Satellite tv for pc communications firm Viasat is the newest sufferer of China’s Salt Hurricane cyber-espionage group, which has beforehand hacked into the networks of a number of different telecom suppliers in the US and worldwide.
Viasat gives satellite tv for pc broadband companies to governments worldwide and aviation, army, power, maritime, and enterprise clients. Final month, the telecom big informed shareholders that it had roughly 189,000 broadband subscribers in the US.
The corporate found the Salt Hurricane breach earlier this 12 months and has been working with federal authorities to research the assault, as Bloomberg first reported.
“Viasat and its impartial third-party cybersecurity associate investigated a report of unauthorized entry by a compromised system. Upon finishing an intensive investigation, no proof was discovered to recommend any affect to clients,” Viasat informed BleepingComputer.
“Viasat engaged with authorities companions as a part of its investigation. Because of the delicate nature of data sharing with authorities companions, we’re unable to offer additional particulars. Viasat believes that the incident has been remediated and has not detected any current exercise associated to this occasion.”
BleepingComputer first contacted Viasat in February with questions relating to a possible breach, however acquired no reply on the time.
Russian hackers additionally breached Viasat’s KA-SAT consumer-oriented satellite tv for pc broadband service in February 2022, wiping satellite tv for pc modems utilizing AcidRain information wiper malware roughly one hour earlier than Russia invaded Ukraine.
The 2022 cyberattack impacted tens of hundreds of broadband clients in Ukraine and Europe, together with modems controlling roughly 5,800 wind generators in Germany.
Salt Hurricane telecom breaches
Because the FBI and CISA confirmed in October, the Chinese language Salt Hurricane state hackers had breached a number of telecom suppliers (together with AT&T, Verizon, Lumen, Constitution Communications, Consolidated Communications, and Windstream) and different telecom firms in dozens of nations.
Whereas inside U.S. telecom networks, the attackers additionally accessed the U.S. legislation enforcement’s wiretapping platform and gained entry to the “non-public communications” of a “restricted quantity” of U.S. authorities officers.
Earlier this month, NSA and CISA officers additionally tagged Comcast and Digital Realty as doubtlessly compromised in Salt Hurricane’s telecom assaults.
Salt Hurricane has been breaching authorities organizations and telecom firms since a minimum of 2019 and stored actively concentrating on telecoms between December 2024 and January 2025, breaching extra telecommunications suppliers worldwide through unpatched Cisco IOS XE community gadgets.