Why Telecoms Are High-Value Targets
Open a laptop at home, type a domain, hit enter. Before that request reaches anything you would call “the internet,” it has already crossed miles of someone else’s infrastructure. You did not choose that path. You cannot audit it. Every packet you have ever sent has crossed some version of it.
That is why telecoms are one of the most valuable targets a nation-state has. Attacking you risks burning an exploit on one person. Attacking your carrier buys visibility into millions of people at once.
A carrier holds exactly what an intelligence service wants: who talks to whom and when, where you are at all times, every SMS code sent to your number, and anything you send unencrypted.12
Data at national scale is the prize, and a telecom hands it over in bulk.
What a Telecom Actually Looks Like
Four layers, roughly.
The last mile is the physical connection to you: fiber, coax, the cell site down the road. Thousands of nodes, each seeing a handful of subscribers.
Aggregation gathers those connections into regional sites. Traffic concentrates here for the first time.
The core backbone is a small number of very large sites carrying everything between regions. One router here sees a meaningful share of a country’s traffic.
The control plane is the part that knows who you are. It authenticates your SIM, tracks you between towers, routes your calls and texts, and answers your DNS queries.
Attackers want reach and longevity, and the joint advisory published in August 2025 says so plainly: the actors focus on “large backbone routers of major telecommunications providers” and “often modify routers to maintain persistent, long-term access to networks.”3 Once there, the moves are unglamorous. They adjust the device’s own settings so their traffic is allowed, build a tunnel, capture traffic on the way past, and take the credentials that unlock every other device.3
Then they use the trusted links between providers to step into the next network. Compromising one carrier is rarely the end state.
A position in the middle is not only for watching, either. Whoever controls the path can change what reaches you. For example, answer your DNS lookup with the wrong address and send you to a server of their choosing, or push a connection back down to something readable. This is why CISA describes the risk as interception “or manipulation.”1
None of which means the equipment in your house is out of scope. The same advisory notes these actors “may target edge devices regardless of who owns a particular device”3, including yours, if you are personally worth the effort.
This Already Happened, Repeatedly
In late 2024, U.S. agencies confirmed that PRC-affiliated actors, publicly tracked as Salt Typhoon, had compromised commercial telecommunications infrastructure. CISA’s description of the result is worth reading twice: it “enabled the theft of customer call records and the compromise of private communications for a limited number of highly targeted individuals.”1
It is not an American problem.

In April 2025, South Korea’s largest carrier noticed unusually large amounts of data leaving its network. Attackers had taken roughly 27 million subscriber identity records, which the carrier had failed to encrypt. Investigators traced the root cause back to a 2022 breach that was never properly handled. What the stolen data enables, in the government’s own words: SIM-cloning and “call/message interception.”4
No one has publicly named who was inside. That is its own kind of answer: the network held the identity of every subscriber, and someone else had it for years.
The playbook is older than the headlines, too. Operation Soft Cell, documented in 2019 and running since at least 2012, was a worldwide campaign against telecom providers assessed with high confidence as China state-sponsored. What the attackers wanted was not the network. It was call records belonging to specific individuals from various countries.2 They owned entire carriers to read the metadata of a handful of people.
Which brings us to the part that matters for you. Two weeks after publishing hardening guidance for carriers,5 CISA published advice for individuals. Its opening instruction is the thesis of this post:
Highly targeted individuals should assume that all communications between mobile devices, including government and personal devices, and internet services are at risk of interception or manipulation.1
Note what the federal cybersecurity agency did not say. Not “we fixed it.” It was “stop trusting the network.”
And that assumption should travel with you. Land somewhere else and your phone attaches to a carrier you did not choose, in a jurisdiction you did not pick, which now knows who and where you are and carries your calls and texts. The 2025 advisory says so outright. Data stolen from foreign telecommunications and internet providers, as well as intrusions in the lodging and transportation sectors, “ultimately can provide Chinese intelligence services with the capability to identify and track their targets’ communications and movements around the world.”3 Assume your carrier is breached at home. Assume the same everywhere else.
What You Can Actually Do
You cannot harden a telecom. You can make it irrelevant. Push everything you care about up a layer, so the network carries traffic it cannot read or alter. Nearly all of this is CISA’s own guidance, which is a nice change from having to argue for it.1
| Change | Why it matters | Where |
|---|---|---|
| Use end-to-end encrypted messaging | The carrier still moves your messages but cannot read them. CISA’s first recommendation. | Signal, on every device |
| Stop using SMS for authentication | “SMS messages are not encrypted.” Anyone with access to a carrier can read the codes. | Passkeys or a hardware security key |
| Turn on encrypted DNS | Hides which sites you look up, and stops the answer being swapped for a fake one | Apple devices: my profile builder. Android: Private DNS |
| Set a port-out PIN | Blocks the low-effort SIM swap, still far more common than a nation-state implant | Your carrier account |
| Kill the SMS fallback | Stops a message quietly downgrading from encrypted to carrier SMS | iPhone: turn off “Send as Text Message”. Android: RCS is only encrypted in Google Messages |
| Turn on Lockdown Mode or Advanced Protection | Keeps the phone off legacy vulnerable cellular protocols6 | iPhone and Android settings |
Traveling: take a device with only what the trip requires and leave the primary phone home. Assume voice and SMS on a foreign network are collected. Encrypted DNS should already be on at home. If it is not, fix that before you leave, not after you land. Clear off the accounts and data you would not want examined at a border.
The Realistic Bar
None of this stops a state actor from living inside a carrier’s core routers. That fight is not yours, and it is genuinely hard. The infrastructure is enormous, expensive to replace, and lightly monitored in exactly the places that matter. Campaigns running since at least 2012 and found years later are the evidence.
What you control is how much a compromised network learns from you, and how much it can change. If your traffic is encrypted, it sees that you connected to something, when, for how long, and which tower you were on, but not what was said. If it is not, it sees the sites you visit, the codes texted to your phone, and what you texted.
In addition to confidentiality, encryption also protects integrity: what reaches you is what you actually asked for.
The goal is not to be unreachable. It is to make the network a dumb pipe: assume it is hostile, and let that assumption guide you into becoming a harder target.
Did you know?
Lawful intercept is a design requirement in certain countries. In the U.S., CALEA has required carriers to build interception capability into their networks since 1994. So the ability to monitor communications at scale is not something an attacker has to build. It is already in the network, by law, waiting for whoever reaches it. Building a capability and restricting who may use it are two very different engineering problems, and only the first has ever been solved.
-
CISA, “Mobile Communications Best Practice Guidance,” December 18, 2024. https://www.cisa.gov/resources-tools/resources/mobile-communications-best-practice-guidance ↩︎ ↩︎ ↩︎ ↩︎ ↩︎
-
Cybereason, “Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers,” June 2019. https://www.cybereason.com/blog/research/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers ↩︎ ↩︎
-
NSA, CISA, FBI, DC3 and international partners, “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System” (AA25-239A), August 27, 2025; v1.1 September 3, 2025. https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a ↩︎ ↩︎ ↩︎ ↩︎
-
Ministry of Science and ICT (Republic of Korea), “MSIT Releases Final Investigation Results on SK Telecom Data Breach,” July 10, 2025. https://www.korea.net/Government/Briefing-Room/Press-Releases/view?articleId=8120 ↩︎
-
CISA / NSA / FBI and international partners, “Enhanced Visibility and Hardening Guidance for Communications Infrastructure,” December 3, 2024. https://www.cisa.gov/resources-tools/resources/enhanced-visibility-and-hardening-guidance-communications-infrastructure ↩︎
-
Electronic Frontier Foundation, “Your Phone Is Vulnerable Because of 2G, But It Doesn’t Have to Be,” June 9, 2020. https://www.eff.org/deeplinks/2020/06/your-phone-vulnerable-because-2g-it-doesnt-have-be ↩︎