The telecom sector faces a new phishing reality. How should it respond?

Until recently, telecom organisations sat outside the crosshairs of phishing attacks. Threat actors instead focused on sectors such as financial services, retail, and government.

Until recently, telecom organisations sat outside the crosshairs of phishing attacks. Threat actors instead focused on sectors such as financial services, retail, and government. That is now changing.

Data by Crane Authentication and published in APWG’s Q1 2026 Phishing Activity Trends report shows that telecom-targeted URL phishing incidents increased by 75% between Q4 2025 and Q1 2026. The sector accounted for 33% of all observed phishing attacks, up from just 5.9% the previous quarter.

The data reflects a broader shift in attacker behaviour, with threat actors expanding into sectors that have historically attracted less attention. But why, and what should telecom organisations be doing not just in response, but in anticipation of future threats?

Why telecom has become strategically valuable

The transformation of the telecom industry may help explain why attackers are increasingly targeting the sector, with this trend looking set to grow in the coming years. Many carriers now combine Internet Service Provider (ISP) services with email hosting, telephony, and mobile identity within a single customer account. As a result, one successful compromise can provide attackers with access to other accounts and services, opening up a far broader set of credentials to exploit.

For example, phishing emails sent via ISP-linked email accounts offer new opportunities for attackers. This is because they usually originate from trusted domain names. These emails also don’t include the typical indicators of phishing, such as suspicious links, because they mimic a legitimate transaction, like a PayPal receipt or invoice. The invoice itself is also likely to include a vishing phone number for fake tech support, which isn’t immediately obvious to the recipient.

Smaller telecom businesses can also inadvertently create additional routes for attackers by issuing customers email addresses under their own domains. If those email addresses are used for password recovery purposes for other online services, compromising them could allow an attacker to intercept password resets and breach other accounts. Access to a mobile account can also open the door to other forms of fraud, particularly where mobile numbers or accounts are used to verify identity or recover access to other services.

Telephone-based fraud is adding further risk to the sector. Vishing, where fraudsters use calls or voice messages to trick individuals into sharing personal information, and smishing, where SMS texts trick users into doing the same, increased by 15% from Q4 2025 to Q1 2026. These types of attacks are often interlinked. SIM swapping can follow successful phishing attempts, allowing attackers to intercept two-factor authentication codes to break into accounts.

Never-before-phished

Businesses typically prepare for phishing fraud based on what they already know, such as the previous attack types they’ve faced, and the threat types the wider sector commonly deals with. But bad actors aren’t sticking to static target lists. Instead, they pursue opportunities. A sector offering interconnected value, trusted infrastructure, or additional fraud opportunities is an attractive prospect.

It’s even more attractive when it’s an industry that hasn’t developed a strategy to deal with sustained targeting.  The telecom sector illustrates the risk facing “never-before-phished” organisations: lower or even non-existent historical incident volume doesn’t necessarily translate to lower exposure. It may simply mean they haven’t been targeted yet.

A shift in focus to where phishing threats are heading

The more important question for telecom organisations is whether their security strategies reflect where phishing threats are heading, rather than where they have historically been. As attackers shift their focus and exploit increasingly interconnected digital services, organisations need to move beyond reacting to individual incidents and towards identifying emerging campaigns before they gain momentum.

That requires greater visibility into the infrastructure supporting phishing activity, from suspicious domain registrations and Secure Sockets Layer (SSL) certificates to evolving impersonation techniques. Rapid investigation and coordinated enforcement, backed by the ability to escalate enforcement efforts across several possible paths, can effectively tackle threats. With these capabilities covering channels such as domains, email, SMS, phone, and social media, organisations can disrupt campaigns earlier, reduce customer exposure, and make it harder for attackers to reuse the same tactics – allowing them to stay one step ahead.

An early warning of what might be next

For telecom organisations, the rise in phishing activity should be treated as an early warning of what might be about to happen. As the sector becomes more connected to identity, communications, and customer access, attackers are finding more value in every successful compromise.

The warning should also be heard beyond telecom. The sector’s experience shows how quickly attackers can redirect their attention when they identify trusted infrastructure, interconnected services, valuable credentials, or opportunities to enable further fraud. Industries that have historically experienced lower levels of phishing may be especially attractive because their defences have not yet been tested by sustained campaigns.

Both telecom businesses and wider industries must now respond before phishing becomes a familiar problem. That means shifting from reactive takedowns to proactive detection, intelligence-led enforcement, and faster disruption across the full threat lifecycle. Protecting trust means recognising phishing risk as a growing sector-wide challenge, and responding with the speed and resilience needed to stay ahead of it.


Inside Telecom provides you with an extensive list of content covering all aspects of the tech industry. Keep an eye on our Telecom sections to stay informed and up-to-date with our daily articles.

Join our WhatsApp Channel WhatsApp Channel