Heimdal Security Blog

US Critical Organizations Alerted of Threats to SATCOM Networks by CISA and FBI

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) announced yesterday that they are aware of potential threats to satellite communication (SATCOM) networks in the United States and around the world.

The security advisory issued yesterday also notified US critical infrastructure entities about the risk of SATCOM providers’ customers being affected as a result of network breaches.

Successful intrusions into SATCOM networks could create risk in SATCOM network providers’ customer environments.

CISA and FBI strongly encourage critical infrastructure organizations and other organizations that are either SATCOM network providers or customers to review and implement the mitigations outlined in this CSA to strengthen SATCOM network cybersecurity.

Source

In light of the current geopolitical situation, CISA’s  Shields Up initiative requires all companies to lower their threshold for reporting and sharing signs of cybercrime.

The new warning comes after the KA-SAT network of US satellite communications provider Viasat, which is “intensely used by the Ukrainian military,” was hit by an attack. Satellite services in Central and Eastern Europe were disrupted as a result of the cyberattack.

According to BleepingComputer, the outage also disconnected roughly 5,800 wind turbines in Germany and affected customers from Germany, France, Italy, Hungary, Greece, and Poland. The outage also impacted approximately 5,800 wind turbines in Germany, as well as customers in Germany, France, Italy, Hungary, Greece, and Poland.

Mitigations for SATCOM Network Providers and Customers

Critical infrastructure organizations and other entities that are SATCOM network providers are strongly recommended by CISA and the FBI to review and apply mitigations such as putting in place additional monitoring at ingress and egress points to SATCOM equipment to look for anomalous traffic.

Also, both SATCOM Network customers and providers should:

All organizations are urged to report incidents and anomalous activity to CISA 24/7 Operations Center at report@cisa.gov or (888) 282-0870 and/or to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

If you liked this article, follow us on LinkedInTwitterFacebookYoutube, and Instagram for more cybersecurity news and topics.