Government hackers infiltrated Ribbon, a major telecom company, for an extended period before being discovered.

A recent disclosure by telecommunications giant Ribbon revealed that government-sponsored hackers managed to infiltrate the company’s network for nearly a year before being discovered. The firm indicated in a recent filing with the U.S. Securities and Exchange Commission that a suspected nation-state actor gained access to its IT network as early as December 2024. Ribbon took action by notifying law enforcement and believes that the hackers are no longer present in its network.

Based in Texas, Ribbon offers phone, networking, and internet services to various companies, enterprises, and critical infrastructure entities, including energy and transportation systems. Among its clientele are numerous Fortune 500 companies and government agencies, such as the Department of Defense. While three of Ribbon’s customers were affected by the breach, the company has opted to protect their identities under confidentiality protocols.

Although it remains uncertain whether the hackers extracted personally identifiable information or other confidential data from corporate customers during the breach, Ribbon’s disclosure mentioned that some customer files residing outside of the primary network on two laptops were accessed by the threat actor. The company promptly informed the affected customers about the incident. Despite being part of a concerning trend involving telecom providers succumbing to cyberattacks in recent years, Ribbon has refrained from attributing the breach to a specific government entity when quizzed by TechCrunch reporters.

In the past, hackers with ties to China targeted and compromised over 200 U.S.-based companies, including telecommunications and internet service providers, aiming to pilfer phone records and calling data linked to senior U.S. government officials. Notable telcos like AT&T, Verizon, and Lumen were confirmed to have fallen victim to this campaign, alongside prominent cloud service providers and data center operators. Some targeted companies were located beyond U.S. borders, with Canada also witnessing similar incursions.

Salt Typhoon, the hacking collective affiliated with China, represents one of many factions sponsored by the Asian nation and allegedly intent on surveilling the U.S. and its allies as part of a scheme aimed at preparing for a potential Chinese incursion into Taiwan, as per statements from U.S. government officials.

Ribbon’s spokesperson, Catherine Berthier, opted not to disclose further details concerning the ongoing investigation when approached by TechCrunch. It is a continuous struggle for companies in the telecommunications sector to safeguard their networks against persistent cyber threats from state-sponsored actors. The evolving nature of such threats necessitates constant vigilance and proactive cybersecurity measures to prevent and mitigate the impact of cyber intrusions in the modern digital landscape.