Ransomware now hits telcos at scale alongside state activity.
Cyble’s 2025 telecommunications threat landscape records 34 ransomware attacks against telcos globally — a fourfold increase in malware-linked incidents since 2021 — running in parallel to nation-state intrusion campaigns already operating inside carrier networks.
Why Telecommunications is in the crosshairs
Five shifts shaping the global and Australian telco threat environment — what Salt Typhoon has exposed, and what regulators are now asking operators to demonstrate.
Salt Typhoon has reframed the sector globally
At least eight US telcos compromised, one to two years of undetected access, and per the Senate Commerce Committee the campaign is still not fully remediated at end of 2025. Senator Cantwell's "seven-year-old unpatched router vulnerabilities" detail captures the systemic failure that made the intrusion possible. Every major telco now has to assume edge infrastructure has been a target of this class of actor.
Lawful-intercept infrastructure is a specific systemic weakness
Salt Typhoon exploited US CALEA wiretapping infrastructure — systems that, by design, provide access to telecommunications metadata and content for lawful intercept. The FCC's ruling that vulnerabilities "are still being exploited" applies with particular force here. Australia's equivalent architecture sits under the Telecommunications (Interception and Access) Act and carries structurally similar risk.
Nation-state adversaries pre-position for disruption, not just espionage
The White House briefing was explicit: "for espionage, but potentially for disruption at a time of crisis or conflict as well." Volt Typhoon's pattern is pre-positioning against US critical infrastructure; Salt Typhoon's is persistent counterintelligence-relevant access. ASIO DG Mike Burgess confirmed in November 2025 that both have attempted access to Australian critical infrastructure, including telecommunications.
Legacy edge infrastructure is the single largest risk category
Cantwell's seven-year-patch-gap and former FCC official Deb Jordan's iPhone analogy capture the operational reality: core and provider-edge firmware often runs unpatched for reasons that range from operational risk aversion to loss of vendor support. Verizon's 2025 DBIR finding that the share of vulnerability-exploitation breaches targeting edge devices and VPNs rose from 3% to 22% lands with double weight in telco.
Ransomware now hits telcos at scale alongside state activity
Cyble's 2025 analysis counts 34 telecom ransomware attacks involving groups including Qilin, Akira, and Play — a fourfold increase on malware-linked incidents since 2021. MVNOs, regional ISPs, and smaller carriers are particularly exposed. Telstra's November 2024 employee-database hacker-forum listing (47,300 staff) and Frontier Communications' April 2024 ransomware breach (750,000+ customer records) illustrate both sides of the exposure.
What regulators and experts are saying
Senior national security officials said the breach occurred in large part because telecommunications companies failed to implement rudimentary cybersecurity measures. Investigators found legacy equipment not updated in years, router vulnerabilities with patches available for seven years that were never applied, and hackers acquiring credentials through weak passwords.
Telecom networks are a high-priority target, one that's in the bull's-eye of nation-state programs. We believe this one is for espionage, but potentially for disruption at a time of crisis or conflict as well.
To date, telecom companies infiltrated in the attack have failed to prove the Chinese hackers have been eradicated from their networks… Experts agree that the attack has not been fully remediated from telecommunications networks, and the FCC's ruling concedes that vulnerabilities are still being exploited.
TSRMP Rules are now live
The telecommunications security regime under the SOCI Act commenced 4 April 2025, with CIRMP obligations for existing nominated telco assets in force since 4 October 2025 across an expanded asset scope
Telecommunications carriers and carriage service providers are subject to the SOCI Act CIRMP obligations as critical infrastructure entities. The CIRMP must address four hazard vectors: cyber and information security, personnel, supply chain, and physical security. For the cyber hazard vector, entities must adopt one of five approved frameworks — ASD Essential Eight, NIST CSF, ISO/IEC 27001, C2M2, or AESCSF. The former Telecommunications Sector Security Reforms (TSSR) have been replaced by the TSRMP Rules 2025, which align with the SOCI CIRMP structure. Carriers must also comply with carrier licence conditions and obligations under the Telecommunications Act 1997.
Federal legislation covering telecommunications as a critical infrastructure sector. Since April 2025, the TSRMP Rules moved telco obligations from the Telecommunications Act into the SOCI Act. Carriers and CSPs must maintain a CIRMP addressing four hazard vectors: cyber, personnel, supply chain, and physical security. NodeZero directly validates controls under the cyber hazard vector across CPE, OSS/BSS, and cloud infrastructure. For the cyber vector specifically, entities must also adopt one of five approved frameworks which define the detailed technical controls.
Prescriptive and technically focused. Eight specific mitigation strategies with clear pass/fail controls. Common for government-adjacent entities, defence industry, and smaller organisations adopting ASD guidance.
Where NodeZero appliesBroad lifecycle coverage from governance through recovery without mandating specific technologies. Suited to entities operating across jurisdictions or mapping existing controls into a flexible structure.
Where NodeZero appliesInternational management system standard with formal certification. Chosen by larger entities with mature security programs, international operations, or existing ISO certification investment.
Where NodeZero appliesMaturity model assessing organisational capability across 10 domains. Originally built for the US electricity sector. Process and governance oriented -- less about specific controls, more about repeatable capability.
Where NodeZero appliesSector-specific to energy. Derived from C2M2 and NIST CSF with Australian privacy additions. Managed by AEMO. The default for electricity and gas market participants with OT/ICS environments.
Where NodeZero appliesTelcos hold extensive customer personal information including call records, location data, and account details subject to the Australian Privacy Principles and the Telecommunications Act data retention regime.
Where NodeZero appliesRelevant for telcos providing managed services, cloud connectivity, or hosted solutions to enterprise and government customers.
Where NodeZero appliesApplies to telecommunications providers processing customer billing and payment card transactions.
Where NodeZero appliesMandatory ransomware reporting for telecommunications carriers and carriage service providers as critical infrastructure entities.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
TSRMP Rules 2025 (asset scope expansion)
4 Apr 2025Part 14 of the Telecommunications Act has been repealed. All telco security obligations now sit under the SOCI Act via CIRMP. Asset scope has expanded to include CPE, OSS/BSS, cloud infrastructure, IT support systems, and third-party integrations — adding thousands of assets to compliance scope.
Cyber Security Act 2024 (ransomware reporting)
30 May 2025Mandatory ransomware payment reporting to ASD within 72 hours for all entities with $3M+ annual turnover. Telecommunications carriers are high-value ransomware targets due to network criticality and service continuity pressure. Dual reporting obligations apply — both TSRMP and Cyber Security Act.
Cyber Incident Review Board
30 May 2025Independent review board can examine significant cyber incidents affecting critical infrastructure, with statutory power to require information and documents. Telecommunications operators should be able to reconstruct control failures for a potential no-fault post-incident review.
Smart Device Security Standards
4 Mar 2026Mandatory minimum cyber security standards for internet-connected devices sold or distributed in Australia. Telecommunications operators managing CPE and IoT networks must audit device inventory, replace non-compliant equipment, and validate firmware update mechanisms.
CIRMP maturity uplift
Jun 2026The Enhanced CIRMP Rules 2026, registered 9 June 2026, lift the minimum cyber-framework maturity to level 2 across nine critical infrastructure asset classes, phasing in over 24 months to June 2028. Telecommunications assets sit under the parallel TSRMP rules — but the regulatory direction on maturity floors is the same. NodeZero provides attack-based evidence that an uplifted posture actually holds.
Government intervention powers
20 Dec 2024Enhanced Response and Prevention Act 2024 allows the Minister for Home Affairs to issue directions to operators with "seriously deficient" security programs. Directions can mandate specific control implementations with defined compliance windows and penalties for non-compliance.
Find your organisation
See how the changes affect you specifically
Carriers & CSPs
Major and regional carriers facing TSRMP compliance, 5G cloud core validation, and expanded SOCI Act obligations across critical national infrastructure.
View details →ISPs & wholesale providers
Regional ISPs, wholesale providers, and NBN access seekers needing cost-effective continuous security validation without dedicated red teams.
View details →Managed service providers
MSSPs, systems integrators, and managed service providers delivering security services to telecommunications clients across the ANZ market.
View details →The only autonomous pentesting platform that is:
Validate your compliance posture before regulators do
See how NodeZero tests across the expanded TSRMP asset scope in your environment

