Viasat has shipped 30,000 replacement modems to customers throughout Europe whose internet service was permanently disabled during a single morning in February. The U.S.-based satellite network operator disclosed the extent of the damage on March 30, more than a month after the cyberattack on its KA-SAT system. The attack began on February 24, coinciding with the start of Russia’s invasion of Ukraine.
What initially appeared as a distributed denial-of-service assault originating from modems inside Ukraine quickly escalated into a destructive phase. A malicious software update was pushed across the entire network, overwriting the internal memory of modems and rendering them completely inoperable.
No reboot could restore functionality. The devices became unusable. The disruption extended far beyond Ukraine’s borders.
Broadband access for tens of thousands of ordinary residents from Poland to France was wiped out. The attack also affected critical infrastructure in central Europe, where wind turbines lost remote access capabilities.
Operators could no longer monitor or control equipment that generates power for the electrical grid. Ukrainian officials have attributed the attack to Russian hackers. Victor Zhora, Ukraine’s top cybersecurity official, told reporters in March that his country possesses “obvious evidence” linking the operation to Russia.
He stated the goal was to sever connections between customers using the satellite system. Zhora declined to identify which Ukrainian agencies beyond the military were affected, though contracts show his own agency, the State Service for Special Communications and Information Protection, relies on the KA-SAT network.
Viasat has not named a perpetrator, citing an ongoing investigation. The company has shipped replacement modems, though logistics continue to take time. The attack did not distinguish between military targets and civilian infrastructure. The KA-SAT system serves both, and the destructive update affected all connected devices.
Ukraine’s government and military lost connectivity, as did residential broadband users with no involvement in the conflict. The timing of the attack was not coincidental.
It struck in the early hours of Russia’s invasion, representing a coordinated effort to disable communications at a critical moment. This dual impact on military and civilian networks makes it the largest known cyber operation of the war so far. The incident exposed vulnerabilities inherent in satellite networks that cross national boundaries.
A modem in France is part of the same system as a modem in Kyiv. The attack demonstrated that a destructive cyber operation can be launched from inside Ukraine and spread across Europe within hours.
It also showed that civilian infrastructure is not immune from targeting. Wind turbines, broadband routers, and satellite links all proved vulnerable. The consequences continue to unfold.
The February 24 attack proved that the network used to connect people can be turned against itself with devastating speed.





























