2025 Ribbon Communications — nation-state intrusion; legacy customer files on laptops (Sep–Oct disclosure)
Data compromised
Limited legacy customer file sets; not characterized as full core network exfiltration
Technical writeup
Ribbon Communications, a U.S. telecom core and network-software supplier serving global carriers and government integrators, disclosed in late October 2025 SEC filings and follow-on press (Reuters, SecurityWeek, The Register, Dark Reading) that suspected nation-state actors accessed its IT network with initial activity as early as December 2024 and discovery in September 2025. The company described access to a small number of legacy customer files stored on two laptops segregated from core networks and notified a handful of customers, while broader Salt Typhoon–era telecom espionage discussions provided context.
Root cause
Nation-state–suspected intrusion; long-dwell espionage tradecraft per analysis
References
- https://www.reuters.com/business/media-telecom/us-company-with-access-biggest-telecom-firms-uncovers-breach-by-nation-state-2025-10-29/
- https://www.securityweek.com/major-us-telecom-backbone-firm-hacked-by-nation-state-actors/
- https://www.theregister.com/2025/10/29/major_telco_networking_provider_compromised/
- https://www.darkreading.com/cyberattacks-data-breaches/ribbon-communications-breach-latest-telecom-attack