The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

943 threat reports
Page 72 of 79

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Telecommunications Threat Reports

Showing 853–864 / 943 reports
NSA-Linked Cyberattack Highlights Risks to China’s National Time Service Center (2023–2024)
Impact· low

NSA-Linked Cyberattack Highlights Risks to China’s National Time Service Center (2023–2024)

Between March 2022 and June 2024, China’s National Time Service Center reportedly fell victim to a sophisticated cyber-espionage campaign allegedly orchestrated by the U.S. National Security Agency (NSA). Attackers initially compromised employee mobile devices via a text-messaging service vulnerability, leading to credential theft and enabling unauthorized access to the Center’s internal systems by April 2023. From August 2023 onward, the NSA purportedly leveraged a suite of 42 advanced cyber tools to target sensitive infrastructure, using VPNs and forged certificates to evade detection and bypass defenses. The attack put critical services at risk, with potential consequences including network disruption, financial system instability, and interruptions to vital communications and national defense functions. This incident underscores escalating nation-state cyber competition, especially over foundational infrastructure. The methods used—mobile device exploitation, lateral movement, and evasion through encrypted channels—reflect trending Tactics, Techniques, and Procedures (TTPs) in state-sponsored attacks, raising concerns for governments and critical sectors worldwide about supply chain and timing-related risks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Europol Takedown of SIMCARTEL: SIM Box Fraud Network Disrupted
Impact· high

Europol Takedown of SIMCARTEL: SIM Box Fraud Network Disrupted

In October 2024, Europol led a coordinated international operation to dismantle a sophisticated cybercrime syndicate known as "SIMCARTEL". This network, spanning Austria, Estonia, and Latvia, leveraged over 1,200 SIM box devices and 40,000 active SIM cards to conduct large-scale phishing, credential theft, and financial fraud across more than 3,200 recorded cases. Authorities linked the group to $5.8 million in financial losses, the creation of 49 million fraudulent accounts, and infrastructure facilitating criminal services in over 80 countries. The takedown resulted in seven arrests, seizure of servers, SIMs, websites, luxury vehicles, and the freezing of suspect assets. This incident highlights the growing global threat posed by SIM farms and SIM box networks, which enable scammers to evade detection, commit diverse types of fraud, and undermine trust in online communications. The rapid adoption of similar tactics worldwide puts financial institutions, telecoms, and consumers increasingly at risk.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
F5 Supply Chain Breach 2025: China-Linked Attack Exposes Global BIG-IP Risk
Impact· low

F5 Supply Chain Breach 2025: China-Linked Attack Exposes Global BIG-IP Risk

In October 2025, F5 Networks disclosed a major cybersecurity incident involving a China-linked nation-state group (UNC5291) that gained unauthorized access to its infrastructure. Attackers reportedly maintained covert access for at least a year, stealing F5 BIG-IP source code and information on as-yet-undisclosed vulnerabilities. While F5 stated there’s no evidence of active exploitation of these flaws, the breach affects more than 266,000 exposed BIG-IP instances worldwide. The attackers leveraged advanced persistence techniques and deployed specialized malware, raising serious concerns about global supply chain integrity. This breach highlights the persistent targeting of critical infrastructure vendors by highly resourced nation-state actors. Government agencies and enterprises face heightened urgency as regulatory bodies issue emergency directives to patch devices, with compliance and operational risks elevated by the scale and sophistication of the attack.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Europol Busts Massive SIM-Box Cybercrime Network in 2025
Impact· high

Europol Busts Massive SIM-Box Cybercrime Network in 2025

In October 2025, Europol led a major operation codenamed 'SIMCARTEL' that dismantled an extensive SIM-box network servicing global cybercriminals. The illicit operation spanned multiple countries, employed 1,200 SIM-box devices and 40,000 SIM cards, and provided fake phone numbers for cybercrimes such as phishing, fraud, impersonation, and extortion. Two key websites, gogetsms.com and apisim.com, were seized. Authorities arrested seven suspects, confiscated servers and luxury assets, and froze significant cryptocurrency and bank funds. Investigators linked the service to at least 3,200 fraud cases and a direct financial loss exceeding €4.5 million, with indications the service was used to create over 49 million fraudulent online accounts. This incident underscores a growing trend in Cybercrime-as-a-Service, where sophisticated tools enable large-scale identity obfuscation and fraud. The takedown reflects mounting law enforcement pressure on criminal infrastructure rentals fueling online financial crime, highlighting urgent regulatory and security challenges for organizations reliant on voice and messaging account verification.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Multi-Vendor Vulnerabilities Exploited in September 2025: Key Lessons for Zero Trust and Compliance
Impact· medium

Critical Multi-Vendor Vulnerabilities Exploited in September 2025: Key Lessons for Zero Trust and Compliance

In September 2025, a wave of critical vulnerabilities across major vendors – including Cisco, TP-Link, Sitecore, and Adminer – were actively exploited by threat actors in high-impact campaigns. Attackers leveraged CVEs such as CVE-2025-20333 and CVE-2025-20362 in Cisco ASA devices to deploy advanced malware (RayInitiator and LINE VIPER), and exploited deserialization flaws in Sitecore (CVE-2025-53690) and Adminer SSRF (CVE-2021-21311) to enable data exfiltration, lateral movement, and persistent control. The vulnerabilities affected a diverse range of enterprise products and cloud platforms, enabling remote code execution and privilege escalation via sophisticated attack chains and, in some cases, public proof-of-concept exploits. This wide-ranging exploitation underscores the growing sophistication of attacker tradecraft and the urgent need for proactive, risk-driven vulnerability management. Given the increasing regulatory and operational impact of such incidents, organizations must prioritize patching, improve detection for abuse of critical CVEs, and strengthen security posture across hybrid environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Satellite Communications Exposed: 2025’s Unencrypted Data Crisis
Impact· high

Satellite Communications Exposed: 2025’s Unencrypted Data Crisis

In mid-2025, a landmark study revealed that a vast portion of global geostationary satellite communications—including critical infrastructure, government, corporate, and consumer data—are transmitted unencrypted. Security researchers, using inexpensive commercially available satellite equipment, intercepted highly sensitive transmissions such as internal communications, private calls and SMS, and in-flight internet traffic. Because thousands of geostationary transponders broadcast across enormous geographic areas, these unprotected signals can be passively accessed by unauthorized parties from virtually anywhere within satellite coverage zones, putting confidential data at significant risk of interception and exploitation. This incident underscores a persistent and growing concern regarding the lack of robust encryption in satellite communications, even as regulations and cyber threats evolve rapidly. Increasing satellite connectivity for aviation, maritime, and remote access drives urgency around encryption, as adversaries and data brokers exploit these vulnerabilities on a global scale.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
North Korean Hackers Target Job Seekers with Advanced Malware & Blockchain C2 (2024)
Impact· high

North Korean Hackers Target Job Seekers with Advanced Malware & Blockchain C2 (2024)

In early 2024, cybersecurity researchers from Cisco Talos and Google Threat Intelligence Group uncovered a sophisticated cyber-espionage campaign led by North Korea-aligned groups, Famous Chollima and UNC5342. These actors exploited job recruitment platforms by duping job seekers into downloading malicious code, including new malware strains—namely BeaverTail, OtterCookie, JadeSnow, and InvisibleFerret—during fake interview processes. The attackers leveraged advanced techniques such as blockchain-based command and control (EtherHiding) to exfiltrate credentials, steal cryptocurrency, and deploy ransomware. Information-stealing modules captured keystrokes and screen data, highlighting the ongoing evolution of North Korea’s threat ecosystem while successfully avoiding conventional detections. This incident underscores the persistent risks posed by nation-state threat actors utilizing social engineering and innovative evasion tactics. The convergence of credential theft, ransomware delivery, data exfiltration, and resilient C2 infrastructure signals an escalation in global threat sophistication, especially targeting corporate and finance sectors.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Hackers Exploit Cisco SNMP Zero-Day to Deploy Rootkit on Switches
Impact· high

Hackers Exploit Cisco SNMP Zero-Day to Deploy Rootkit on Switches

In October 2025, threat actors exploited a zero-day vulnerability (CVE-2025-20352) in Cisco networking devices, leveraging flaws in the Simple Network Management Protocol (SNMP) to gain remote code execution on affected IOS and IOS XE switches. Trend Micro reported that attackers primarily targeted Cisco 9400, 9300, and legacy 3750G series devices, deploying rootkits on switches and unprotected Linux systems. These rootkits established a persistent backdoor, allowing attackers to control device behavior, evade logging, bypass security controls, and move laterally across VLANs. Cisco acknowledged active exploitation and classified the issue as a zero-day, urging immediate firmware and ROM analysis if compromise is suspected. The incident highlights the continued targeting of network infrastructure via legacy vulnerabilities and sophisticated rootkits, as well as the pressing need for organizations to update detection capabilities, even on older or end-of-life systems. The use of unpatched infrastructure and the absence of robust endpoint detection provided attackers with a broad attack surface, underpinning the current urgency around zero trust networking and east-west traffic monitoring.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
Inside the Largest U.S. School Data Breach: PowerSchool’s 2024 Ransomware Attack
Impact· high

Inside the Largest U.S. School Data Breach: PowerSchool’s 2024 Ransomware Attack

In September 2024, PowerSchool, a leading education software provider, suffered a devastating ransomware attack orchestrated by Matthew Lane, who used compromised contractor credentials to access and exfiltrate sensitive records. Nearly 70 million student and teacher records were stolen, with the data held hostage for a $2.9 million ransom, which was ultimately paid. The breach led to subsequent extortion attempts on multiple school districts and resulted in over $14 million of financial losses and lifetime risks of identity theft for millions of affected individuals. Lane was sentenced in October 2024 to four years in prison, three years supervised release, and over $14 million in restitution. This incident highlights the urgency of addressing third-party risks, as threat actors increasingly exploit supply chain weaknesses to orchestrate high-impact ransomware attacks. Regulatory scrutiny and ransomware activity targeting the education sector continue to rise, underscoring the need for robust zero trust, lateral movement prevention, and data protection strategies.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
F5 2025 Breach: Nation-State Attackers Target BIG-IP Source Code
Impact· high

F5 2025 Breach: Nation-State Attackers Target BIG-IP Source Code

In August 2025, cybersecurity giant F5 detected a sophisticated breach by nation-state hackers who gained unauthorized access to its BIG-IP product development environment and engineering knowledge management platforms. Over an extended period, attackers exfiltrated undisclosed BIG-IP vulnerabilities, product source code, and select customer configuration information. F5 asserts no evidence that the attackers modified software, exploited the stolen vulnerabilities in active attacks, or that critical customer data was exposed. Response actions included credential rotations, hardening of development environments, enhanced threat detection, and external code audits by firms such as CrowdStrike, Mandiant, NCC Group, and IOActive. F5 also proactively issued security updates and guidance to impacted customers. This incident underscores the growing trend of sophisticated, supply-chain-oriented intrusions targeting technology providers with a wide enterprise customer base. It illustrates the strategic value of source code and zero-day exploits to well-resourced threat actors, and raises ongoing concerns about the security of key software infrastructure used widely across industries.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Maverick: How WhatsApp Became the Gateway for Brazil’s Biggest Banking Trojan in 2024
Impact· medium

Maverick: How WhatsApp Became the Gateway for Brazil’s Biggest Banking Trojan in 2024

In October 2024, a sophisticated banking Trojan dubbed Maverick was detected actively targeting Brazilian users. The malware was delivered via malicious ZIP files sent through WhatsApp, bypassing platform detection. Victims executed an LNK file that triggered a fully fileless, multi-stage infection chain, utilizing PowerShell, .NET, and encrypted shellcode. Maverick, which shares code similarities with the Coyote Trojan, leverages locale checks to target only Brazilians and uses WPPConnect to automate the spread through hijacked WhatsApp accounts. Once established, the Trojan provides attackers full remote access, including keylogging, screen control, and phishing overlays to harvest banking and cryptocurrency credentials. This incident is notable for its complex multi-stage deployment, worm-like propagation, and use of AI-aided code, reflecting a new evolution in financially motivated malware. The attack demonstrates the increasing convergence of social engineering, sophisticated fileless techniques, and abuse of popular messaging platforms, signaling urgent challenges for both enterprises and end users.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
2025 Mysterious Elephant Attack: Asia-Pacific Government Cyber-Espionage Exposed
Impact· medium

2025 Mysterious Elephant Attack: Asia-Pacific Government Cyber-Espionage Exposed

In early 2025, the Mysterious Elephant advanced persistent threat group launched a sophisticated campaign targeting government and foreign affairs entities across Pakistan, Bangladesh, Afghanistan, Nepal, and Sri Lanka. Utilizing spear phishing emails, exploit kits, and malicious documents as entry vectors, the group deployed custom and open-source malware—such as BabShell, MemLoader HidenDesk, and ChromeStealer—to gain persistent network access, move laterally, and exfiltrate sensitive data. Their tooling leveraged advanced evasion tactics and targeted WhatsApp data for exfiltration, compromising documents, images, and browser credentials. The operation demonstrates considerable code reuse and customized tooling, posing a significant disruption to national and diplomatic processes in the region. Mysterious Elephant’s shift to tailored malware, WhatsApp-specific exfiltration, and cloud-based infrastructure highlights a broader threat landscape trend: state-sponsored actors refining tactics for targeted governmental espionage. This underscores the importance of proactive monitoring and cross-border information sharing to address escalating nation-state risks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports