New data from CYFIRMA rated telecommunications and media sector’s external cyber threat landscape as high, citing sustained activity from advanced persistent threat actors, cyber incidents, dark web activity and vulnerabilities. In a report published Aug. 23, the cybersecurity firm said telecommunications and media organizations appeared in 25 of 70 observed APT campaigns, or 36%, up from 15 of 25 campaigns in the previous period. China-linked, Russia-linked, North Korean and Iranian actors were among those observed, while Salt Typhoon and Volt Typhoon were notable for targeting telecommunications infrastructure. Routers, firewalls, VPN solutions, network monitoring tools and content delivery networks were among the technologies targeted.
CYFIRMA tracked 41 publicly reported cyber incidents involving telecommunications and media organizations during the past 90 days, ranking the sector fifth among 14 industries. Account takeover was the leading technique, appearing in nine incidents, followed by phishing in six. Customer data was the primary asset lost, with breaches involving Charter, RingCentral and Japanese providers accounting for more than 30 million records combined, according to the report.
“Leveraging the ability of our platforms to ingest and process publicly available information, we are introducing a new category of reported cyber incidents,” the report identified. “This feature is still in development, using machine learning to process publicly available information and reporting of cyber incidents to identify industry, threat actors, attack techniques, malware/tools used, and create data sets for actionable intelligence.”
For the reported cyber incidents category, hackers will be a mixed use of established names and nations, as in many cases, reports only specify the attacking country. Similarly, sometimes reports include the victims’ country; sometimes they do not. “The main data point is the number of incidents per industry; the rest of the data points are subject to highly diverse public reporting and information, therefore uneven and often lacking some of the information. Yet we still believe it is useful as another data point for each industry to see long-term trends and techniques or malware/tools used.”
CYFIRMA also identified state-linked activity, with China and Russia each associated with four incidents, while noting continued targeting of communications infrastructure through exploitation of edge devices.
The report observed APT campaigns are dominated by suspected China-linked, state-sponsored actors, with Stone Panda leading, followed closely by MISSION2074. Mustang Panda, Emissary Panda, Leviathan, Salt Typhoon, and Volt Typhoon provide additional representation, the latter two notable for their known focus on telecommunications infrastructure.
Russia-linked Gamaredon and Cozy Bear feature alongside North Korea-associated Lazarus Group and Iran-linked Fox Kitten, OilRig, and MuddyWater. Financially motivated actors TA505, FIN11, and FIN7 account for a meaningful share, alongside Turkish and Vietnamese cybercriminal groups.
The report also identified rising vulnerability and underground-market activity affecting the sector. CYFIRMA recorded 1,985 telecommunications and media-related mentions in underground and dark web channels over 90 days, placing the sector tied for second among 14 industries, with breach and leak discussions increasing sharply. It identified 396 industry-linked vulnerability mentions, ranking the sector third, with remote and arbitrary code execution vulnerabilities dominating and cross-site scripting rising steadily.
Vulnerability activity was also high, with the sector ranking third among 14 industries and accounting for 11.18% of industry-linked disclosures across 396 mentions. Remote code execution vulnerabilities tripled after the first period and remained steady, affecting routing infrastructure, subscriber management platforms and internet-facing network equipment. Cross-site scripting vulnerabilities also rose throughout the period, creating risks for subscriber portals and account management interfaces. Memory and buffer vulnerabilities affecting network firmware could extend exposure because patch cycles are often longer than those for enterprise software.
Underground and dark web chatter remained high, placing the sector second among 14 industries at 10.74% of all industry-linked activity. Breach and leak discussions rose several-fold after the first period and remained elevated, unlike the broader decline across other sectors during the same forum disruption window. DDoS, hacktivism and claimed hacks declined toward zero while breach chatter increased, suggesting a shift from visible disruption toward data theft. The elevated telecom breach activity could also signal increased risks of SIM swapping and account takeover targeting banking and enterprise identity systems.
Ransomware activity was moderate, with 63 victims, down 8.7% from 69 and ranking 12th among 14 industries. Monthly activity remained relatively stable between 21 and 27 victims, with a rise in July, while the January peak and February trough appeared to be outliers. Publishing and digital media and content platforms accounted for nearly half of sector victims. Qilin and TheGentlemen led ransomware activity, while the geographic spread contracted from 30 to 22 countries and the U.S. accounted for 40% of sector victims.
Data identified that ransomware presented a comparatively lower risk, with 63 verified victims during the period, down 8.7% from 69 in the previous quarter. Publishing and digital media and content platforms accounted for the largest share of ransomware victims.
Victim distribution spans 29 countries, with the U.S., Japan, and the U.K. recording the highest victim counts, followed by India, South Korea, and Australia. The concentration across major telecommunications markets reflects targeting of network operators and media organizations with significant regional reach.
European presence is broad, with France, Germany, the Netherlands, Ukraine, Italy, Spain, Hungary, Portugal, Switzerland, and Belgium all recording victims, consistent with Russia-linked actor activity in the region. Middle Eastern presence is led by Saudi Arabia and the UAE, aligning with the Iran-linked actors observed this period.
Southeast Asian countries including the Philippines, Thailand, Vietnam, Singapore, Malaysia, Indonesia, and Cambodia appear regularly across observed campaigns, reflecting the region’s expanding telecommunications infrastructure.
CYFIRMA also detailed that web applications and operating systems account for the majority of observed attacks this period. Application infrastructure software features prominently across seven campaigns, reflecting threat actor interest in the underlying platforms supporting telecommunications and media service delivery.
“Database management software and VPN solutions also appear across multiple campaigns,” the report identified. “Notably, routers, network monitoring tools, firewall software, firewall security management software, and content delivery networks all feature in the targeted technology profile, pointing to sustained interest in network-level access and traffic visibility consistent with the state-sponsored actors observed this period.”
The report observed that account takeover is the leading technique with nine items, ahead of phishing at six. It shows up as SIM-swapping in Poland, more than 20,000 Instagram accounts stolen through abuse of Meta AI support, Telegram and Snapchat hijacking, and an FBI warning on 12 August about social engineering against personal accounts.
“Customer data is the main asset being lost,” according to CYFIRMA. “Charter confirmed 4.85 million accounts in late May, RingCentral 1.6 million on 13 August, both attributed to ShinyHunters, which is the only repeat actor at 5 items. Japanese providers lost up to 14.2 million email logins across six ISPs on 28 June and a further 12 million at a major telco on 7 July.”
It added that state activity is real and evenly split. “China and Russia each account for 4 attributed items. The 14 July joint advisory from CISA, NSA, FBI and international partners names Russian targeting of communications and energy through edge-device exploitation. On the Chinese side, APT groups shared a Linux backdoor against Central Asian telcos in May, and a House committee reported on 5 August that Chinese carriers keep a deep US presence despite Salt Typhoon links. NSO Group appears once, via WhatsApp, disrupting Pegasus phishing on 8 June.”


