CISA and the FBI said today that they are aware of “potential threats” to satellite communications (SATCOM) networks in the US and globally.
See also: FBI Warning: MFA Flaw Exploited by Government Hackers

In a statement, they also warned US critical infrastructure agencies of risks to SATCOM providers' customers following network breaches
"Successful intrusions into SATCOM networks could create risk to the customer environments of SATCOM network providers," CISA and the FBI said.
«CISA and the FBI encourage critical infrastructure organizations and other organizations that are either SATCOM network providers or customers to review and implement the mitigations outlined in this CSA to enhance SATCOM network cybersecurity.»
While the two federal agencies advised SATCOM network providers to add additional ingress and egress monitoring to detect any suspicious traffic, they also shared common mitigation actions that should be implemented by both customers and providers.
See also: CISA and FBI: Data wiping attacks will also appear outside Ukraine

These include:
- Using secure methods for authentication, including multi-factor authentication where possible
- Enforcing the principle of least privilege through authorization policies
- Audit trust relationships with IT service providers to remove potential attack vectors
- Implement encryption on all communication links leased or provided by the SATCOM provider
- Ensuring strong system patch and configuration controls
- Monitor logs for suspicious activity
- Confirm that incident response, resilience and business continuity plans are in place
See also: FBI on BEC attacks: Fraudsters impersonate CEOs in virtual meetings
The warning comes after the KA-SAT network of US satellite communications provider Viasatwas affected by a cyberattack that led to disruptions of satellite services in Central and Eastern Europe.
The outage also disconnected around 5,800 wind turbines in Germany and affected customers from Germany, France, Italy, Hungary, Greece and Poland.
