1918
German engineer Arthur Scherbius filed patents for the Enigma rotor cipher machine, aiming to secure commercial and diplomatic telecommunications against wiretapping and line interception.
1943
Bell Labs and Alan Turing developed SIGSALY (Project X), the world's first digital voice encryption terminal, securing high-level Allied communications between Washington and London during WWII.
1982
Judge Harold Greene ordered the breakup of AT&T's monopoly into 7 Regional Bell Operating Companies (Baby Bells), creating multi-operator interconnects and new signaling boundaries.
1994
The Communications Assistance for Law Enforcement Act (CALEA) forced US telecom carriers to design their networks so that lawful interception could be performed on demand — embedding a permanent surveillance capability into the core of every switch.
1997
Underground syndicates commercialized "Clone King" EPROM modification kits, allowing widespread cellular subscription fraud and free international calls across North American carriers.
1998
Attackers spoofed ICMP Echo Requests to IP directed-broadcast addresses — including Portuguese academic backbones FCCN/RCTS — producing 100x amplification floods that downed victims' uplinks.
2005
Hackers breached T-Mobile's backend web customer-care interface, gaining unauthorized access to Danger cloud servers and publishing private celebrity phonebooks, SMS logs, and photos.
2012
The US House Permanent Select Committee on Intelligence published a bipartisan investigative report concluding that Huawei and ZTE equipment posed systemic national security risks to critical telecom backbones.
2017
Cybercriminals abused SS7 roaming interfaces to intercept bank-issued SMS one-time passcodes (OTPs), draining accounts of customers at O2 Germany and Metro Bank UK.
2017
The FCC and ATIS/SIP Forum finalized the STIR/SHAKEN framework, mandating cryptographic digital signature validation on SIP interconnects to combat caller ID spoofing and fraudulent robocalls.
2019
The GSM Association launched its formal Coordinated Vulnerability Disclosure (CVD) program and Hall of Fame, establishing standard operating procedures for researchers to responsibly report 2G–5G protocol and core vulnerabilities.
2021
Federal indictments exposed international cybercrime rings bribing retail store employees at AT&T, Verizon, and T-Mobile to execute unauthorized SIM swaps, stealing tens of millions of dollars in cryptocurrency.
2024
Attackers executed an unauthorized SIM swap against the phone number tied to the US SEC official X account, broadcasting a fraudulent Bitcoin ETF approval that caused hundreds of millions in market swings.
2025
The European Union began strict enforcement of the NIS2 Directive, classifying telecommunications carriers, Internet Exchange Points (IXPs), DNS service providers, and subsea cable landing stations as Essential Entities with mandatory 24-hour incident notification and personal executive liability.