Critical networks face stealthy intrusions, record-breaking DDoS attacks and rising cryptographic demands, according to Nokia study

- Nearly 2 in 3 telecom operators experienced at least one “living off the land” attack the past 12 months, and 32% saw four or more.
- Terabit-scale DDoS attacks are happening five times more frequently and with greater peak strength, as 4% of the world’s home internet connections are compromised; some 37% of DDoS attacks now end within two minutes.
- More than 70% of telecom security leaders now prioritize AI- and ML-based threat analytics, and over half plan to deploy AI for detection within 18 months.
Cyber attackers are increasingly penetrating core telecom infrastructure undetected; DDoS attacks have surged to new extremes, powered by compromised home internet connections; and crypto agility is moving from roadmap to requirement, according to Nokia’s 11th annual Threat Intelligence Report.
Stealthy campaigns now target the telco core
Attackers have stepped up their intrusions into core networks, in some cases reaching sensitive systems such as subscriber data and lawful interception platforms, as seen in the high-profile Salt Typhoon case. They often hide in plain sight by abusing trusted tools, unpatched devices and misconfigurations.
- 63% of operators faced at least one “living off the land” attack last year; 32% saw four or more.
- Multi-year, low-profile infections have led to major data exposure and forced operators into costly remediation, highlighting the business and reputational risks of long-term, privileged access.
- As the CISO from one leading CSP in North America said, “Salt Typhoon was the most significant cybersecurity incident we faced in the last 12 months. … Some of the entry points were put in place years ago, just sitting and waiting for the right moment to trigger.”
DDoS attacks are shorter and more powerful
Terabit-scale DDoS attacks are now a daily reality, up from once every five days in 2024, and gigabit residential broadband connectivity is amplifying the dangers.
- DDoS peaks in the 5 to 10 Tbps range are the “new normal,” escalating faster than most alert systems can raise alarms.
- Some 78% of DDoS attacks now end within five minutes (up from 44% in 2024), with 37% wrapping up in under two minutes, highlighting the need for rapid detection and mitigation.
- Over 100 million residential endpoints (4% of the global total) are now available for exploits and malicious uses of bandwidth.
AI is now central to defense, and quantum-safe networking is the next frontier
More than 70% of telecom security leaders now prioritize AI- and ML-based threat analytics, and over half plan to deploy AI for detection within 18 months — a direct response to stealthy attacks and rapid DDoS campaigns. In a similar sense, telcos also need to adopt automated certificate management and encryption that’s ready for the quantum future.
- The timespan in which digital certificates remain valid is shrinking dramatically, from currently over a year to just 47 days by 2029.
- Despite upcoming compliance deadlines from governing bodies — particularly in the European Union — the industry’s sense of urgency is low: Quantum computing risk ranks second to last among concerns for network security professionals.
Insider risk, human error and misconfigurations remain major vulnerabilities
Nearly 60% of high-cost breaches stem from insider actions or mistakes, with complex supply chains further increasing exposure to credential misuse, privilege escalation and physical access breaches.
- Hygiene gaps still open doors too, as 76% of vulnerabilities stem from missing patches.
- Application‑layer issues, including poor access controls and exploitable software flaws, remain prevalent as digital services expand.
“Connectivity powers everything from public safety and financial transactions to digital identity. Recent attacks have reached lawful interception systems, leaked sensitive subscriber data and disrupted emergency services. The industry must fight back through shared threat intelligence, AI-driven detection and response, and crypto-agility, turning interconnected networks from a vulnerability into a source of resilience,” said Kal De, Senior Vice President, Product and Engineering, Cloud and Network Services, Nokia.
“In light of the rise of industrialized attack tools, millions of insecure IoT endpoints and organized botnets employing residential proxies, network owners must act now to protect their assets and customers from massive, complex and highly variable DDoS attacks in the 10+ terabit range. Security should not be an afterthought; rather, DDoS protection must be built into the network itself, ensuring critical network functions continue uninterrupted,” said Jeff Smith, Vice President and General Manager, Deepfield, Nokia.
Related News.
September 18, 2026
The war premium has moved into the balance sheet
Hormuz, $100 oil and the question shipowners should ask before buying their next vessel The Strait of Hormuz is not closed. That may be precisely…
September 18, 2026
Stop attacking merchant ships and seafarers IMO Secretary-General to Member States
Conflicts must not be used as pretext to attack merchant ships. The Secretary-General of the International Maritime Organization, Mr. Arsenio…
September 18, 2026
Intellian and Network Innovations sign Strategic Partnership to develop and distribute Multi-Band, Multi-Orbit WGS Flyaway Terminals for Military and Government Markets
Agreement Paves the Way for Enhanced Flexibility and Resiliency with the Provisioning of Concurrent Mil-X, Mil Ka-band and Commercial Ka and Ku…
September 18, 2026
One in ten inspected cargo units found with safety deficiencies
More than one in ten cargo transport units inspected during 2025 had safety deficiencies, according to data published by the World Shipping Council…
September 18, 2026
Hormuz risks drive increase in road haulage for smaller oil parcels
The use of trucks to move small bunkers and gasoline cargoes within the Persian Gulf region has ballooned in recent months as companies look to save…
September 18, 2026
Torvald Klaveness 2006–2016 charting a new course
By the mid-2000s, Klaveness had expanded its international presence, continued developing new shipping activities, and built interests that extended…
September 18, 2026
Bunker Holding strengthens commercial leadership to drive customer value and growth
Bunker Holding is reshaping its commercial leadership organisation to strengthen its commercial capabilities, bring fresh perspectives to the…
September 18, 2026
How the Shipping Sector must respond to UNEP’s Overshoot report
Responding to the publication of the UN Environment Programme report Limiting Overshoot: Navigating exceedance of 1.5°C and pathways towards return,…
September 18, 2026
Intermodal Report Week 37 2026
Ps find below the Intermodal Report - Week 37 2026 Intermodal Report Week 37 2026
September 18, 2026
Allied Weekly Market Review Week 37
Pls find below the Allied - Weekly Market Review - Week 37 ALLIED - Weekly Market Report- Week 37
Subscribe to our newsletter!
if you dont want to swim alone in the ocean of news, sign up for the newsletter, and you will receive daily all the important news of world shipping!
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved























