Critical networks face stealthy intrusions, record-breaking DDoS attacks and rising cryptographic demands, according to Nokia study

- Nearly 2 in 3 telecom operators experienced at least one “living off the land” attack the past 12 months, and 32% saw four or more.
- Terabit-scale DDoS attacks are happening five times more frequently and with greater peak strength, as 4% of the world’s home internet connections are compromised; some 37% of DDoS attacks now end within two minutes.
- More than 70% of telecom security leaders now prioritize AI- and ML-based threat analytics, and over half plan to deploy AI for detection within 18 months.
Cyber attackers are increasingly penetrating core telecom infrastructure undetected; DDoS attacks have surged to new extremes, powered by compromised home internet connections; and crypto agility is moving from roadmap to requirement, according to Nokia’s 11th annual Threat Intelligence Report.
Stealthy campaigns now target the telco core
Attackers have stepped up their intrusions into core networks, in some cases reaching sensitive systems such as subscriber data and lawful interception platforms, as seen in the high-profile Salt Typhoon case. They often hide in plain sight by abusing trusted tools, unpatched devices and misconfigurations.
- 63% of operators faced at least one “living off the land” attack last year; 32% saw four or more.
- Multi-year, low-profile infections have led to major data exposure and forced operators into costly remediation, highlighting the business and reputational risks of long-term, privileged access.
- As the CISO from one leading CSP in North America said, “Salt Typhoon was the most significant cybersecurity incident we faced in the last 12 months. … Some of the entry points were put in place years ago, just sitting and waiting for the right moment to trigger.”
DDoS attacks are shorter and more powerful
Terabit-scale DDoS attacks are now a daily reality, up from once every five days in 2024, and gigabit residential broadband connectivity is amplifying the dangers.
- DDoS peaks in the 5 to 10 Tbps range are the “new normal,” escalating faster than most alert systems can raise alarms.
- Some 78% of DDoS attacks now end within five minutes (up from 44% in 2024), with 37% wrapping up in under two minutes, highlighting the need for rapid detection and mitigation.
- Over 100 million residential endpoints (4% of the global total) are now available for exploits and malicious uses of bandwidth.
AI is now central to defense, and quantum-safe networking is the next frontier
More than 70% of telecom security leaders now prioritize AI- and ML-based threat analytics, and over half plan to deploy AI for detection within 18 months — a direct response to stealthy attacks and rapid DDoS campaigns. In a similar sense, telcos also need to adopt automated certificate management and encryption that’s ready for the quantum future.
- The timespan in which digital certificates remain valid is shrinking dramatically, from currently over a year to just 47 days by 2029.
- Despite upcoming compliance deadlines from governing bodies — particularly in the European Union — the industry’s sense of urgency is low: Quantum computing risk ranks second to last among concerns for network security professionals.
Insider risk, human error and misconfigurations remain major vulnerabilities
Nearly 60% of high-cost breaches stem from insider actions or mistakes, with complex supply chains further increasing exposure to credential misuse, privilege escalation and physical access breaches.
- Hygiene gaps still open doors too, as 76% of vulnerabilities stem from missing patches.
- Application‑layer issues, including poor access controls and exploitable software flaws, remain prevalent as digital services expand.
“Connectivity powers everything from public safety and financial transactions to digital identity. Recent attacks have reached lawful interception systems, leaked sensitive subscriber data and disrupted emergency services. The industry must fight back through shared threat intelligence, AI-driven detection and response, and crypto-agility, turning interconnected networks from a vulnerability into a source of resilience,” said Kal De, Senior Vice President, Product and Engineering, Cloud and Network Services, Nokia.
“In light of the rise of industrialized attack tools, millions of insecure IoT endpoints and organized botnets employing residential proxies, network owners must act now to protect their assets and customers from massive, complex and highly variable DDoS attacks in the 10+ terabit range. Security should not be an afterthought; rather, DDoS protection must be built into the network itself, ensuring critical network functions continue uninterrupted,” said Jeff Smith, Vice President and General Manager, Deepfield, Nokia.
Related News.
August 28, 2026
Iran’s blockade trilemma: endure, escalate or negotiate
Key takeaways • The renewed US blockade is making the status quo progressively more expensive for Tehran. Pressure now extends from crude and…
August 28, 2026
Oil and gas companies remain key adopters of CCUS despite project delivery challenges, says GlobalData
Carbon capture, utilisation, and storage (CCUS) has become an important decarbonization pathway for oil and gas, power, cement, steel and other…
August 28, 2026
Iran’s bottleneck is Hormuz, not the buyer
The Iranian crude that reached Asia is being taken. The crude that has not reached it is standing at the strait and behind it, and there is nearly…
August 28, 2026
Diana Shipping announces direct continuation of time charter contract for m/v Leto with Cargill
Diana Shipping , a global shipping company specialising in the ownership and bareboat charter-in of dry bulk vessels,announced that, through a…
August 28, 2026
Euroseas announces 2-Year Charter contract extension for its Feeder Containership, M/V Jonathan P
Euroseas Ltd., an owner and operator of container carrier vessels and provider of seaborne transportation for containerized cargoes, announced today…
August 28, 2026
Lloyd’s Register wins Austal contract for Australian Army landing craft program
LR to provide classification services for the delivery of 18 landing craft medium to the Australian Army. Lloyd's Register (LR) has secured a…
August 28, 2026
Nautical Institute Singapore Conference 2026 Brought Seaworthiness and the Future of Seafarers to Centre Stage
The need to look at seaworthiness beyond the physical condition of a vessel, strengthen long-term career pathways for seafarers, and keep seafarer…
August 28, 2026
Allied Weekly Market Review Week 34
Pls find below the Allied - Weekly Market Review - Week 34 ALLIED - Weekly Market Report- Week 34
Subscribe to our newsletter!
if you dont want to swim alone in the ocean of news, sign up for the newsletter, and you will receive daily all the important news of world shipping!
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved





















