Sector research identified 444 incidents involving data theft from telecommunications firms, including 133 listings of stolen databases that could contain customer or operational information.
The Subset Is The Finding
444 incidents is a count of events. 133 database listings is a count of things offered for sale or publication — which means somebody assessed the material as saleable and made it available.
That is closer to a measure of consequence than an incident tally. Roughly 30% of recorded incidents produced a marketable dataset; the rest did not, or the data was retained, or the claim was never substantiated.
It Is Also A Supply Figure For Everything Downstream
A carrier database listing is an input. The credential compilations at 25-0620 and the account compromise distribution at 25-0912 are assembled from exactly this kind of material.
And the fields at 25-0720 — identity documents, payment instruments, addresses, phone numbers — make a telecom database unusually complete for the impersonation attacks the corpus files throughout.
What A Listing Does Not Establish
That the data is real, current, or what it claims to be. This desk filed at 26-0425 and 25-1230 that leak-site content is advertising, and database listings on criminal markets are frequently recycled, padded with earlier breaches, or fabricated.
133 listings means 133 claims of a saleable dataset. Graded medium: the direction and the ratio are useful and neither number should be treated as verified.
Built on published vendor research, listed below. Listings are claims and their contents have not been verified by this desk. Corrections: corrections@forensicpost.com.
- Telecommunication sector faces new threatsThe Cyber Express
- Telecom sector sees steady rise in ransomware attacksCybersecurity Dive