Cybersecurity in Telecommunications: A CISO's Guide to New Threats
Telecommunications networks face threats that most security programs were not built for: signaling protocol abuse, SIM swap fraud, and subscriber data traded underground. This guide sets out how CISOs approach cybersecurity in telecommunications, from the protocols adversaries exploit to the controls that limit damage when a provider is hit.
Published September 4, 2026

Telecommunications networks sit quietly behind almost everything you do each day. They support everyday communication as well as the services entire industries depend on, often without being noticed.
Because of their scale and constant uptime demands, these networks come with layers of complexity and long-standing dependencies. This makes cybersecurity in telecommunications a growing concern, especially as threats become more targeted and disruptions more costly. In this blog, we cover what you need to know about telecommunications security, the most common risks, and the key questions people still have.
» Skip to the solution: Try KELA's cyber threat intelligence for free
The Systems Holding Modern Communication Together
It acts as the central nervous system of modern society, facilitating everything from simple voice calls and text messages to high-speed internet, financial transactions, and the operation of critical public services.
Why Telecommunications is a Premier Target
Telecommunications providers are uniquely positioned at the intersection of critical infrastructure and massive data collection, making them "crown jewel" targets for both cybercriminals and nation-state actors.
- Role as critical infrastructure: Because these networks underpin financial systems, emergency services, and power grids, a successful disruption can destabilize an entire nation's economy or security.
- High-value data repositories: Telco companies manage vast amounts of PII (Personally Identifiable Information), including location data and financial records, which serve as a goldmine for identity theft and dark web sales.
- Centralized point of interception: By compromising a single provider, an adversary can gain access to the communications of millions of individuals and thousands of corporate entities simultaneously.
- Complex attack surface: The integration of legacy systems (like 2G/3G) with modern IoT and 5G infrastructure creates numerous "blind spots" that are difficult to patch or monitor effectively.
- Gateway to other sectors: Attackers often use telecom networks as a stepping stone to breach other highly regulated industries through intercepted multi-factor authentication (MFA) or session hijacking.
» Discover how implementing Identity Guard strategies can immediately reduce risk and secure your digital identities
How Adversaries Exploit the Network
Adversaries do not just target the perimeter; they exploit the fundamental protocols that allow different global networks to "talk" to one another.
- Protocol manipulation (SS7 & Diameter): Attackers exploit the inherent trust in legacy protocols like SS7 to send fraudulent signaling messages that can track user locations or intercept SMS-based 2FA codes.
- Subscriber identity exploitation: By targeting large-scale customer repositories and SIM-based authentication, criminals perform SIM-swapping to take over bank accounts and digital identities.
- 5G downgrade attacks: Threat actors can force modern 5G devices to "downgrade" to less secure 4G or 3G connections, allowing them to use older, well-documented exploits that 5G was designed to prevent.
- SIP and voice fraud: Adversaries manipulate Session Initiation Protocol (SIP) to conduct unauthorized long-distance calling or "vishing" (voice phishing) campaigns at scale.
» Make sure you know the difference between a vulnerability, a threat, and a risk
The CISO Roadmap: Preparing for Next-Generation Threats
CISOs must prepare for new attack techniques targeting the expanded attack surface of next-generation telecom infrastructure. This includes:
- Abuse of IoT devices: The massive number of interconnected IoT devices provides a large, often poorly secured, entry point. Attackers can create massive botnets to launch distributed denial of service (DDoS) attacks or use compromised devices to move laterally within the network.
- Satellite interception: With the rise of Low Earth Orbit (LEO) satellite constellations, new vulnerabilities are emerging in Non-Terrestrial Networks (NTNs). Adversaries could intercept satellite communications or disrupt critical services.
- Targeting edge computing nodes: The move to edge computing, which processes data closer to the source, expands the attack surface. Edge nodes can be targeted to manipulate data, inject malicious code, or launch attacks that disrupt a wide range of connected services.
» Read more: The CISO's guide to proactive cybersecurity
Strategies for Building Stronger Cybersecurity in Telecommunications
The telecom sector is facing an unprecedented surge in sophisticated attacks. To stay ahead, CISOs must shift from reactive "firefighting" to a model of continuous, automated intelligence.
Neutralizing the Underground Credential Market
Telecom operators must treat employee and contractor credentials as high-risk assets.
Credential theft remains a core exposure for telecom operators, though it no longer leads the table. The 2026 Verizon Data Breach Investigations Report, covering incidents from November 2024 through October 2025, found vulnerability exploitation behind 31% of breaches against 13% for credential abuse: the first time in the report’s 19-year history that stolen credentials have not been the top initial access vector. Separately, IBM’s Cost of a Data Breach Report 2025 puts the global average breach cost at $4.44 million.
To combat this, dark web monitoring tools should be integrated directly into Identity and Access Management (IAM) workflows. Instead of security teams manually reviewing alerts, integration allows for:
- Automated risk-based access: If KELA surfaces a supplier’s email address in a credential list circulating on Telegram or an underground forum, the incident can be pushed straight into your security stack by webhook, where it can drive a password reset or a step-up authentication challenge before the credential is tested.
- Early warning via infostealer intelligence: Since many credentials are harvested by infostealer malware on unmanaged devices, monitoring "logs" for sale allows CISOs to invalidate session tokens before an attacker even attempts a login.
- Proactive account freezing: For high-privileged accounts, real-time alerts can temporarily suspend access until the user verifies their identity through a secondary, out-of-band channel.
» Learn how to reduce damage from info-stealing malware
Defending Subscriber Data from Illicit Trade
Protecting customer PII is a critical mandate: personally identifiable information was compromised in 53% of the breaches studied in IBM’s Cost of a Data Breach Report 2025, the most frequently exposed data category in the report. When subscriber data is exposed at scale, the response window is short.Orange Belgium disclosed on August 20, 2025 that a cyberattack detected at the end of July had given an intruder access to data from 850,000 customer accounts, including surname, first name, telephone number, SIM card number, PUK code and tariff plan, though no passwords, email addresses, bank or financial details. Those middle fields are why an exposure like this matters beyond the operator: SIM card numbers and PUK codes are the material that makes SIM swap fraud easier.
- Prevention measures: CISOs should implement Zero Trust Architecture that assumes the network is already compromised. By encrypting data at rest and in transit and using micro-segmentation, operators ensure that a breach in one department doesn't lead to a total database dump.
- Response protocols: When a leak surfaces, containment speed drives cost more than almost any other factor. IBM’s Cost of a Data Breach Report 2025 found that breaches with a lifecycle over 200 days cost $1.14 million more than those resolved inside 200 days, against a global average lifecycle of 241 days.
- Automated brand monitoring: Tools like KELA provide "Human Intelligence" (HUMINT) from closed forums, allowing telcos to identify if a specific database is being advertised before it is widely distributed. This enables the operator to notify regulators and affected customers proactively, fulfilling GDPR and CCPA legal requirements while minimizing reputational fallout.
» Learn more: Darknet markets explained
Securing the Vendor and Supply Chain Ecosystem
A single point of failure in a hardware provider or a SaaS platform can cascade across the entire network. In August 2025, attackers stole OAuth tokens belonging to the Salesloft Drift chatbot integration and used them to reach Salesforce data at more than 700 organizations, without exploiting a Salesforce vulnerability or a single user password.
- Vendor Risk Management (VRM): CISOs must move beyond "point-in-time" questionnaires. Modern VRM requires continuous security ratings and mandatory third-party audits for any vendor with access to the core network or subscriber data.
- Threat intelligence as a filter: Ongoing intelligence helps uncover "Island Hopping," where attackers breach a smaller, less-secure vendor to gain access to the major telecom provider. Monitoring underground sources for mentions of vendor domains can surface exposure before the vendor discloses it, which is often the only warning a downstream operator gets.
- Regulatory compliance: Under modern regulations, telcos are often held legally responsible for their vendors' failures. Proactive monitoring isn't just a technical strategy; it’s a necessary legal defense to avoid massive fines and litigation costs.
» Learn how supply chain threat intelligence strengthens your security posture
Mitigating Insider Risks (Negligent and Malicious)
SOC teams must be equipped to handle threats coming from within the organization. Insider risk detection increasingly depends on identity and behavioral signals rather than perimeter controls, because the activity in question is authorized by definition.
- Behavioral intelligence (UEBA): By using machine learning to establish a "normal" baseline for every user, UEBA can detect "low and slow" data exfiltration or credential misuse that traditional systems miss.
- Layered monitoring (UAM & DLP): For unintentional risks, Data Loss Prevention (DLP) tools serve as a safety net, flagging or blocking sensitive data before it accidentally leaves the company network.
- Privileged Access Management (PAM): Restricting "keys to the kingdom" through Just-In-Time access ensures that even if an insider is compromised, their reach is limited.
Hardening Against Ransomware and Outages
Telecom providers must harden their infrastructure against groups seeking to cause mass outages. With ransomware attacks on critical infrastructure rising, the focus is now on resilience and rapid recovery.
- Micro-segmentation: By isolating the 5G core from general corporate IT, operators prevent ransomware from moving laterally across the entire network.
- Immutable backups: Maintaining un-erasable, off-site backups is the only guarantee of a clean restore point if core systems are encrypted.
» Not convinced? Here are the reasons you need cyber threat intelligence
Securing the Future of Connectivity with KELA Cyber
The scale of modern telecommunications demands a shift from reactive defense to proactive, intelligence-led security. KELA Cyber provides the critical visibility needed to monitor the hidden corners of the dark web where adversaries coordinate attacks on your network. By integrating our real-time intelligence into your existing SOC and IAM workflows, we help you neutralize stolen credentials and identify data leaks before they escalate into costly outages.
Our platform acts as an automated extension of your team, scanning the underground for mentions of your brand, employees, and critical infrastructure. In an era where a single breach can cost millions, KELA offers the early warning system necessary to protect your subscribers and maintain national resilience.
» Ready to get started? Contact us to learn more about our cyber threat intelligence services
FAQs
What parts of a telecom network are most commonly targeted?
Identity systems, signaling protocols, legacy components, and vendor access points are frequent pressure areas.
Can attacks on telecom providers impact other sectors?
Yes. Intercepted communications and compromised access can be used to reach banks, healthcare systems, and enterprise networks.
Are there emerging threats specific to modern telecom networks?
Yes. IoT devices, 5G vulnerabilities, and satellite communication points expand the attack surface and require specialized defensive strategies.
How does telecom cybersecurity protect subscribers and critical data?
Telecom cybersecurity practices combine continuous monitoring, proactive threat intelligence, and strict access controls to prevent breaches, secure customer data, and maintain network reliability.




