Satellite communications provider Viasat has confirmed it was breached by China’s Salt Typhoon cyber-espionage group, joining a growing list of telecommunications companies targeted by the state-sponsored hackers.
## The Viasat Breach
Viasat, which provides satellite broadband services to governments, military, aviation, energy, and maritime customers worldwide, discovered the breach earlier this year. The company serves approximately 189,000 broadband subscribers in the United States.
“Viasat and its independent third-party cybersecurity partner investigated a report of unauthorized access through a compromised device,” the company stated. “Upon completing a thorough investigation, no evidence was found to suggest any impact to customers.”
The company worked with federal authorities during the investigation and believes the incident has been resolved, with no recent malicious activity detected.
## Previous Security Incidents
This isn’t Viasat’s first major cyber incident. In February 2022, Russian hackers targeted the company’s KA-SAT satellite service just one hour before Russia’s invasion of Ukraine. The attack used AcidRain malware to wipe satellite modems, affecting tens of thousands of customers across Ukraine and Europe, including systems controlling 5,800 wind turbines in Germany.
## Salt Typhoon’s Widespread Campaign
The FBI and CISA confirmed in October that Salt Typhoon has compromised multiple major U.S. telecommunications providers, including:
– AT&T
– Verizon
– Lumen
– Charter Communications
– Consolidated Communications
– Windstream
The group has also targeted telecom companies in dozens of countries worldwide. During these breaches, the hackers gained access to U.S. law enforcement wiretapping platforms and intercepted private communications of government officials.
Recent reports suggest Comcast and Digital Realty may also be compromised in these attacks.
## Ongoing Threat
Salt Typhoon has been active since at least 2019, continuously targeting government organizations and telecommunications companies. The group remained active through December 2024 and January 2025, exploiting unpatched Cisco IOS XE network devices to breach additional telecommunications providers globally.
The persistent nature of these attacks highlights the critical need for robust cybersecurity measures and regular security updates across telecommunications infrastructure.
