Communications

Industry

Attack on Service Provider Affects Ericsson

April 17, 2025

A service provider for Ericsson Inc. suffered a cyberattack last April where personally identifiable information from Ericsson fell into the hands of the threat actor.
Ericsson said it holds personal data for employees and customers and, from time to time, shares this information with the company’s service providers. Ericsson sent a letter out to victims notifying them of data security incident that occurred at one of its services providers, which ma involved personal information.
“On April 28, 2025, our service provider became aware of a suspicious event that may have involved potential unauthorized access to certain data on their system,” the company said in a letter to victims. “It promptly initiated an investigation with the assistance of external cybersecurity specialists. It also notified the Federal Bureau of Investigation and implemented measures to enhance security and minimize the risk of a similar incident occurring in the future.”

read more

Evergreen Printing Cyber Incident Causing Operational and Fulfillment Disruption

December 19, 2025

Evergreen Printing suffered a ransomware attack that disrupted its operations. In particular newspaper printing, subscriber fulfillment systems, and mailing operations were impacted. Affected customers were forced to rebuild mailing lists and deal with delays in press operations. The company activated its incident response plan and engaged outside experts to investigate and remediate the attack. Besides The Retrospect, no other Evergreen Printing customers have been publicly named.

read more

Cyberattack Forces Temporary Printing Halt at Roularta Media

June 10, 2025

Belgian Roularta Media Group was hit by a DDoS attack. The attack locked critical IT systems that controlled scheduling, workflow, and production management. Presses could not operate normally until the systems were restored. The disruption affected the timely processing of newspapers and magazines such as Knack and Libelle. The impact is limited however, some Knack readers will receive their magazine a day later.

read more

Dragonforce Ransomware Locks Local Norwegian Newspaper Servers, Printing Halted

May 24, 2025

Norwegian regional newspaper Altaposten and its sister publication Ávvir were hit by a ransomware attack. The ransomware locked key IT resources, including the server shared by both newspapers, and prevented staff from accessing content and publishing normally. The media outlet’s owners refused to pay the ransom. Management stated it was more cost‑effective to discard the affected server and rebuild rather than follow the attackers’ instructions to retrieve decryption keys. The printed edition of Altaposten was canceled — the first time since the paper’s launch in 1969.

read more

Ransomware Attack at London Literary Agency

February 7, 2025

The Agency, a London-based literary and talent agency, disclosed a ransomware attack. The incident caused significant disruption to its IT systems. The Agency informed clients that personal and internal data may have been accessed or copied during the breach, reported the incident to the UK Information Commissioner’s Office. No public confirmation that any stolen data was released by the hackers responsible for the attack.

read more

BK Technologies Hit in Ransomware Attack

September 20, 2025

Communications equipment maker, Melbourne, Florida-based BK Technologies suffered a cyberattack in September and it appears a ransomware attack group is taking credit for the hack.
“On or about September 20, 2025, BK Technologies Corporation detected potentially suspicious activity involving its information technology (“IT”) systems,” according to the 8-K report with the Securities and Exchange Commission (SEC). “Upon detecting the issue, the company began taking steps to assess, contain, and remediate the potentially unauthorized activity, including isolating the affected systems and launching an investigation with the assistance of external cybersecurity advisors.”
As a result of the incident, a limited number of non-critical systems experienced minor disruption.

read more

Ransomware Attack at KY Phone Co-Op

February 13, 2025

Jamestown, Kentucky-based Duo County Telephone Cooperative Corporation, Inc. and Cumberland Cellular, LLC (doing business under the shared branding Duo Broadband) suffered a ransomware attack that exposed personally identifiable information.
Duo Broadband suffered a security incident that may have exposed some of your personal information. There were 42,518 victims in the incident, the company said.
“On February 13, Duo Broadband discovered a data security incident in which a cyber threat actor attempted to disrupt our systems in a possible effort to deploy ransomware, and solicit a ransom payment from us,” the company said in a letter to victims of the incident.

read more

Ransomware Attack Disrupts Operations at Turkish Information Technologies and Communication Authority (BTHK)

March 28, 2025

Bilgi Teknolojileri ve Haberleşme Kurumu, Turkey’s information technology and communication authority, was hit by an attack on March 28, 2025. The company stated that the attack was detected at an early stage and successfully prevented without any data loss or system disruption. “Contrary to claims in some media outlets, all of our Institution’s systems continue to operate securely and are closed to the outside world. Additional security measures have been implemented. Necessary updates are being rapidly implemented. In this context, following system improvements, routine work will begin as planned on Monday, April 7, 2025.”

On April 4 Kibrispostasi news reported that the website is inaccessible, communication records have been deleted, and number portability between operators has been blocked.

read more

British COLT Telecom hit by WarLock Ransomware

August 12, 2025

UK-based telecommunications company Colt Technology Services suffered a cyberattack, The attack caused a multi-day outage of some of the company’s operations, including hosting and porting services, Colt Online, and Voice API platforms. The company stated the impacted systems are support services, not the core customer network infrastructure. Warlock is said to be behind the attack. The group has not leaked even a snippet of the data it stole online. Instead it opted to try and sell the data privately via auction

The recovery might not be completed until late November 2025. If Colt’s estimated return-to-normal timeframe is accurate, the time spent tackling the disruption would amount to more than three and a half months.

read more

MA Telecom, Security Provider Suffers Cyberattack

July 11, 2025

Norwood, Massachusetts-based communications and security provider, LAN-TEL Communications, Inc. suffered a cyberattack this past July and notice is now going out to victims of the hack.
The breach occurred July 11, when an external system suffered compromise through a hack attack. As it turns out, the situation ended up discovered over two months later on September 23.
The company sent out written notifications to victims of the attack on October 9, informing them of the breach and the potential risks associated with it.

read more