In the early hours of 24 February 2022, at around 04:00 UTC, as Russian forces began their full-scale invasion of Ukraine, tens of thousands of satellite-broadband modems across Europe stopped working within minutes of each other. The network hit was KA-SAT, a geostationary satellite serving consumers, businesses and some government users across the continent, operated commercially by Viasat after its acquisition of the European operator that had run it. The timing was not a coincidence. Ukraine's military and government were among the users who relied on KA-SAT connectivity, and disabling that connectivity at the moment of invasion was plainly the point.
The attack did not target the satellite itself, which is the part most people picture when they imagine attacking space infrastructure. It targeted the ground segment and the user terminals. Attackers gained access to the management network of the KA-SAT ground system, most likely through a misconfigured VPN appliance, and from there pushed malicious commands out to the modems in customers' homes and offices. Analysts at SentinelLabs later identified and named the wiper malware AcidRain, a piece of code designed to overwrite the modems' firmware and storage so thoroughly that the devices could not simply be rebooted back to life. Many had to be physically replaced. The lesson embedded in that design choice is important. This was not a temporary jamming or a denial of service. It was destruction of the endpoint, reaching out from a compromised operations centre to brick hardware sitting in tens of thousands of separate locations.
The spillover beyond Ukraine was immediate and unintended, at least in its precise scope. Among the affected customers was the German wind-turbine manufacturer Enercon, which lost remote monitoring and control connectivity to roughly 5,800 wind turbines across central Europe. The turbines kept generating power, but the operator could no longer manage them remotely through the satellite link. Other European users, from businesses to individual subscribers, were knocked offline in France, Italy, Germany and elsewhere. An operation aimed at Ukrainian command and control had degraded civilian infrastructure across several NATO member states, because they all happened to depend on the same commercial satellite network with the same compromised ground system.
Attribution followed in May 2022, when the European Union, the United Kingdom and the United States each publicly blamed the Russian state, with the Russian military intelligence service, the GRU, identified as the actor behind the KA-SAT operation. That joint attribution was itself notable, because Western governments do not casually put their names to accusations of a specific state cyberattack on civilian infrastructure. The coordinated statement signalled that the KA-SAT hit was being treated as a serious act, and as a warning of what a satellite-broadband network looks like as a wartime target.
The episode confirmed a warning that European cybersecurity agencies had been making for years. A satellite-communications system is not just a satellite. It is a satellite plus a ground network plus a control plane plus a very large number of small, cheap, physically dispersed terminals, and the security of the whole is governed by the weakest of those parts. KA-SAT's space segment was never touched. The attackers walked in through the management network and out to the customer premises. The most exposed surface was not orbital hardware costing hundreds of millions but the software path connecting an operations centre to a modem on a wall.
The KA-SAT attack also reset expectations about the pace of such an operation. There was no siege, no gradual degradation, no window in which defenders might have noticed and intervened. The commands went out and the modems died within minutes, on the same schedule as the ground invasion, as one coordinated element of the assault. That synchronisation is itself a warning. A commercial satellite network is not a peripheral convenience that fails gracefully at the margins of a war. It can be a primary target, timed to the opening move, chosen precisely because so much depends on it and because knocking it out serves the attacker's first objectives. European operators had tended to think of their networks as commercial services with a security overlay. AcidRain showed them their networks were, in a conflict, military objectives.
For states thinking about their own resilience, the concrete takeaway is unsentimental. Relying on a single commercial satellite network for critical connectivity concentrates risk in a control plane you do not run and cannot inspect. When that network is attacked, you inherit the consequences whether or not you were the target, as Germany's wind operators discovered. Sovereignty over a communications capability is not established by signing a service contract with a well-regarded operator. It depends on who controls the ground systems, how the terminals are managed, and whether an adversary who compromises one operations centre can reach into your infrastructure at scale. KA-SAT showed that in the space of a single morning.