Back to news

Salt Typhoon Reached Viasat Through the Ground Segment

Share:
Salt Typhoon Reached Viasat Through the Ground Segment

Viasat, the California-based satellite communications company, was breached by the Chinese state-sponsored group Salt Typhoon in an intrusion the company discovered in early 2025 and that became public that June. The compromise involved unauthorized access through a device on its network, as BleepingComputer reported from Bloomberg's account, and Viasat said an investigation with federal authorities found no evidence customers were affected. The detail that matters for satellite operators is where the access sat: in the ground network that controls the spacecraft, reached through the same kind of remote-management link every operator depends on.

The route in was the ground segment

New Jersey's state cybersecurity cell, the NJCCIC, characterized the Viasat compromise as abuse of remote-management links tied to the company's ground infrastructure. No outage followed and no satellite was commanded. The significance, in the cell's assessment, was that the access reached far enough that satellite telemetry and control data were within range. Ground segments carry that exposure by design. Operators run satellites remotely over continuous links, often through distributed stations and outside contractors, which leaves a standing set of internet-facing entry points that a spacecraft in orbit does not have. The same class of exposure runs through the wider campaign. Salt Typhoon's way into telecom networks repeatedly ran through unpatched edge devices and remote-access appliances, the points where a network meets the internet, which is largely what a satellite ground station is built from.

Espionage this time

The Viasat intrusion was one node in a much larger Salt Typhoon campaign. The same group had already worked its way into AT&T, Verizon, Lumen and other carriers, and in some cases into the lawful-intercept systems US authorities use for court-ordered wiretaps, exposing call metadata for people in and around Washington during the 2024 election cycle. In September 2025 the US Treasury sanctioned Sichuan Juxinhe Network Technology, a Chinese firm it tied to the group, in an action that linked Salt Typhoon to the Ministry of State Security. The pattern reads as collection rather than sabotage. No wiper ran on Viasat's network, and the company says the incident was remediated with no recent activity.

The doctrine that makes the foothold dangerous

A second Chinese group operates on a different mission. In a February 2024 joint advisory, CISA, the NSA and the FBI assessed with high confidence that the group tracked as Volt Typhoon was pre-positioning inside US critical-infrastructure networks to enable disruptive or destructive attacks during a future crisis or conflict, behavior the agencies said was not consistent with espionage. Volt Typhoon leans on living-off-the-land techniques that abuse legitimate system tools, and it has held access in some victim networks for more than five years. Communications is among the sectors the advisory names, and a satellite operator's ground segment is communications critical infrastructure. The quiet, persistent access Salt Typhoon demonstrated at Viasat is the kind of foothold that doctrine is built to acquire. Viasat has now been on the receiving end of both models. Russian wiper malware called AcidRain knocked out its KA-SAT modems across Europe about an hour before the 2022 invasion of Ukraine, taking roughly 5,800 German wind turbines offline, and Salt Typhoon's operators came in three years later through the ground network.

What the allied agencies told operators to do

The official response has been guidance aimed at the ground segment. On March 24, 2026, the NSA and the Australian Signals Directorate's Australian Cyber Security Centre, working with the Australian Space Agency, Canada's Cyber Centre and New Zealand's NCSC, published a cybersecurity information sheet titled "Securing Space: Cyber Security for Low Earth Orbit Satellite Communications." It runs across the space, ground and user segments and the supply chain behind them, and its ground-segment measures are ordinary enterprise hygiene applied to an under-hardened environment: continuous monitoring, phishing-resistant multi-factor authentication and endpoint protection, plus controls on suppliers. Breaking Defense noted that the document named no specific incident. It also hands buyers a set of security questions to put to a SATCOM provider before signing, among them how the provider secures the remote-management paths into its ground stations.

The Viasat breach was first reported by Bloomberg; the LEO SATCOM guidance was published by the NSA and ASD's ACSC.