1837
Francois and Joseph Blanc hijacked the French optical telegraph network by bribing operators to insert deliberate backspace/error codes into stock market transmissions. The scheme ran for roughly two years before being exposed in 1836, making it the first documented attack combining an insider, a covert channel, and a financial network.
1844
Samuel Morse transmitted the first message ("What hath God wrought") over the Baltimore–Washington line on May 24, 1844, exposing physical wiretapping along unencrypted DC lines almost immediately.
1850
John & Jacob Brett laid the first subsea cable across the English Channel between Dover and Calais, connecting the British and French telegraph networks on August 28, 1850.
1876
Alexander Graham Bell was granted US Patent 174,465 for the telephone, introducing analog voice circuits that immediately opened new attack surfaces for inductive and galvanic eavesdropping.
1891
Undertaker Almon Strowger patented the first automated stepping switch after suspecting manual telephone operators were diverting his business calls to a competing undertaker.
1903
Illusionist and wireless pioneer Nevil Maskelyne intercepted and injected sarcastic Morse code insulting Guglielmo Marconi during a live demonstration at the Royal Institution in London, proving that open radio channels lacked origin authentication.
1917
British cable ship Telconia severed Germany's direct transatlantic subsea cables at the outbreak of WWI, forcing German diplomatic messages onto neutral cables transiting British landing stations where Room 40 intercepted the Zimmermann Telegram.
1918
German engineer Arthur Scherbius filed patents for the Enigma rotor cipher machine, aiming to secure commercial and diplomatic telecommunications against wiretapping and line interception.
1943
Bell Labs and Alan Turing developed SIGSALY (Project X), the world's first digital voice encryption terminal, securing high-level Allied communications between Washington and London during WWII.
1956
TAT-1 (Transatlantic No. 1) was inaugurated between Oban, Scotland and Clarenville, Newfoundland, providing 36 simultaneous telephone circuits and replacing erratic HF radiotelephone links.
1957
Seven-year-old blind boy Joe Engressia discovered that whistling an exact 2600 Hz pitch into a receiver reset AT&T toll trunk lines, founding the phone-phreaking movement.
1964
John Draper ("Captain Crunch"), Steve Wozniak, Steve Jobs and others built Blue Boxes that emitted 2600 Hz plus MF digit tones to make free global calls, industrializing the SF signaling flaw.
1971
US Navy & NSA divers wrapped a 6-ton inductive recording pod around a submerged Soviet military cable in the Sea of Okhotsk, capturing traffic for nearly a decade.
1972
Ron Rosenbaum published 'Secrets of the Little Blue Box' in Esquire, exposing the technical mechanics of 2600 Hz phone phreaking, Captain Crunch, and homebrew Blue Box construction to a global audience.
1976
AT&T deployed Common Channel Interoffice Signaling (CCIS) across its toll network, separating call control signaling into a dedicated data network and neutralizing acoustic blue box toll fraud.
1978
Phreakers engineered specialized Red Boxes simulating payphone coin drop frequencies (1700 Hz + 2200 Hz) and Silver Boxes with modified DTMF keypads to seize military Autovon priority override circuits.
1982
Judge Harold Greene ordered the breakup of AT&T's monopoly into 7 Regional Bell Operating Companies (Baby Bells), creating multi-operator interconnects and new signaling boundaries.
1983
Ameritech launched the first commercial 1G AMPS cellular network in Chicago, but cleartext transmission of ESN and MIN identifiers quickly led to widespread over-the-air cellular cloning.
1986
John R. MacDougall overpowered HBO's satellite broadcast feed with a 2,000-watt transmitter to protest unscrambling subscription fees, exposing commercial satellite uplink vulnerabilities.
1986
Astronomer Clifford Stoll traced a 75-cent accounting error at Lawrence Berkeley Lab to a hacker in Hannover, Germany using international X.25 network gateways to spy for the Soviet KGB.
1987
An unknown pirate broadcaster overpowered the terrestrial microwave Studio-Transmitter Links (STL) of WGN-TV and PBS station WTTW in Chicago, broadcasting distorted Max Headroom audio and video into thousands of homes.
1988
CCITT standardized the SS7 protocol suite in 1988 across mobile and fixed networks, built on implicit operator trust with no authentication — the root cause of every later signaling attack.
1988
TAT-8 became the first transoceanic fiber-optic cable in service, scaling transatlantic telecommunications capacity to 40,000 circuits and revolutionizing global data connectivity.
1990
A single line of buggy C code in a 4ESS switch patch caused a cascading SS7 recovery storm on January 15, 1990, dropping roughly 60 million calls over nine hours.
1991
The European Telecommunications Standards Institute (ETSI) deployed 2G GSM, introducing digital subscriber identity modules (SIM cards) and the A5/1 stream cipher for over-the-air voice privacy.
1994
The Communications Assistance for Law Enforcement Act (CALEA) forced US telecom carriers to design their networks so that lawful interception could be performed on demand — embedding a permanent surveillance capability into the core of every switch.
1995
Tsutomu Shimomura and the FBI tracked and arrested Kevin Mitnick in Raleigh, North Carolina using direction-finding antennas and cellular switchboard real-time ESN/MIN location triggers.
1997
Underground syndicates commercialized "Clone King" EPROM modification kits, allowing widespread cellular subscription fraud and free international calls across North American carriers.
1998
David Wagner and Ian Goldberg (UC Berkeley ISAAC Group) completely cracked the GSM COMP128-1 algorithm, allowing extraction of SIM master keys (Ki) and physical cloning of SIM cards.
1998
Attackers spoofed ICMP Echo Requests to IP directed-broadcast addresses — including Portuguese academic backbones FCCN/RCTS — producing 100x amplification floods that downed victims' uplinks.
2001
3GPP Release 99 standardized 3G UMTS, introducing bidirectional mutual authentication (3G AKA) to defeat rogue base stations (IMSI catchers) and replacing A5/1 with the KASUMI block cipher.
2003
Elad Barkan, Eli Biham, and Nathan Keller published an instant ciphertext-only attack against the GSM A5/2 cipher, recovering the session key in under 1 second on a standard PC and forcing 3GPP to deprecate the cipher globally.
2004
Rogue software patches in Vodafone Greece's Ericsson AXE-10 switches activated dormant Lawful Interception capability to wiretap the Greek Prime Minister and 100+ senior officials during the 2004 Athens Olympics period.
2005
Hackers breached T-Mobile's backend web customer-care interface, gaining unauthorized access to Danger cloud servers and publishing private celebrity phonebooks, SMS logs, and photos.
2006
Court disclosures and Freedom of Information filings revealed the widespread deployment of commercial IMSI-catchers (Harris StingRay) by law enforcement and intelligence agencies to perform unauthenticated mobile tracking.
2007
Automated botnets scanned global IP blocks for exposed SIP UDP port 5060, brute-forcing default extension credentials on Asterisk PBXs to route millions of unauthorized calls to high-cost premium-rate numbers in Somalia, Cuba, and Latvia.
2008
Dan Kaminsky disclosed a fundamental DNS cache-poisoning flaw affecting core ISP resolvers worldwide, in the same year that BGP origin-validation failures caused the Pakistan Telecom and YouTube hijacks.
2008
Ship anchor drags severed multiple major undersea optical cables simultaneously near Alexandria, knocking out 70% of Egypt's internet and 60% of India's international telecom capacity within minutes.
2009
Karsten Nohl and the Chaos Computer Club published a 2-terabyte rainbow-table set at 26C3 enabling real-time over-the-air decryption of A5/1-protected 2G GSM calls and SMS with inexpensive hardware.
2010
Sylvain Munaut and Harald Welte demonstrated OsmocomBB at 27C3, releasing an open-source GSM baseband stack that enabled over-the-air call decoding on $15 consumer handsets.
2011
Attackers breached Dutch Certificate Authority DigiNotar and issued 500+ rogue wildcard SSL certificates, which were deployed at the national Iranian telecommunications provider level to conduct a massive Man-in-the-Middle on 300,000+ Gmail users.
2012
The US House Permanent Select Committee on Intelligence published a bipartisan investigative report concluding that Huawei and ZTE equipment posed systemic national security risks to critical telecom backbones.
2013
British intelligence agency GCHQ compromised Belgian telecom provider Belgacom (Proximus) using Quantum Insert packet injection to intercept European Union and NATO mobile data roaming sessions.
2013
Snowden disclosures revealed GCHQ's TEMPORA and NSA's MUSCULAR programs, which installed passive optical beam splitters on transatlantic fiber cables and inter-datacenter backhauls.
2014
Tobias Engel and SRLabs demonstrated at 31C3 that SS7 design flaws allow global subscriber location tracking, call interception, and SMS 2FA theft using legally obtainable access to the signaling network.
2014
Symantec and Kaspersky exposed Regin, an extraordinarily sophisticated nation-state malware platform specifically engineered to infiltrate GSM cellular base station controllers and telecom routing cores.
2015
Security researchers demonstrated that 4G LTE Diameter signaling networks inherited the unauthenticated trust vulnerabilities of SS7, allowing subscriber tracking and denial-of-service over IPX interconnects.
2015
Joshua Drake (Zimperium) disclosed multiple critical vulnerabilities in Android's Stagefright media engine that allowed attackers to execute remote code on 950 million phones via a single silently received cellular MMS video message.
2015
Security researchers published proof-of-concept exploits showing that WebRTC JavaScript APIs in Chrome and Firefox sent unauthenticated STUN packets that bypassed active VPN tunnels and leaked the user's real public and private LAN IP addresses.
2017
Cybercriminals abused SS7 roaming interfaces to intercept bank-issued SMS one-time passcodes (OTPs), draining accounts of customers at O2 Germany and Metro Bank UK.
2017
The FCC and ATIS/SIP Forum finalized the STIR/SHAKEN framework, mandating cryptographic digital signature validation on SIP interconnects to combat caller ID spoofing and fraudulent robocalls.
2017
Positive Technologies disclosed critical architectural flaws in GTP (GPRS Tunnelling Protocol) across 2G, 3G, and 4G networks, demonstrating how attackers on IPX roaming networks could hijack subscriber data sessions and execute over-the-air fraud.
2018
Attackers announced rogue BGP routes for Amazon Route 53 IP prefixes through Russian and Nigerian ISP transit, hijacking DNS traffic for MyEtherWallet to steal $150,000 in cryptocurrency.
2018
Cybereason revealed Operation Soft Cell, a massive multi-year cyber espionage campaign by suspected nation-state actors that completely compromised multiple telecommunications providers to exfiltrate raw subscriber Call Detail Records.
2019
CrowdStrike revealed that the LightBasin (UNC1945) APT had compromised 13+ global telecom operators since at least 2016 using custom GTP and SS7 tooling to masquerade as roaming infrastructure.
2019
AdaptiveMobile Security disclosed Simjacker, an exploit abusing legacy S@T Browser technology on SIM cards across 30+ countries to track subscriber location without user awareness.
2019
An attacker only had to ring a WhatsApp call. NSO Group's Pegasus implant was delivered to ~1,400 targets through a buffer overflow in the VoIP call stack — the victim never had to answer, and the missed-call log was the only trace.
2019
The GSM Association launched its formal Coordinated Vulnerability Disclosure (CVD) program and Hall of Fame, establishing standard operating procedures for researchers to responsibly report 2G–5G protocol and core vulnerabilities.
2020
5G Standalone (Release 16, 2020) replaced SS7/Diameter trust assumptions with HTTP/2 service-based APIs over TLS, OAuth 2.0 token authentication, and cryptographically concealed subscriber identities (SUCI).
2021
A global consortium of journalists revealed that NSO Group's Pegasus spyware had targeted 50,000+ phone numbers across 50 countries, utilizing zero-click SMS/iMessage parser vulnerabilities.
2021
Federal indictments exposed international cybercrime rings bribing retail store employees at AT&T, Verizon, and T-Mobile to execute unauthorized SIM swaps, stealing tens of millions of dollars in cryptocurrency.
2021
A misconfigured BGP routing filter inside Vodafone Idea (AS5583) leaked over 30,000 global BGP routing prefixes to international transit provider Telstra, rerouting massive volumes of global telecommunications and Google DNS traffic into India.
2022
Minutes before Russia's invasion on 24 February 2022, a wiper attack against Viasat's KA-SAT ground infrastructure took roughly 45,000 modems offline across Ukraine and Central Europe — the first major cyber-physical attack on a civilian satellite network during wartime.
2022
Explosions damaging the Nord Stream subsea pipeline network raised international alerts regarding the extreme physical vulnerability of adjacent Baltic submarine telecommunications fiber cables.
2023
Two submarine communications cables connecting Taiwan to the Matsu Islands were severed by Chinese fishing and cargo vessels within six days, disconnecting 14,000 residents from broadband internet.
2023
Threat intelligence researchers uncovered RedEye / ChamelGang deploying custom eBPF (Extended Berkeley Packet Filter) kernel rootkits directly inside telecom core network servers to intercept subscriber GTP data and signaling stealthily.
2023
3GPP and leading telecom vendors standardized the Network Data Analytics Function (NWDAF), integrating machine learning and deep reinforcement learning directly into 5G Core signaling planes to detect sub-second zero-day signaling exploits autonomously.
2024
A dragging anchor from the struck cargo ship Rubymar severed three major submarine cables in the Bab-el-Mandeb Strait, disrupting 25% of data traffic between Asia, the Middle East, and Europe.
2024
Attackers executed an unauthorized SIM swap against the phone number tied to the US SEC official X account, broadcasting a fraudulent Bitcoin ETF approval that caused hundreds of millions in market swings.
2024
Chinese APT group Salt Typhoon breached the core networks of major US telecom providers — AT&T, Verizon, Lumen and others — reaching CALEA lawful-intercept systems and sustained metadata and audio collection across at least nine carriers.
2024
Days before the New Hampshire primary, a cloned AI voice of President Biden urged Democrats not to vote. The FCC responded within weeks by ruling that AI-generated voices are "artificial" under the Telephone Consumer Protection Act — making AI voice robocalls illegal outright.
2024
Two major submarine optical fiber cables connecting Finland to Germany and Lithuania to Sweden were physically severed in the Baltic Sea by an anchor dragged by the Chinese bulk carrier Yi Peng 3.
2024
A multinational firm's Hong Kong branch lost $25.6 million (HK$200M) after an employee was deceived into authorizing wire transfers during a video conference where every other participant was an AI-synthesized real-time deepfake.
2024
Sophisticated social engineering syndicates deployed zero-shot generative voice-cloning models to synthesize real-time conversational audio of corporate executives, bypassing carrier voice biometrics and executing multimillion-dollar SIM swaps and wire transfers.
2025
The European Union began strict enforcement of the NIS2 Directive, classifying telecommunications carriers, Internet Exchange Points (IXPs), DNS service providers, and subsea cable landing stations as Essential Entities with mandatory 24-hour incident notification and personal executive liability.
2025
SpaceX Starlink and T-Mobile rolled out commercial Direct-to-Cell satellite service, deploying LEO satellites equipped with onboard 3GPP eNodeB cellular base stations connecting standard unmodified LTE/5G smartphones from space.
2026
3GPP SA3 finalized Release 19 security specifications integrating NIST Post-Quantum Cryptography (FIPS 203 ML-KEM and FIPS 204 ML-DSA) to protect 5G subscriber privacy (SUCI) and inter-operator Service-Based Architecture (SBA) tunnels against Harvest-Now-Decrypt-Later threats.