Why Telecoms Are High-Value Targets

A home internet request crossing the last mile, a carrier drawn as a circle of interlinked routers, and a peering handoff before reaching a website, with the middle of the path marked as infrastructure you did not choose.

Open a laptop at home, type a domain, hit enter. Before that request reaches anything you would call “the internet,” it has already crossed miles of someone else’s infrastructure. You did not choose that path. You cannot audit it. Every packet you have ever sent has crossed some version of it.

That is why telecoms are one of the most valuable targets a nation-state has. Attacking you risks burning an exploit on one person. Attacking your carrier buys visibility into millions of people at once.

A carrier holds exactly what an intelligence service wants: who talks to whom and when, where you are at all times, every SMS code sent to your number, and anything you send unencrypted.12

Millions of subscribers drawn as a wide field of dots funnelling into a single carrier, with one dot highlighted as you. A warning triangle marks the carrier and one arrow leaves it, carrying who talks to whom, where everyone is, every SMS code and anything unencrypted, for all of them at once.

Data at national scale is the prize, and a telecom hands it over in bulk.

What a Telecom Actually Looks Like

A telecom network in four layers: last mile, aggregation and core backbone along the bottom, with a control plane above them. Warning triangles show where an intruder wants to be, traffic being copied out of the core, and pivots outward to another provider and back down to the customer’s own equipment.

Four layers, roughly.

The last mile is the physical connection to you: fiber, coax, the cell site down the road. Thousands of nodes, each seeing a handful of subscribers.

Aggregation gathers those connections into regional sites. Traffic concentrates here for the first time.

The core backbone is a small number of very large sites carrying everything between regions. One router here sees a meaningful share of a country’s traffic.

The control plane is the part that knows who you are. It authenticates your SIM, tracks you between towers, routes your calls and texts, and answers your DNS queries.

Attackers want reach and longevity, and the joint advisory published in August 2025 says so plainly: the actors focus on “large backbone routers of major telecommunications providers” and “often modify routers to maintain persistent, long-term access to networks.”3 Once there, the moves are unglamorous. They adjust the device’s own settings so their traffic is allowed, build a tunnel, capture traffic on the way past, and take the credentials that unlock every other device.3

Then they use the trusted links between providers to step into the next network. Compromising one carrier is rarely the end state.

A phone asks where a bank’s website is. The question goes by default to the carrier’s DNS server, which is marked as compromised. The reply carries an address the attacker controls, so the phone connects to a malicious server while the real bank is never contacted.

A position in the middle is not only for watching, either. Whoever controls the path can change what reaches you. For example, answer your DNS lookup with the wrong address and send you to a server of their choosing, or push a connection back down to something readable. This is why CISA describes the risk as interception “or manipulation.”1

None of which means the equipment in your house is out of scope. The same advisory notes these actors “may target edge devices regardless of who owns a particular device”3, including yours, if you are personally worth the effort.

This Already Happened, Repeatedly

In late 2024, U.S. agencies confirmed that PRC-affiliated actors, publicly tracked as Salt Typhoon, had compromised commercial telecommunications infrastructure. CISA’s description of the result is worth reading twice: it “enabled the theft of customer call records and the compromise of private communications for a limited number of highly targeted individuals.”1

It is not an American problem.

The seals of the two dozen national agencies that co-sealed the August 2025 joint advisory, including the NSA, CISA, FBI, and the security and intelligence services of Australia, Canada, New Zealand, the United Kingdom, the Czech Republic, Finland, Germany, Italy, Japan, the Netherlands, Poland and Spain.

Every agency that put its name on the August 2025 advisory.

In April 2025, South Korea’s largest carrier noticed unusually large amounts of data leaving its network. Attackers had taken roughly 27 million subscriber identity records, which the carrier had failed to encrypt. Investigators traced the root cause back to a 2022 breach that was never properly handled. What the stolen data enables, in the government’s own words: SIM-cloning and “call/message interception.”4

No one has publicly named who was inside. That is its own kind of answer: the network held the identity of every subscriber, and someone else had it for years.

The playbook is older than the headlines, too. Operation Soft Cell, documented in 2019 and running since at least 2012, was a worldwide campaign against telecom providers assessed with high confidence as China state-sponsored. What the attackers wanted was not the network. It was call records belonging to specific individuals from various countries.2 They owned entire carriers to read the metadata of a handful of people.

Which brings us to the part that matters for you. Two weeks after publishing hardening guidance for carriers,5 CISA published advice for individuals. Its opening instruction is the thesis of this post:

Highly targeted individuals should assume that all communications between mobile devices, including government and personal devices, and internet services are at risk of interception or manipulation.1

Note what the federal cybersecurity agency did not say. Not “we fixed it.” It was “stop trusting the network.”

A map showing a home country, the country being visited, and a third country that has compromised the visited carrier, so copies of the traveller’s calls, texts and location flow to it while roaming connects the visited carrier back home.

And that assumption should travel with you. Land somewhere else and your phone attaches to a carrier you did not choose, in a jurisdiction you did not pick, which now knows who and where you are and carries your calls and texts. The 2025 advisory says so outright. Data stolen from foreign telecommunications and internet providers, as well as intrusions in the lodging and transportation sectors, “ultimately can provide Chinese intelligence services with the capability to identify and track their targets’ communications and movements around the world.3 Assume your carrier is breached at home. Assume the same everywhere else.

What You Can Actually Do

You cannot harden a telecom. You can make it irrelevant. Push everything you care about up a layer, so the network carries traffic it cannot read or alter. Nearly all of this is CISA’s own guidance, which is a nice change from having to argue for it.1

Change Why it matters Where
Use end-to-end encrypted messaging The carrier still moves your messages but cannot read them. CISA’s first recommendation. Signal, on every device
Stop using SMS for authentication “SMS messages are not encrypted.” Anyone with access to a carrier can read the codes. Passkeys or a hardware security key
Turn on encrypted DNS Hides which sites you look up, and stops the answer being swapped for a fake one Apple devices: my profile builder. Android: Private DNS
Set a port-out PIN Blocks the low-effort SIM swap, still far more common than a nation-state implant Your carrier account
Kill the SMS fallback Stops a message quietly downgrading from encrypted to carrier SMS iPhone: turn off “Send as Text Message”. Android: RCS is only encrypted in Google Messages
Turn on Lockdown Mode or Advanced Protection Keeps the phone off legacy vulnerable cellular protocols6 iPhone and Android settings

Traveling: take a device with only what the trip requires and leave the primary phone home. Assume voice and SMS on a foreign network are collected. Encrypted DNS should already be on at home. If it is not, fix that before you leave, not after you land. Clear off the accounts and data you would not want examined at a border.

The Realistic Bar

Two panels showing the same compromised carrier. Without protections it reads a DNS query, an SMS code and the text you texted. With protections those are unreadable blocks and only the fact of a connection, its time and its duration remain, with location visible either way.

None of this stops a state actor from living inside a carrier’s core routers. That fight is not yours, and it is genuinely hard. The infrastructure is enormous, expensive to replace, and lightly monitored in exactly the places that matter. Campaigns running since at least 2012 and found years later are the evidence.

What you control is how much a compromised network learns from you, and how much it can change. If your traffic is encrypted, it sees that you connected to something, when, for how long, and which tower you were on, but not what was said. If it is not, it sees the sites you visit, the codes texted to your phone, and what you texted.

In addition to confidentiality, encryption also protects integrity: what reaches you is what you actually asked for.

The goal is not to be unreachable. It is to make the network a dumb pipe: assume it is hostile, and let that assumption guide you into becoming a harder target.

Did you know?

Lawful intercept is a design requirement in certain countries. In the U.S., CALEA has required carriers to build interception capability into their networks since 1994. So the ability to monitor communications at scale is not something an attacker has to build. It is already in the network, by law, waiting for whoever reaches it. Building a capability and restricting who may use it are two very different engineering problems, and only the first has ever been solved.


  1. CISA, “Mobile Communications Best Practice Guidance,” December 18, 2024. https://www.cisa.gov/resources-tools/resources/mobile-communications-best-practice-guidance ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

  2. Cybereason, “Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers,” June 2019. https://www.cybereason.com/blog/research/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers ↩︎ ↩︎

  3. NSA, CISA, FBI, DC3 and international partners, “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System” (AA25-239A), August 27, 2025; v1.1 September 3, 2025. https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a ↩︎ ↩︎ ↩︎ ↩︎

  4. Ministry of Science and ICT (Republic of Korea), “MSIT Releases Final Investigation Results on SK Telecom Data Breach,” July 10, 2025. https://www.korea.net/Government/Briefing-Room/Press-Releases/view?articleId=8120 ↩︎

  5. CISA / NSA / FBI and international partners, “Enhanced Visibility and Hardening Guidance for Communications Infrastructure,” December 3, 2024. https://www.cisa.gov/resources-tools/resources/enhanced-visibility-and-hardening-guidance-communications-infrastructure ↩︎

  6. Electronic Frontier Foundation, “Your Phone Is Vulnerable Because of 2G, But It Doesn’t Have to Be,” June 9, 2020. https://www.eff.org/deeplinks/2020/06/your-phone-vulnerable-because-2g-it-doesnt-have-be ↩︎