Researchers Say a Long-Running Intrusion Campaign Has Been Sitting Inside Regional Telecoms
A joint report from three security firms describes years of quiet access to call-detail records at operators in five countries, with no ransom and no data ever sold.
Three security firms published a joint report on Thursday describing an intrusion campaign that maintained access to core network systems at telecom operators in five African countries for periods ranging from eight months to nearly four years.
The behavioral signature is what makes the report notable. The intruders took no money, deployed no ransomware, and none of the accessed data has surfaced on criminal markets. What they did do, repeatedly, was query call-detail records for small sets of specific subscriber numbers — in one documented case, 31 numbers over a fourteen-month period.
"When somebody spends four years inside a network to look up thirty-one phone numbers, you are not looking at crime," said one of the report's authors, who asked that neither she nor her firm be named given the sensitivity. "We are describing behavior. We are not naming a sponsor, because we cannot prove one, and everyone who has tried to guess in public has embarrassed themselves."
The affected operators were notified before publication; two have confirmed remediation and three have not commented. The report's practical recommendations are unglamorous — segment the lawful-intercept infrastructure, log every CDR query, alert on repeated lookups of the same subscriber — and, the authors note, would have caught this campaign in weeks rather than years.
Why the offline-first bet is reshaping African AI · The Build Loop
When you purchase through links in our articles, we may earn a small commission. This doesn't affect our editorial independence.
Grace Wekesa
Data and Investigations Reporter
Grace Wekesa leads data-driven investigations at Afrikons, working with filings, procurement records, and leaked documents. She trained as a statistician and still builds most of her own scrapers.
View BioLoading the next article


