Reporting places satellite communications provider Viasat among the organisations reached by the campaign, with internal systems compromised through abuse of remote management links associated with its ground infrastructure.
Nobody Attacks A Satellite
The orbital segment is genuinely hard to reach: physically inaccessible, running constrained purpose-built software, communicating over links that require specialised equipment to transmit on.
The ground segment is a data centre. It runs commodity operating systems, is administered remotely, and is connected to a corporate network so that people can do their jobs. Every practical route to a satellite constellation runs through a building.
This is the IT-and-OT boundary from 25-0505 and 26-0729 in its most extreme form: the operational asset is in orbit, and the thing that controls it is an ordinary enterprise estate.
Remote Management Is The Recurring Route
Remote management links exist because ground stations are unstaffed, geographically dispersed and expensive to visit. The economics that justify them also make them the most attractive single target in the architecture.
The same object appears throughout this corpus under different names — a support portal at 25-0105, a backup service at 25-0917, an integration at 25-0818. Each is the mechanism by which a small team operates a large estate, and each is therefore where the reach concentrates.
Why Satellite Operators Are On The Target List
Satellite communications serve maritime, aviation, remote industrial and military users — precisely the traffic that does not traverse terrestrial networks and would therefore not be visible through the carrier access described at 25-0304.
Graded medium: the compromise is reported consistently, but the extent of access, whether customer traffic was reachable, and whether any orbital asset was affected are not established, and we do not assert them.
Compiled from public reporting, listed below. No effect on orbital assets or customer communications has been established and none is asserted. Corrections: corrections@forensicpost.com.