GettyImages-1276687348.jpg
– Getty

Telecom vendor Ribbon Communications has reportedly been the victim of a nation-state hack.

The stealth attack saw intruders access Ribbon’s systems for around nine months, according to a Securities and Exchange Commission (SEC) filing made by the firm last week.

Several files from three “smaller” clients saved outside of Ribbon's main network on a pair of laptops were accessed by the attackers, with both the customers and the bad actor unnamed in the SEC filing.

Ribbon said it was working with “multiple third-party cybersecurity experts, including federal law enforcement.” The firm added it believed it had “been successful in terminating the unauthorized access by the threat actor.”

A spokesperson from the Cybersecurity and Infrastructure Security Agency (CISA) told The Register that the body was aware of the incident while directing any further inquiries to Ribbon Communications.

The company provides IP-optical kit and communications software to the likes of Verizon, Lumen Technologies, Deutsche Telekom, SoftBank, and the Department of Defense.

Ribbon was recently tapped to provide a middle-mile network solution for Vibrant Broadband, following similar ventures in Alabama, Illinois, Montana, and Pennsylvania.

The firm has also made its move into the autonomous networks segment, releasing an AI for IT operations (AIOps) platform last month.

Another nation-backed hack

The hacking incident follows a similar stealth move that affected security firm F5.

In an SEC filing, F5 reported that a China-linked threat actor had breached its networks and gained “long-term, persistent access” to certain areas of its system, with prior reports suggesting the hackers had access to its network for at least a year.

These latest incidents come after the infamous Salt Typhoon attacks that targeted critical networks in 2024.

Cybersecurity firm Darktrace recently published analysis that claimed a European telecoms organisation was attacked by the hacking group in July.

Affiliated with the People’s Republic of China (PRC), Salt Typhoon was blamed for what was dubbed the worst telecom hack in U.S. history last year, which saw attacks on AT&T, Verizon, and Lumen Technologies, among others.

In an interview with SDxCentral, Gregory Richardson, VP and advisory CISO at BlackBerry, commented that such attacks are a reminder that trusting internal communications is no longer valid.

“It demonstrates that massive amounts of sensitive data, including cellular backhaul, clear text messages and calls …. are transmitted in the open simply because they are assumed to be secure internal links. This, combined with the Salt Typhoon attackers’ ability to compromise core network devices from within, proves that the network itself cannot be trusted.

“The network should be considered hostile, and all communications must be secured. Security must be redesigned from the perimeter inward, covering every endpoint and extending through the security operations center,” said Richardson.