ukraine and across Europe, as stated by Foreign Secretary Liz Truss [127748].
Preventions 1. Implementation of robust cybersecurity measures such as regular security audits, penetration testing, and network monitoring to detect and prevent potential cyber-attacks [127748]. 2. Enhanced employee training on cybersecurity best practices to prevent social engineering attacks and unauthorized access to critical systems [127748]. 3. Collaboration with government agencies and international partners to share threat intelligence and coordinate responses to cyber threats [127748].
Fixes 1. Enhancing cybersecurity measures and protocols to prevent future cyber-attacks like the one targeting Viasat's satellite internet network [127748].
References 1. UK and US intelligence [Article 127748] 2. EU, UK, US, and other allies [Article 127748] 3. UK's National Cyber Security Centre (NCSC) [Article 127748] 4. Viasat [Article 127748] 5. Paul Chichester, operations director at NCSC [Article 127748] 6. US Cybersecurity and Infrastructure Security Agency [Article 127748] 7. Foreign Secretary Liz Truss [Article 127748]

Software Taxonomy of Faults

Category Option Rationale
Recurring unknown The articles do not provide information about the software failure incident happening again at either the same organization (one_organization) or at multiple organizations (multiple_organization).
Phase (Design/Operation) design, operation (a) The software failure incident related to the design phase is evident in the cyber-attack targeting American commercial satellite internet company Viasat. The attack, attributed to Russia, caused outages for several thousand Ukrainian customers and affected windfarms and internet users in Central Europe. The attack damaged "tens of thousands of terminals" beyond repair, highlighting a failure due to contributing factors introduced during system development or updates [127748]. (b) The software failure incident related to the operation phase is seen in the cyber-attack on the KA-SAT network, which is operated by Viasat. The attack, attributed to Russia, disrupted the operations of the network, causing outages for several thousand Ukrainian customers and affecting windfarms and internet users in Central Europe. This failure can be attributed to contributing factors introduced by the operation or misuse of the system [127748].
Boundary (Internal/External) within_system, outside_system (a) within_system: The software failure incident reported in the articles is primarily attributed to a cyber-attack targeting the American commercial satellite internet company Viasat. The attack, believed to be orchestrated by Russia, caused outages for several thousand Ukrainian customers and affected windfarms and internet users in Central Europe. Viasat stated that "tens of thousands of terminals" were damaged beyond repair in the cyber-attack, indicating a significant impact on the company's internal systems [127748]. (b) outside_system: The external factor contributing to the software failure incident was the cyber-attack initiated by Russia. The attack, which occurred just before Russia invaded Ukraine, targeted Viasat's satellite internet services, impacting not only Ukrainian customers but also users in Central Europe. The attack was part of a broader offensive cyber-operation by Russia against Ukraine, demonstrating the external threat posed by malicious actors to the company's systems [127748].
Nature (Human/Non-human) non-human_actions (a) The software failure incident in the article was attributed to non-human actions, specifically a cyber-attack targeting American commercial satellite internet company Viasat. UK and US intelligence suggest that Russia was behind the attack, which caused outages for several thousand Ukrainian customers and affected windfarms and internet users in Central Europe [127748]. The attack was described as a significant and destructive operation that demonstrated Russia's abilities in cyber warfare. It was noted that the attack on satellite communications was directly in support of military operations and spilled over to other countries, indicating a non-human origin of the failure incident.
Dimension (Hardware/Software) hardware, software (a) The software failure incident related to hardware: - The cyber-attack targeting American commercial satellite internet company Viasat caused outages for several thousand Ukrainian customers and affected windfarms and internet users in Central Europe [127748]. - Viasat mentioned that "tens of thousands of terminals" were damaged beyond repair in the cyber-attack, indicating hardware damage [127748]. (b) The software failure incident related to software: - The cyber-attack on Viasat's network was attributed to Russia by the UK's National Cyber Security Centre (NCSC) [127748]. - The attack involved the deployment of destructive malware called Whispergate in an effort to destroy computer systems and render them inoperable [127748]. - The software failure incident was part of a significant and destructive operation that showcased Russia's cyber capabilities [127748].
Objective (Malicious/Non-malicious) malicious (a) The software failure incident related to the cyber-attack on American commercial satellite internet company Viasat was malicious in nature. UK and US intelligence suggest that Russia was behind the cyber-attack targeting Viasat, with the primary target being the Ukrainian military [127748]. The attack caused outages for several thousand Ukrainian customers, affected windfarms and internet users in Central Europe, and damaged tens of thousands of terminals beyond repair. The attack was described as a deliberate and malicious act by Russia against Ukraine, with significant consequences on ordinary people and businesses in Ukraine and across Europe [127748].
Intent (Poor/Accidental Decisions) unknown (a) The intent of the software failure incident: The software failure incident, which was a cyber-attack targeting American commercial satellite internet company Viasat, was attributed to deliberate and malicious actions by Russia against Ukraine. The attack was specifically aimed at the Ukrainian military, causing outages for several thousand Ukrainian customers and affecting windfarms and internet users in Central Europe [127748]. (b) The intent of the software failure incident: The incident was not attributed to accidental decisions or mistakes but rather to a deliberate and malicious attack orchestrated by Russia against Ukraine. The attack was part of a broader offensive cyber-operation by Russia in support of its military operations in Ukraine [127748].
Capability (Incompetence/Accidental) accidental (a) The software failure incident related to the satellite internet hack at Viasat was not attributed to development incompetence. Instead, it was a deliberate and malicious cyber-attack orchestrated by Russia against Ukraine, causing outages for several thousand Ukrainian customers and affecting windfarms and internet users in Central Europe [127748]. (b) The software failure incident at Viasat was accidental. It was a cyber-attack initiated by Russia targeting the Ukrainian military, which also affected other countries and entities unintentionally. The attack caused damage to tens of thousands of terminals but did not harm the core network infrastructure or the satellite itself [127748].
Duration permanent, temporary (a) The software failure incident in this case can be considered permanent as the article mentions that "tens of thousands of terminals" were damaged beyond repair in the cyber-attack on Viasat's network [127748]. This indicates a lasting impact on the affected terminals, resulting in a permanent failure. (b) The software failure incident can also be seen as temporary to some extent as the core network infrastructure and the satellite itself of Viasat remained unscathed despite the cyber-attack [127748]. This suggests that while there were temporary outages and damage to terminals, the overall infrastructure was not permanently affected.
Behaviour crash, other (a) crash: The software failure incident in this case can be categorized as a crash. The incident involved a cyber-attack targeting American commercial satellite internet company Viasat, causing outages for several thousand Ukrainian customers and affecting windfarms and internet users in Central Europe. The attack resulted in "tens of thousands of terminals" being damaged beyond repair, although the core network infrastructure and the satellite itself remained unscathed [127748]. (b) omission: There is no specific mention of the software failure incident being related to omission in the provided article. (c) timing: The timing of the software failure incident is significant as it began about an hour before Russia invaded Ukraine on 24 February. This indicates a deliberate timing of the cyber-attack to coincide with the military actions [127748]. (d) value: The software failure incident does not seem to be related to the system performing its intended functions incorrectly. (e) byzantine: The software failure incident does not exhibit characteristics of a byzantine failure where the system behaves erroneously with inconsistent responses and interactions. (f) other: The behavior of the software failure incident in this case can be described as a targeted and deliberate attack on the satellite communications network, primarily aimed at the Ukrainian military but with broader implications for other users and infrastructure. The attack was part of a larger offensive cyber-operation by Russia in the context of the war in Ukraine [127748].

IoT System Layer

Layer Option Rationale
Perception None None
Communication None None
Application None None

Other Details

Category Option Rationale
Consequence unknown (a) death: People lost their lives due to the software failure - There is no mention of people losing their lives due to the software failure incident reported in the articles [127748].
Domain information, government, other The failed system in the reported software failure incident was intended to support the following industries: (a) information: The failed system was related to a cyber-attack targeting American commercial satellite internet company Viasat, which provides high-speed satellite broadband to commercial and military customers, causing outages for several thousand Ukrainian customers and affecting windfarms and internet users in Central Europe [127748]. (l) government: The primary target of the cyber-attack was identified as the Ukrainian military, indicating that the system failure incident had implications for the government sector [127748]. (m) other: The incident also had implications beyond the information and government sectors, affecting windfarms and internet users in Central Europe, which could potentially fall under the utilities sector due to the impact on services like power and internet connectivity [127748].

Sources

Back to List