

APT Campaigns – 7.5
25 of 70 campaigns (36%), up from 15 in absolute terms as the pool nearly tripled. Broadest actor set of any sector this period. Salt Typhoon and Volt Typhoon both present, documented for long-dwell pre-positioning in telecom infrastructure. Routers, firewalls, and CDNs targeted, pointing to traffic visibility over data theft.
Cyber Incidents – 7.6
41 incidents, 5th of 14, with quantified subscriber loss across Charter, RingCentral, and Japanese providers exceeding 30 million records combined. Account takeover was the leading technique at nine instances. China and Russia split state attribution evenly, with a July multi-agency advisory naming edge-device exploitation.
Dark Web Chatter – 7.6
1,985 mentions, 2nd of 14 at 10.74%. Breach and leak chatter rose while nearly every other sector declined during the same forum disruption window, indicating genuine targeting rather than artefact. Disruption categories collapsed as data categories climbed, a shift toward quiet acquisition.
Vulnerabilities – 7.3
396 mentions, 3rd of 14 at 11.18%. RCE tripled and held, against edge equipment that is internet-facing by design. XSS rose uninterrupted, connecting to the account takeover activity seen in incidents. Network firmware patch cycles leave exposure open well past disclosure.
Ransomware – 4.8
63 victims, down 8.7% Q-on-Q, 12th of 14. Country spread contracted from 30 to 22. 29% gang participation, with volume leaders showing low sector share. Publishing and Digital Media account for nearly half of victims.
The CYFIRMA Industry Report delivers original cybersecurity insights and telemetry-driven statistics of global industries, covering one sector each week for a quarter. This report focuses on the telecommunications & media sector, presenting key trends and statistics in an engaging infographic format.
Welcome to the CYFIRMA infographic industry report, where we delve into the external threat landscape of the telecommunications & media industry over the past three months. This report provides valuable insights and data-driven statistics, delivering a concise analysis of attack campaigns, public reports, underground & dark web chatter, vulnerabilities, and ransomware incidents targeting telecommunications & media organizations.
We aim to present an industry-specific overview in a convenient, engaging, and informative format. Leveraging our cutting-edge platform telemetry and the expertise of our analysts, we bring you actionable intelligence to stay ahead in the cybersecurity landscape.
CYFIRMA delivers pre-emptive cybersecurity, cyber threat intelligence, and external threat landscape management through its platforms, DeCYFIR and DeTCT. These platforms have been purpose-built over many years to continuously collect, correlate, and analyse large volumes of external threat data, combining proprietary intelligence automation with deep, hands-on cyber threat research.
For the purpose of this report, the analysis draws on intelligence generated from CYFIRMA’s platforms. The data referenced has been processed through automated correlation and enrichment mechanisms, informed and validated by human-led research and investigative expertise, and sourced from both structured and unstructured external intelligence channels.
While this report contains data collected and processed by our in-house AI and ML, all charts, statistics, and analyses are done by human CYFIRMA CTI analysts to ensure the highest quality and provide accurate insights.
Telecommunications & media organizations appeared in 25 of the 70 active campaigns (36% of all campaigns), a significant jump from the previous period, when they appeared in 15 of 25 campaigns. However, this is down from 60% of observed campaigns.


APT activity targeting Telecommunications & media has been continuous. Most of the campaigns have been active and have updated with new detection as recently as August.

Observed APT campaigns are dominated by suspected China-linked, state-sponsored actors, with Stone Panda leading, followed closely by MISSION2074. Mustang Panda, Emissary Panda, Leviathan, Salt Typhoon, and Volt Typhoon provide additional representation, the latter two notable for their known focus on telecommunications infrastructure.
Russia-linked Gamaredon and Cozy Bear feature alongside North Korea-associated Lazarus Group and Iran-linked Fox Kitten, OilRig, and MuddyWater. Financially motivated actors TA505, FIN11, and FIN7 account for a meaningful share, alongside Turkish and Vietnamese cybercriminal groups.

Victim distribution spans 29 countries, with the United States, Japan, and the United Kingdom recording the highest victim counts, followed by India, South Korea, and Australia. The concentration across major telecommunications markets reflects targeting of network operators and media organizations with significant regional reach.
European presence is broad, with France, Germany, the Netherlands, Ukraine, Italy, Spain, Hungary, Portugal, Switzerland, and Belgium all recording victims, consistent with Russia-linked actor activity in the region. Middle Eastern presence is led by Saudi Arabia and the UAE, aligning with the Iran-linked actors observed this period.
Southeast Asian countries including the Philippines, Thailand, Vietnam, Singapore, Malaysia, Indonesia, and Cambodia appear regularly across observed campaigns, reflecting the region’s expanding telecommunications infrastructure.

Web applications and operating systems account for the majority of observed attacks this period. Application infrastructure software features prominently across seven campaigns, reflecting threat actor interest in the underlying platforms supporting telecommunications and media service delivery.
Database management software and VPN solutions also appear across multiple campaigns. Notably, routers, network monitoring tools, firewall software, firewall security management software, and content delivery networks all feature in the targeted technology profile, pointing to sustained interest in network-level access and traffic visibility consistent with the state-sponsored actors observed this period.

Based on observed trajectory across the two reporting periods, the telecommunications and media sector external threat landscape is expected to remain at High through the next 90 days. Campaign presence increased sharply from 15 to 25 in absolute terms, though the sector’s share declined from 60% to 36% as the overall campaign pool nearly tripled. The scale of absolute growth, combined with the breadth of nation-state actors involved, supports a forward posture of continued high-tempo targeting.
Sustained volume: Campaign presence grew from 15 out of 25 to 25 out of 70 observed campaigns period over period. The monthly distribution reflects platform updates and detection stacking patterns rather than genuine gaps, with most campaigns remaining active and receiving new detections as recently as August. 22 to 28 telecommunications and media sector campaigns over the next 90 days is a plausible baseline estimate.
Dominant actor continuity: Stone Panda and MISSION2074 recorded the highest campaign counts and show no indicators of reduced tempo. The presence of Salt Typhoon and Volt Typhoon is particularly significant given their documented focus on telecommunications network infrastructure and long-dwell pre-positioning operations.
Network infrastructure exposure: Routers, network monitoring tools, firewall software, and content delivery networks appearing alongside application infrastructure and VPN solutions point to threat actor interest in network-level access, traffic interception, and persistent visibility rather than data theft alone. Operators with unpatched edge infrastructure and exposed management interfaces face the highest immediate risk.
Geographic targeting: The United States, Japan, and the United Kingdom lead in victim count, with India, South Korea, and Australia also heavily represented. North America, the Indo-Pacific corridor, and Western Europe are expected to remain primary target zones, with continued exposure across expanding Southeast Asian telecommunications markets.
Multi-actor threat profile: China-linked, Russia-linked, North Korean, Iranian, Pakistani, and financially motivated actors all feature this period, alongside Turkish and Vietnamese cybercriminal groups. Defenders should prioritize TTP-based detection over actor-specific IOC tracking given the breadth of actor representation and the overlap in targeted network infrastructure.
Over the past 90 days, DeCYFIR and DeTCT platforms tracked 680 cyber incidents reported publicly. We could identify the industry for 565 of these incidents (75%).
The telecommunications & media industry was detected in 41 incidents, which equals 6.03% of the incidents where we knew the industry, ranking 5th out of 14 industries.

Account takeover is the leading technique with 9 items, ahead of phishing at 6. It shows up as SIM-swapping in Poland, more than 20,000 Instagram accounts stolen through abuse of Meta AI support, Telegram and Snapchat hijacking, and an FBI warning on 12 August about social engineering against personal accounts.
Customer data is the main asset being lost. Charter confirmed 4.85 million accounts in late May, RingCentral 1.6 million on 13 August, both attributed to ShinyHunters, which is the only repeat actor at 5 items. Japanese providers lost up to 14.2 million email logins across six ISPs on 28 June and a further 12 million at a major telco on 7 July.
State activity is real and evenly split. China and Russia each account for 4 attributed items. The 14 July joint advisory from CISA, NSA, FBI and international partners names Russian targeting of communications and energy through edge-device exploitation. On the Chinese side, APT groups shared a Linux backdoor against Central Asian telcos in May, and a House committee reported on 5 August that Chinese carriers keep a deep US presence despite Salt Typhoon links. NSO Group appears once, via WhatsApp, disrupting Pegasus phishing on 8 June.

Account takeover was the dominant technique, appearing consistently across all three periods and accounting for the largest share of identified activity. Malicious app deployments appeared three times, concentrated entirely in the last 30 days, suggesting an emerging delivery vector. Phishing appeared across the previous and last 30 days, while DDoS activity was spread across the first and last 30 days. Supply chain attack, spear-phishing, insider threat, and social engineering each appeared once. The persistence of account takeover across all periods indicates sustained credential-focused targeting, while the emergence of malicious apps in the last 30 days is worth monitoring.

China and Russia were the most frequently identified attacking countries, each appearing in multiple incidents. The United States, Israel, and the Netherlands each appeared once as attacking entities. Victim attribution was more complete, with the United States as the primary target, followed by Japan, where up to 26 million email and account credentials were lost across two separate provider breaches. Angola, Taiwan, Ukraine, and several European countries each recorded isolated cases. Russia and the Netherlands both appeared as attacker and victim, reflecting bidirectional exposure in those countries.
Account takeover is the defining technique, not intrusion. Account takeover appears 9 times, ahead of phishing at 6 and malicious apps at 3. The pattern repeats across subscriber accounts, social platforms and messaging services: SIM-swapping in Poland tied to millions in crypto theft, more than 20,000 Instagram accounts stolen by abusing Meta AI support, a Telegram channel compromise reached through email, Snapchat account hijacking, and an FBI warning on 12 August about social engineering used to breach accounts and steal explicit content. For an operator, this matters twice, because it is both a fraud loss and the mechanism by which its subscribers lose access to every other service secured by a phone number.
Customer data is the primary asset being taken. Charter confirmed a breach on 26 May, with 4,851,517 accounts later quantified and attributed to ShinyHunters. RingCentral disclosed 1,596,490 accounts on 13 August, again ShinyHunters. Japanese providers account for two further large losses, up to 14.2 million email logins across six ISPs on 28 June and 12 million at a major telco on 7 July. ShinyHunters is the only actor appearing repeatedly, in 5 of 41 items, and its activity is opportunistic mass extortion rather than sector-specific targeting.
State-linked targeting of communications infrastructure is confirmed and multi-source. On 14 July, CISA, the NSA, the FBI, DC3 and international partners issued a joint warning on Russian activity targeting communications and energy, with exploitation of edge devices named as the technique. Ukrainian media outlets were designated priority targets for Russian operators on 6 July, and New Zealand sanctioned Russian hacking and propaganda groups on 10 August. On the Chinese side, APT groups were found sharing a Linux backdoor in attacks on Central Asian telecoms in May, using tooling reported as Showboat and JFMBackdoor, and a US House committee reported on 5 August that Chinese carriers retain a deep US presence despite Salt Typhoon links. Taiwan charged two businessmen over a Chinese espionage campaign on 8 July. Attacker attribution splits evenly at 4 items each for China and Russia.
Commercial spyware and insider risk both appear. WhatsApp disrupted new NSO Group spyware phishing on 8 June, the only Pegasus-linked item in the period. Dutch police traced the Odido telecom attack to a suspected local accomplice on 9 July, the sole insider-threat case in the sector and a reminder that operator-side access is a target in its own right.
Availability attacks are present but not dominant. DDoS disrupted the Threema secure messaging service on 16 August, and HTTP/2 bomb attacks were flagged on 15 June as a risk to telecom and healthcare operators. A Japanese anime streaming service was disrupted in an attack that led to an arrest on 6 July.
Media-side risk is regulatory and reputational as much as technical. The period includes the UK TikTok age-verification investigation, DOJ seizure of deepfake sites under the TAKE IT DOWN Act, a disinformation campaign alleged by Georgia, and a ransomware group hijacking a hospital’s Facebook page to amplify pressure during an incident. Platform accounts are being used as an extortion channel, not only as a breach target.

Subscriber-data extortion will remain the most likely realised loss. ShinyHunters-style mass extortion has now hit two large US operators in the period and shows no sign of slowing. Operators should assume customer databases, not networks, are the target and should expect disclosure obligations to drive the cost.
Account takeover and SIM-swap fraud will continue to rise. The technique count already leads the sector; law enforcement action in Poland removed one group but not the model, and AI-assisted support-channel abuse of the kind used against Meta gives attackers a scalable social engineering route into account recovery.
Russian and Chinese targeting of communications infrastructure will persist. The July joint advisory names edge-device exploitation, which points to routers, VPN concentrators and management interfaces rather than core network elements. Operators carrying government, defence or energy traffic are inside the stated targeting set.
Media organisations in or adjacent to conflict zones face elevated targeting. Ukrainian outlets were explicitly designated priority targets, and disinformation operations are now being reported alongside intrusions rather than separately.
Expect further supply chain exposure through advertising and content delivery. The Adform script compromise on 31 July, which pushed a clipboard hijacker through an ad network, shows that media distribution infrastructure is an efficient delivery channel and is likely to be reused.
Over the past 90 days, CYFIRMA’s telemetry has identified 1,985 mentions of telecommunications & media organizations out of a total of 18,490 industry-linked mentions. This is from a total of 300k+ posts across various underground and dark web channels and forums.
Telecommunications & media organizations placed in shared 2nd place out of 14 industries in the last 90 days, with a share of 10.74% of all detected industry-linked chatter.
Below is a breakdown by 30-day periods of all mentions.


Underground & dark web chatter related to the telecommunications & media sector over the last 90 days is dominated by data breach and data leak discussions, both of which increase sharply after the first period and remain elevated through the final period. This runs counter to the declining pattern observed across most other sectors in this report, where breach and leak volumes fell in line with forum disruption and migration dynamics. Ransomware mentions decline gradually across all periods. DDoS collapses in the final period after mid-period elevation, while claimed hacks and hacktivism decline consistently throughout the window. Web exploits remain stable at comparatively low volumes.

Telecommunications & media carries one of the highest chatter volumes across all sectors in this report and is one of the few where breach and leak discussion increased substantially rather than declined over the window. The sector sits upstream of nearly every other industry as an infrastructure and connectivity provider, meaning compromise propagates outward rather than staying contained. The divergence from the sector-wide declining trend is the primary driver of the high score.
Data Breach and Data Leak: Both increase several-fold after the first period and hold at elevated levels through the final period. Telecom and media organisations hold subscriber records, call and messaging metadata, authentication data, and network access credentials, which retain high resale value in underground markets. That these volumes rose while most other sectors declined during the same forum disruption window indicates genuine sustained targeting rather than a monitoring artefact.
Subscriber Data and SIM-Linked Fraud: Telecom subscriber data supports downstream SIM swap and account takeover activity against banking, cryptocurrency, and enterprise identity systems. Elevated breach and leak chatter in this sector is therefore a leading indicator of fraud activity in other sectors, not only a risk to telecom operators themselves.
Ransomware: Consistent gradual decline across all three periods. Ransomware is not the dominant threat vector for this sector currently, with attacker focus concentrated on data acquisition and resale rather than encryption and extortion. Targeted attacks against broadcast and network operations continuity remain plausible given low tolerance for service interruption.
DDoS, Hacktivism and Claimed Hacks: All three drop to near zero in the final period, with DDoS falling from its mid-period peak and hacktivism and claimed hacks declining steadily throughout. The simultaneous collapse across all three disruption and claim-based categories, while breach and leak chatter climbs, points to a shift in attacker focus from visible disruption toward quiet data acquisition rather than reduced overall interest in the sector.
Web Exploit: Stable and low across all periods. Limited web exploit chatter in a sector with this level of confirmed breach activity more likely reflects initial access already established rather than reduced interest, and lateral movement indicators are a more useful detection focus than perimeter probing.
Over the past 90 days, CYFIRMA’s telemetry has identified 396 mentions of telecommunications & media organizations out of a total of 3,543 industry mentions. This is from over 10k CVEs reported and updated in the last 90 days.
Telecommunications & media organizations ranked 3rd out of 14 industries in the last 90 days with a share of 11.18% of all detected industry-linked vulnerabilities.
Below is a breakdown by 30-day periods of all mentions.


Remote and arbitrary code execution vulnerabilities dominate reported CVEs in the telecommunications & media sector over the last 90 days, with a sharp rise after the first period and sustained elevation. Cross-site scripting vulnerabilities consistently increase, tripling from initial levels. Denial of service and injection attacks spike mid-period before declining, though denial of service remains above initial levels. Memory and buffer vulnerabilities rise after the first period and remain steady. Privilege escalation shows a modest but consistent increase, while information disclosure, directory traversal, security misconfigurations, and cryptographic weaknesses remain minimal.

Telecommunications & media carries one of the highest concentrations of reported vulnerabilities across all sectors. Disclosure volume sharply rises after the first period and remains elevated, with Remote & Arbitrary Code Execution (RCE) being the dominant category. This sector’s role as connectivity infrastructure for other industries means sustained exposure has downstream consequences beyond telecom operators.
RCE is the dominant category, tripling after the first period and holding steady. Direct compromise potential against routing infrastructure, subscriber management platforms, broadcast systems, and network edge equipment is the primary CVE-driven risk. Edge and perimeter devices in telecom environments are often internet-facing, shortening the window between disclosure and exploitation.
Cross-Site Scripting (XSS) shows an uninterrupted upward trend, tripling over the window. This is relevant given the sector’s volume of subscriber-facing web portals, account management interfaces, and media distribution platforms, where client-side compromise supports credential theft and account takeover at scale.
Denial of Service (DoS) has a mid-period spike followed by a partial decline, with final-period levels well above the initial baseline. In a sector where service availability is the product, DoS-enabling vulnerabilities carry disproportionate operational and contractual risk relative to their disclosure volume.
Memory & Buffer Vulnerabilities rise sharply after the first period and remain steady through the final period. Memory vulnerabilities in this sector often affect network equipment firmware and embedded telecom components, which have longer patch cycles than enterprise software and leave exposure windows open well past disclosure.
Injection attacks spike mid-period and decline toward initial levels, while privilege escalation rises steadily. Combined with sustained RCE exposure, privilege escalation poses a risk of lateral movement after initial compromise.
Telecom and media infrastructure underpins connectivity across sectors. Vulnerabilities in routing, transit, and subscriber authentication systems expose downstream organisations that have no visibility into or control over the affected components, making disclosure volume in this sector a shared rather than contained risk.
In the past 90 days, CYFIRMA has identified 63 verified ransomware victims in telecommunications & media organizations. This accounts for 2.55% of all 2,469 ransomware victims during the same period, placing this sector 12th out of 14 industries.

Furthermore, a quarterly comparison shows that the number of victims in telecommunications & media organizations has been sustained. It went from 69 to 63 victims, an 8.7% decline. The overall interest, represented by share, however, declined more significantly from 2.93% to 2.55% of all victims.


Monthly activity peaked in January at 31 victims before dropping sharply in February. Activity recovered through March and held steady in the low-to-mid 20s across spring and early summer, rising again to 27 in July. August reflects only the first half so far.

Activity shifted notably across the three-month period. Thegentlemen and Shinyhunters drove the June and July volume, with Qilin building steadily from two victims in June to four in July and a further four in early August. Play, Akira, and DragonForce contributed consistently across multiple months.
Section9 and Global Secret Group appeared only in July, while several groups including Icarus, Chaos, Spacebears, and BrainCipher recorded single victims in June then dropped out. August reflects a partial period, though Qilin’s continued activity alongside new entrants Panzer, Settra, Kairos, L Group, and Clop suggests the actor set is still rotating.

Out of the 99 gangs, 29 recorded victims in the telecommunications & media industry in the last 90 days, representing a 29% participation.
Qilin and Thegentlemen had the highest numbers of victims, but both recorded low shares of their overall activity in this industry, at 3.2% and 2.4% respectively.
Booba (50.0%), Lapsus$ (16.7%), and Section9 (15.0%) stand out as the gangs with the highest shares of telecommunications and media victims, though the first two are low-volume gangs.
On average, gangs active in this industry recorded a 7.4% share of their victims from this industry. That is about 1 in 13 victims.

Publishing and Digital Media & Content Platforms accounted for the largest share of victims by a clear margin, reflecting the concentration of proprietary content, subscriber records, and advertising data these organizations hold. Advertising & Media Agencies and Telecom Infrastructure Providers each recorded meaningful activity, showing targeting across both the media and telecommunications sides of the sector.
Fixed-line telecommunications, ISPs, and broadcasting saw fewer incidents, while equipment manufacturers, mobile network operators, and production studios recorded only isolated cases. The spread across every tracked subsector points to opportunistic targeting rather than a focused campaign against any single segment.

The geographic distribution heatmap underscores the widespread impact of ransomware, highlighting the countries where victims in this industry have been recorded.

Telecommunications & media victimology shows the USA being the most targeted, accounting for 40% of all victims.
Remaining activity is distributed among 21 countries for 38 victims.
Brazil, Italy, India, and Thailand recorded the highest elevations in the last 90 days.
Poland, Japan, the Netherlands, and Morocco saw the largest declines.
In the last 90 days, 22 countries recorded telecommunications & media victims, 8 fewer than the 30 countries in the previous period.

The Telecommunications & Media sector threat landscape is expected to remain at moderate through the next 90 days. Victim volume declined 8.7% quarter-on-quarter from 69 to 63, and the sector’s share of all ransomware victims fell more sharply from 2.51% to 1.70%, placing it 12th of 14 tracked industries. The sector is not a priority target for most active groups, though the concentration of victims in publishing and digital media points to sustained interest in content and subscriber data.
Volume outlook: Monthly activity has oscillated within a stable band since March, holding between 21 and 27 victims per month with no sustained directional trend. The January peak of 31 and the February trough of 14 appear to be outliers rather than turning points. A baseline of 60 to 70 victims over the next 90 days is the most plausible outcome given this demonstrated stability.
Actor behaviour: 29 of 99 active gangs recorded telecommunications and media victims, a 29% participation rate indicating moderate but not concentrated interest across the actor set. Qilin and Thegentlemen led by volume while devoting only a small fraction of their overall activity to this sector, consistent with opportunistic selection. Section9 shows the highest proportional focus among meaningful-volume gangs at 15%, making it the group most likely to sustain deliberate targeting. The rapid rotation of single-appearance groups across months suggests continued volatility in which actors drive monthly totals.
Geographic concentration: The USA strengthened its position as the dominant target, rising from 23 to 25 victims and now accounting for 40% of the sector total. Geographic spread contracted sharply from 30 to 22 countries, the clearest concentration trend visible in the current period. Brazil, Italy, India, and Thailand were the only notable gainers, while European coverage thinned considerably with Poland, the Netherlands, and several smaller markets dropping out entirely.
Subsector risk: Publishing and Digital Media & Content Platforms together account for nearly half of all sector victims, reflecting their combination of monetisable subscriber data and low tolerance for publication disruption. This concentration is unlikely to shift materially in the near term.
APT Campaigns (High): Telecommunications & media featured in 25 of 70 observed campaigns (36%), up sharply from 15 in absolute terms, with share declining from 60% only because the total campaign pool nearly tripled. The actor set is the broadest observed in any sector this period, spanning Chinese, Russian, North Korean, Iranian, and financially motivated groups alongside Turkish and Vietnamese cybercriminals. Stone Panda led campaign counts, followed by MISSION2074, though the more consequential presence is Salt Typhoon and Volt Typhoon, both documented for long-dwell pre-positioning inside telecommunications infrastructure. The targeted technology profile is network-level throughout, with routers, firewalls, network monitoring tools, VPN solutions, and content delivery networks all featuring, pointing to traffic interception and persistent visibility rather than data theft alone.
Reported Cyber Incidents (High): 41 incidents recorded, ranking 5th of 14, with subscriber data as the primary asset lost. Charter confirmed 4.85 million accounts and RingCentral 1.6 million, both attributed to ShinyHunters, while Japanese providers lost up to 26 million email and account credentials across two separate events. Account takeover was the leading technique at nine instances, appearing as SIM swapping, mass Instagram theft through abuse of AI support channels, and messaging platform hijacking. State activity split evenly between China and Russia at four attributed items each, with a 14 July joint advisory from CISA, the NSA, the FBI and international partners naming Russian exploitation of edge devices against communications infrastructure. Malicious app deployments emerged entirely within the final 30 days.
Underground & Dark Web Chatter (High): The sector placed 2nd of 14 at 10.74% of all industry-linked chatter. Breach and leak discussion rose several-fold after the first period and held elevated, running directly counter to the declining pattern seen across nearly every other sector during the same forum disruption window, which indicates genuine sustained targeting rather than a visibility artefact. DDoS, hacktivism, and claimed hacks all collapsed toward zero in the final period while breach chatter climbed, a divergence consistent with a shift from visible disruption toward quiet data acquisition. Elevated telecom breach chatter functions as a leading indicator for SIM swap and account takeover fraud in banking and enterprise identity systems, making this a shared rather than contained risk.
Vulnerabilities (High): The sector ranked 3rd of 14 at 11.18% of industry-linked disclosures across 396 mentions. RCE tripled after the first period and held steady, landing against routing infrastructure, subscriber management platforms, and network edge equipment that is internet-facing by design, which compresses the interval between disclosure and exploitation. XSS rose uninterrupted across the window, relevant given the volume of subscriber-facing portals and account management interfaces, and connecting directly to the account takeover activity observed in reported incidents. Memory and buffer vulnerabilities affect network firmware with patch cycles longer than enterprise software, leaving exposure windows open well past disclosure.
Ransomware (Moderate): 63 victims, down 8.7% from 69, ranking 12th of 14. Monthly activity has oscillated within a stable band since March, holding between 21 and 27 with a July rise, and the January peak and February trough appear to be outliers rather than turning points. Publishing and Digital Media & Content Platforms together account for nearly half of all sector victims. Gang participation was 29%, with Qilin and Thegentlemen leading by volume while devoting small fractions of their overall activity to the sector. Geographic spread contracted sharply from 30 to 22 countries while the USA strengthened to 40% of the sector total.