← Ribbon Communications

2025 Ribbon Communications — nation-state intrusion; legacy customer files on laptops (Sep–Oct disclosure)

2025 Unknown records affected Share on X

Data compromised

Limited legacy customer file sets; not characterized as full core network exfiltration

Technical writeup

Ribbon Communications, a U.S. telecom core and network-software supplier serving global carriers and government integrators, disclosed in late October 2025 SEC filings and follow-on press (Reuters, SecurityWeek, The Register, Dark Reading) that suspected nation-state actors accessed its IT network with initial activity as early as December 2024 and discovery in September 2025. The company described access to a small number of legacy customer files stored on two laptops segregated from core networks and notified a handful of customers, while broader Salt Typhoon–era telecom espionage discussions provided context.

Root cause

Nation-state–suspected intrusion; long-dwell espionage tradecraft per analysis

References