1917
British cable ship Telconia severed Germany's direct transatlantic subsea cables at the outbreak of WWI, forcing German diplomatic messages onto neutral cables transiting British landing stations where Room 40 intercepted the Zimmermann Telegram.
1986
Astronomer Clifford Stoll traced a 75-cent accounting error at Lawrence Berkeley Lab to a hacker in Hannover, Germany using international X.25 network gateways to spy for the Soviet KGB.
1995
Tsutomu Shimomura and the FBI tracked and arrested Kevin Mitnick in Raleigh, North Carolina using direction-finding antennas and cellular switchboard real-time ESN/MIN location triggers.
1997
Underground syndicates commercialized "Clone King" EPROM modification kits, allowing widespread cellular subscription fraud and free international calls across North American carriers.
1998
Attackers spoofed ICMP Echo Requests to IP directed-broadcast addresses — including Portuguese academic backbones FCCN/RCTS — producing 100x amplification floods that downed victims' uplinks.
2004
Rogue software patches in Vodafone Greece's Ericsson AXE-10 switches activated dormant Lawful Interception capability to wiretap the Greek Prime Minister and 100+ senior officials during the 2004 Athens Olympics period.
2005
Hackers breached T-Mobile's backend web customer-care interface, gaining unauthorized access to Danger cloud servers and publishing private celebrity phonebooks, SMS logs, and photos.
2006
Court disclosures and Freedom of Information filings revealed the widespread deployment of commercial IMSI-catchers (Harris StingRay) by law enforcement and intelligence agencies to perform unauthenticated mobile tracking.
2011
Attackers breached Dutch Certificate Authority DigiNotar and issued 500+ rogue wildcard SSL certificates, which were deployed at the national Iranian telecommunications provider level to conduct a massive Man-in-the-Middle on 300,000+ Gmail users.
2013
British intelligence agency GCHQ compromised Belgian telecom provider Belgacom (Proximus) using Quantum Insert packet injection to intercept European Union and NATO mobile data roaming sessions.
2014
Symantec and Kaspersky exposed Regin, an extraordinarily sophisticated nation-state malware platform specifically engineered to infiltrate GSM cellular base station controllers and telecom routing cores.
2017
Cybercriminals abused SS7 roaming interfaces to intercept bank-issued SMS one-time passcodes (OTPs), draining accounts of customers at O2 Germany and Metro Bank UK.
2018
Cybereason revealed Operation Soft Cell, a massive multi-year cyber espionage campaign by suspected nation-state actors that completely compromised multiple telecommunications providers to exfiltrate raw subscriber Call Detail Records.
2019
CrowdStrike revealed that the LightBasin (UNC1945) APT had compromised 13+ global telecom operators since at least 2016 using custom GTP and SS7 tooling to masquerade as roaming infrastructure.
2019
AdaptiveMobile Security disclosed Simjacker, an exploit abusing legacy S@T Browser technology on SIM cards across 30+ countries to track subscriber location without user awareness.
2021
A global consortium of journalists revealed that NSO Group's Pegasus spyware had targeted 50,000+ phone numbers across 50 countries, utilizing zero-click SMS/iMessage parser vulnerabilities.
2021
Federal indictments exposed international cybercrime rings bribing retail store employees at AT&T, Verizon, and T-Mobile to execute unauthorized SIM swaps, stealing tens of millions of dollars in cryptocurrency.
2023
Threat intelligence researchers uncovered RedEye / ChamelGang deploying custom eBPF (Extended Berkeley Packet Filter) kernel rootkits directly inside telecom core network servers to intercept subscriber GTP data and signaling stealthily.
2024
Attackers executed an unauthorized SIM swap against the phone number tied to the US SEC official X account, broadcasting a fraudulent Bitcoin ETF approval that caused hundreds of millions in market swings.
2024
Chinese APT group Salt Typhoon breached the core networks of major US telecom providers — AT&T, Verizon, Lumen and others — reaching CALEA lawful-intercept systems and sustained metadata and audio collection across at least nine carriers.