Telecommunications — Cyber Threat Activity
Telecommunications carries the lowest incident count of any tier-one sector here and by some distance the highest strategic value. Our log records more than 120 incidents across 43 countries, over 50 in the trailing 180 days, with 39 groups attributed at least one claim, led by Qilin (22), Akira (15), Play (10) and DragonForce (9). That criminal volume is genuine but it is not the reason telecom matters. An operator sits on call detail records, subscriber location, message routing and lawful-intercept infrastructure, which means whoever holds the network can answer who spoke to whom, from where, and when, for an entire population. Cybereason's analysis of a multi-year campaign against operators documented exactly that objective: sustained waves of intrusion aimed at call metadata and credentials rather than at disruption or extortion, with access maintained for years. Chinese state actors have been assessed by US agencies as pre-positioning in communications infrastructure among other critical sectors, and telecom access has repeatedly proven to be the point from which surveillance of specific individuals becomes possible. Our graph reflects that asymmetry: 96 groups are associated with the sector once profile-level research is counted, against 39 attributed through measured incidents, and 165 malware families are linked through those actors. Recorded geography is United States-led at 51 claims with a long thin tail. The correct reading of this page is that a low claim count is not reassurance. Espionage against an operator succeeds by remaining invisible, produces no leak-site post, and is usually disclosed years later by a government rather than by the carrier.
- Recorded incidents: 163
- Incidents, trailing 180 days: 56
- Tracked threat actors: 97
- Malware families: 174
Recent incidents
- zayo.com 2026-08-31
- Freelom 2026-08-22
- Nteitalia 2026-08-21
- UFOC 2026-08-19
- Canal 9 Litoral 2026-07-22
- Koperasi Karyawan PT Aplikanusa Lintasarta 2026-07-21
- NewNet 2026-07-18
- Orange România SA 2026-07-17
- Westcoast Communication Services 2026-07-17
- Boston Electric and Telephone 2026-07-16
- Edison Global Networks Limited 2026-07-14
- Atcom 2026-07-14
- Retelit SpA PIVA 2026-07-11
- Telewave, Inc. 2026-07-06
- T Online 2026-07-01
- Canada Wide Media 2026-07-01
- Gsma 2026-06-29
- Sivatel Bangkok 2026-06-21
- Tri-tec 2026-06-21
- Q Link Wireless 2026-06-16
Threat actors targeting Telecommunications
- Qilin 25 incidents
- Akira 18 incidents
- DragonForce 10 incidents
- Play Ransomware 10 incidents
- INC Ransom 6 incidents
- Lynx Ransomware 6 incidents
- Cl0p 5 incidents
- ShinyHunters 5 incidents
- The Gentlemen 4 incidents
- Salt Typhoon 3 incidents
- APT73 3 incidents
- Coinbase Cartel 3 incidents
- FunkSec 3 incidents
- Handala 3 incidents
- Hunters International 3 incidents
- Deadlock 2 incidents
- Space Bears 2 incidents
- LockBit 2 incidents
- Medusa Ransomware 2 incidents
- NightSpire 2 incidents
- Nova 2 incidents
- SafePay 2 incidents
- LAPSUS$ 1 incident
- Booba Project 1 incident
Where these victims are
- United States 55
- Canada 6
- United Kingdom 6
- Germany 4
- Italy 4
- Australia 3
- Czech Republic 3
- Austria 2
- Belgium 2
- Chile 2
- Colombia 2
- France 2
Malware used against Telecommunications
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- BlackCat Malware
- Cobalt Strike Malware
- Impacket Tool
- Mimikatz Tool
- PlugX Malware
- PsExec Tool
- China Chopper Malware
- Chisel Tool
- CrackMapExec Tool
- Empire Tool
- gh0st RAT Malware
- Godzilla Malware
Coverage. 94.8% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.