tsunami
– Getty Images

It’s safe to say Salt Typhoon still blows strong for telecoms.

Affiliated with the People’s Republic of China (PRC), the Salt Typhoon hacking group was blamed for what was dubbed the worst telecom hack in U.S. history last year, with attacks placed on AT&T, Verizon, and Lumen Technologies, among others.

The ill wind didn’t stop there, with cybersecurity firm Darktrace recently claiming an unnamed European telecoms business was attacked by the hacking group in July 2025.

The same year saw U.K. telco Colt Technology Services knocked practically offline for more than three months due to a ransomware breach, while Ribbon Communications admitted in October it had been the victim of a nine-month-long hack. Without naming any specific suspects, the U.S. telecom vendor pointed the finger at a nation-state attacker in the same vein as Salt Typhoon.

In Nokia’s recent Threat Intelligence report, only 7% of communication service providers (CSPs) reported they were fully prepared for another Typhoon-esque attack. This was the area of least confidence for telcos, sitting on par with the more hypothetical danger of quantum computing threats.

With stats like these compounding recent cybersec telco fails, the situation begs two questions as to whether telecoms is taking cybersecurity seriously enough, and why state-sponsored threats remain such a quandary for businesses in the sector.

While Nokia was unable to comment on both issues when prompted by SDxCentral, it did report that North American operators reported stronger readiness for ransomware and DDoS attacks compared to those in other territories.

EY Global TMT lead analyst Adrian Baschnonga, meanwhile, believes telcos are "certainly" taking cybersecurity seriously enough in spite of CISO concerns.

“[This is] given telcos store large amounts of sensitive data and are subject to a range of cyberthreats involving different actors. Regulatory focus on network security is also growing, underlining telcos’ status as a critical national infrastructure,” Baschnonga told SDxCentral.

The EY analyst believes the issue is that regardless of industry, the cybersecurity function in business is “positioned as reactive, technically focused, and compliance-driven.”

At a recent Ericsson summit, Vincenzo Procopio, Telia’s head of cybersecurity for Telia, admitted that cyber attacks were “becoming more and more sophisticated,” with an increasingly complex regulatory landscape becoming just as great a problem – until the Swedish telecom took on a more proactive approach.

“After GDPR, we started understanding that the IT landscape and the architecture were not sufficient, so we had to extend to adopt a security framework to be able to handle all these requirements,” said Procopio.

As such, Telia opted to adopt the NIST Cybersecurity Framework (CSF), with Procopio and team implementing features such as endpoint detection and response (EDR), security orchestration, automation, and response (SOAR), alongside zero trust security.

‘Terabit tsunamis’

As with all things telco and tech today, it’s hard to avoid the AI elephant in the room, especially when it comes to security and governance, and Procopio revealed that enabled through its more proactive and agile approach, AI threat hunting is the next stage of Telia’s security transformation.

But the cybersecurity lead also highlighted the double-edged nature of the tech.

“We can use artificial intelligence with positive intent. But if you want to act as a criminal, you can use AI to attack and build the code for attacks. So we need to also be able to discern when we have a deployment of an application for positive intent, and negative intent, at the same time.”

In the same spirit, Nokia’s representative told SDxCentral that across nearly all regions, the abiding trend in telecom security is “prioritizing AI- and machine learning-driven threat analytics and automation as the cornerstone of future network defense.”

The firm’s research report also pointed to Google's evidence of nation-state-backed actors experimenting with large language models (LLMs) for reconnaissance automation and attack scripting.

PwC echoed such concerns with research warning AI use in network performance has scaled to match Internet of Things (IoT) and 5G expansion, resulting in increased attack surface and data exposure within the telecoms sector.

Following the release of both reports, Google identified what it claimed to be the first observed live malware using an LLM to produce operational commands in real time, targeting network structures.

Known as Promptsteal, the networking threat employs the LLM to generate on-demand Windows commands for data exfiltration and system reconnaissance. The dynamically generated commands enable the malware to gather system information and identify sensitive files before transmitting them across the network to an adversary-controlled server.

While that experimental threat was promptly snuffed out by Google with added guardrails to its Gemini LLM, it is clear the barriers have been broken when it comes to AI-assisted attacks.

Automated DDoS campaigns have already reached record scale, with Nokia reporting 52% of attacks hit multiple hosts, with 58% using multiple vectors, and 78% finishing within five minutes.

There are now over 100 million compromised endpoints in the ecosystem, Nokia claimed, enabling terabit-scale floods such as the 22.2 Tb/s DDoS attack blocked by Cloudflare in September.

Nokia warned that with state-sponsored threats adopting AI in their arsenal, DDoS defense needs response speeds driven by algorithms that keep pace. This is the only way to stem what it described to SDxCentral as “the new wave of ‘terabit tsunami’ attacks.”

“Legacy methods like blackholing or traffic scrubbing simply can’t keep up with the scale and sophistication of modern threats. The path forward lies in solutions that blend speed, intelligence, and scale, powered by AI, to help operators stay several steps ahead in an increasingly volatile threat environment,” Nokia’s spokesperson explained.

But even with AI, CSPs still need human security experts. This is easier said than done, according to Telia’s Procopio, who claimed at the same summit that “it’s not easy to find cybersecurity experts in today’s market.”

This is borne out by recent TM Forum Research claiming cybersecurity to be telecom’s most in-demand expertise set at 67%, outpacing the need for AI experts (65%).

“Cybersecurity expertise is in high demand as new technology cycles challenge the security of existing systems and processes, with demand for cyber skills often outpacing supply,” EY’s Baschnonga concurred.

The EY telecom analyst noted telcos are responding in various ways, either by increasing their focus on reskilling, receiving support from technology partners, or building new partnerships with universities.

“Telcos that can effectively harness these different options will be best placed to maximize their cybersecurity capabilities,” he explained.

Security in SIMs and slices

Cybersecurity talent now and in the near future will undoubtedly have to factor in the effect of AI on telecom network security. But they’ll also have to acknowledge post-quantum security, 6G implementation, and the more autonomous intent-based networking (IBN) that is made possible by level four (L4) autonomy.

According to Nokia, IBN introduces new classes of programmable infrastructure that come with their own specific threat models and failure modes, rather than serving as safer replacements for software-defined networking (SDN).

In the post-5G era, the vendor told SDxCentral it is optimistic that “stronger trust and security mechanisms being built into 6G architectures will ensure more reliable policy enforcement across interconnected networks.”

Dan Hays, PwC partner and telecom leader, recently echoed this vision by arguing that “in 6G, trust won’t be an add-on, it’ll be an operating principle,” helping operators counter the trust and safety issues that could be compromised by 6G’s AI-native nature.

To see how this works in principle, it’s worth observing how providers like Telia are working with programmable proto-6G features such as network slicing in their operations.

At the Ericsson conference, Procopio revealed the Swedish operator partnered with British Telecom (BT) on securing a 5G standalone (5G SA) network slice as part of its security overhaul.

The project onboarded a SIM card on the slice, with Telia’s security services provided on top of said slice. Thus, in the event of a malware attack, the operator can remove the SIM card from the slice automatically.

“If this is not sufficient, we can instruct the orchestration to remove the entire network slice and recreate it again, reattaching the subscriptions that need to stay in the slice.”

Procopio viewed the function as an “opportunity” in exploring 5G technology, showcasing the inspiration that can arise in tackling today’s cybersecurity challenges.

In his EY report, Baschnonga’s research reported 68% of telco CISOs found it difficult to articulate the value cybersecurity delivers beyond risk protection, stymied in part by a lack of cybersecurity input into cross-functional decision-making at the leadership level.

Baschnonga believes that cybersecurity expertise has an integral role to play in value creation, especially in supporting the development of new products and services like in the Telia example.

“Bridging this gap requires CISOs to position themselves as strategic enablers for the business, deepening their commercial acumen and further aligning cybersecurity teams with broader organizational goals,” he argued.

In the EY view, a bigger CISO presence in the telecom boardroom may see both bigger budgets and a greater number of stakeholders when it comes to ensuring security is at the forefront of business decisions.

In other words, commercial potential can grease the helm, and all hands on deck are needed to ensure telecoms survive foreboding Typhoons on the horizon.

This article first appeared in the Cybersecurity Supplement.

To read the Supplement for free, simply register