We warned that backdoors would leave us open to attack.
We warned that being forced to keep customer data in readily-accessible databases was dangerous.
We warned that telcos were the weakest link in the cybersecurity stack.
Yet few listened.
All government could do was rub its hands together at the idea of all the data it could get its hands on and what it could do with it. Data to catch criminals. Data to catch terrorists. Data to snoop on citizens.
All CISOs could do was try to tackle the top 10 risks on their list. Telecoms fell outside their remit, wasn’t seen as a high enough priority, and was down to suppliers to manage.
And then came Salt Typhoon and all of those saying that telecoms was one of the biggest risks to national and commercial security collectively shook their heads. ‘We told you so’ doesn’t even come close to how devastated we are. We tried to tell you what the risks were and what to do about them. But everything we said fell on deaf ears.
Customer convenience was more important. Government expediency was more important. Regulators had better things to do. Ministers just didn’t understand the issues or the interdependencies. Executives who should have known better were more concerned with profit margins, lobbying government, avoiding spending money.
I even used the old Northern adage that telecoms had become ‘all fur coat and no knickers’. Still, no-one flinched – let alone was shocked into action.
Some of it is the fault of telecoms executives – undoubtedly. We have to take our share of the blame.
But it’s also the fault of ineffective regulators, political ignorance and expediency, a lack of strategic thought, and large corporates who never asked the right questions and didn’t properly manage their risk.
It doesn’t help that I’ve spent years telling anyone who’d listen that the industry is riddled with 1990s tech and processes that are no longer fit for purpose. Whether that’s mobile number portability – a continued risk due to the UK’s completely inadequate process – or legally-mandated backdoors.
The most obvious result was an infiltration across 80+ countries stretching from North America, across Europe to Asia and Africa.
By taking a steady, stealthy approach to data interception and not doing anything that would set off the alarms (stealing money, bringing down websites etc), Salt Typhoon was able to compromise core network interfaces and live inside the network for years. This allowed the interception of metadata and the monitoring of unencrypted traffic – including from high-value targets such as Donald Trump, JD Vance, Boris Johnson, Liz Truss and Rishi Sunak, as well as FBI counterintelligence databases and more.
Exfiltration techniques made stolen data appear to be routine internal network traffic so far as monitoring systems were concerned.
Salt Typhoon’s primary objective was intelligence collection – including the interception of call records, geolocation data, communications metadata and content from high-value targets – using access to backbone networks, lawful intercept systems and router-level controls.
Its sister campaign – Volt Typhoon – is aimed at embedding itself within critical infrastructure using ‘living-off-the-land’ techniques to avoid detection. It is an embedded, hidden sabotage infrastructure that creates backdoors, command-and-control footholds, and digital time bombs.
The fallout is that even the most heavily defended telecoms have been shown to be vulnerable to compromise, that the network cannot be trusted, and it’s rammed home the obvious – increased connection and interconnection is a massive risk. And thank goodness. Because up until now nobody was listening when we warned that telecoms had a massive latent security problem that just wasn’t being spoken about.
But what does all of this mean for the sector?
More scrutiny. Yet more demands from government. Big questions – and quite rightly – from corporate customers. And, sadly, the loss of yet more customer trust.
Where to start fixing things? Since the scale is huge – both in terms of volume, variety and velocity.
According to Nokia, around 63% of operators were targeted last year by so-called ‘living-off-the-land’ attacks, which stay inside the core network for sustained periods, infecting systems, gathering credentials and extracting data. A third of telcos (32%) experienced at least four of these attacks in 2024.
The West has now embarked on a new programme of removing every last vestige of Chinese equipment from their networks. This will add to costs, cause more delays and, on its own, will not fix the issues.
Telcos are also taking a long hard look at their lawful intercept systems. Are they sufficiently secure? What can be done to harden them further?
But what about all that DDoS traffic the industry has been ignoring for years as just ‘scale in the pipe’? Nokia says terabit-scale DDoS attacks are now a daily occurrence. While that shouldn’t be dismissed, it’s important not to overlook low-level DDoS traffic – with no network being completely clear of it.
And what about outdated processes – like the UK’s insecure mobile number portability process? What about the ability to compromise key staff to gain access to core infrastructure, or the effects of unpatched systems and human error?
But surely AI can fix all of this? As with most things, AI is part of the answer and a powerful tool; but, according to IBM, it can create as many problems as it solves. AI hallucinations, it turns out, are a big problem for cybersecurity. They may cause a telco or enterprise to overlook a threat, raise false alarms that divert resources, or derail mitigation efforts by providing the wrong recommendations.
If the telecoms industry wants to retain the confidence and trust of its customers – government, corporate and consumer – it has some big questions to answer.
If the network, systems and processes can’t be trusted until we fix them, tell me – what’s the ONE change telcos should make immediately. Before the next breach makes all of this look like the warm-up act?
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.