Communications

Industry

Data Breached at Telefónica, a Spanish Telecommunications Company

January 10, 2025

Spanish telecommunications company Telefónica confirms an internal ticketing system was breached after a Telefónica Jira database was leaked on a hacking forum. .In an email to BleepingComputer today, Telefónica confirmed its ticketing system was breached and are investigating the incident.

Three people behind this attack, Grep, Pryx, and Rey, are also members of a recently launched ransomware operation known as Hellcat Ransomware.

read more

UK Book Printer CPI Hit by Ransomware Attack

February 7, 2025

The UK’s leading book printer, CPI was hit by a ransomware attack. Clients of CPI, including Welsh independent Firefly Press, have been majorly affected.
Production at 8 factories shut down for over 12 days. Customers reported delays in printing their books as long as 18 days after the initial attack.

read more

Large Scale DDoS Attack at Large Russian Telecoms MegaFon

January 24, 2025

A significant cyberattack hit MegaFon, one of Russia’s largest mobile and internet operators. The failure in Megafon’s operation occurred on the morning of January 24. The cause was a carpet DDoS attack on the mobile operator. Forbes reports the attack was carried out by one of the groups of “politically motivated hackers” (the IT army of Ukraine). The attack “was effective, and degradation of services was observed at the international level.”

Later the Russian media revealed the true cause of the disruptions – a highly effective “carpet-bombing DDoS attack” targeting MegaFon. While the company claimed its network was operating “smoothly,” it admitted to “possible access issues” caused by factors beyond its control.

read more

DDoS Attack at Russian Telecom Beeline

February 26, 2025

Beeline experienced a failure due to a DDoS attack. About 6,000 users complained about the problems on Downdetector. “Specialists are taking all necessary measures to minimize possible consequences and maintain stable operation of services,” the operator’s press service said.

read more

Rostelecom Investigates Data Leak

January 21, 2025

Rostelecom, a major Russian telecommunications provider, says it’s investigating a cyberattack on one of its contractors. A hacker group calling itself Silent Crow, earlier released a batch of allegedly stolen company data. The company admitted it had previously detected “information security incidents” at one of its contractors. According to Rostelecom, the unnamed contractor is responsible for maintaining its corporate website and procurement portal. Both were reportedly targeted by hackers.

read more

DDoS Attack on Russian Telecom Beeline Causes Outages

March 3, 2025

Some Russians had their internet disrupted on Monday due to a targeted distributed denial-of-service (DDoS) attack on the telecom Beeline — the second major attack on the Moscow-based company in recent weeks. Beeline confirmed the attack to local media following reports from several outage-tracking services and user complaints. The provider has more than 44 million subscribers.

Data from the internet monitoring service Downdetector indicates that most Beeline users in Russia faced difficulties accessing the company’s mobile app, while some also reported website outages, notification failures and internet disruptions.

Russia’s communications watchdog, Roskomnadzor, reported that subscribers in Moscow and surrounding regions had filed mass complaints over connectivity issues following Monday’s incident.

read more

Official .uk Domain Registry Confirms Network Breach

January 13, 2025

Nominet, the official .UK domain registry and one of the largest country code registries, has confirmed that its network was breached two weeks ago using an Ivanti VPN zero-day vulnerability. Since it detected suspicious activity on its network, the company has reported the attack to relevant authorities, including the NCSC, and restricted access to its systems via VPN connections. “The entry point was through third-party VPN software supplied by Ivanti that enables our people to access systems remotely,” Nominet says in a customer notice shared with BleepingComputer. “”e currently have no evidence of data breach or leakage.

read more

Cyberattack at Japan’s Largest Mobile Carrier, NTT Docomo

January 2, 2025

Japan’s largest mobile carrier, NTT Docomo, reported a cyberattack temporarily disrupted operations. Its system were targeted by a distributed denial-of-service (DDoS) attack.
From early Thursday morning until late afternoon, local users were unable to access NTT Docomo’s news website, video streaming platform, mobile payment and webmail services. The company reported that access to most services had been restored late afternoon, although some content updates might still face delays.

read more

Cyberattack Affects > 18,000 Workstations at Telecom Argentina.

July 18, 2024

On July 18, top Argentinian telecom provider Telecom Argentina announced that it was the target of a ransomware attack. The effects of the attack were first noticed when the Telecom’s employees started facing issues and lag in their systems while accessing the company’s VPN (virtual private network). The internal security systems instantly set-off the alarms but not before the ransomware was installed in over 18,000 workstations.

The attackers demanded nearly $7.5 million, threatening to raise the ransom to $15 million if they weren’t compensated within three days. Telecom Argentina confirmed that none of its dependent services were affected.

read more

Singtel Reportedly Hacked as Test Run for Further Hacks against US Communications companies.

June 1, 2024

Chinese government cyberspies Volt Typhoon reportedly breached Singapore Telecommunications over the summer of 2024 as part of their ongoing attacks against critical infrastructure operators. The digital break-in was discovered in June, according to Bloomberg, citing “two people familiar with the matter” who told the news outlet that the Singtel breach was “a test run by China for further hacks against US telecommunications companies.” The hackers used a web shell and exploited a Versa SD-WAN vulnerability. (see separate incident dated June 12).

In February, the feds and other nations’ governments warned that the Beijing-backed crew had compromised “multiple” critical infrastructure orgs’ IT networks in America and globally, and were “disruptive or destructive cyberattacks” against those targets.

read more