Ribbon Communications, a major U.S.-based telecommunications and networking provider, confirmed that its IT network was compromised by threat actors reportedly linked to a Chinese nation-state. The breach, discovered in September 2025 but believed to have originated as early as December 2024, involved unauthorized access to the company's systems. Ribbon Communications initiated an incident response plan, engaged third-party cybersecurity experts, and notified federal law enforcement. The company stated that it has successfully terminated the unauthorized access and is continuing its investigation.
While the investigation is ongoing, Ribbon Communications has not found evidence that the attackers accessed or exfiltrated any material information from its main network. However, several customer files stored on two laptops outside the main network were accessed, and affected customers have been notified. The company anticipates incurring additional costs related to the incident and is working closely with authorities to assess the full impact. No technical details about the intrusion have been disclosed publicly at this time.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Follow-up coverage said the attackers were suspected Chinese state-backed actors, adding attribution detail beyond the initial nation-state characterization. The reporting also highlighted the breach as the latest in a series of attacks affecting telecom organizations.
Ribbon Communications reported that it had been breached in a cyberattack attributed to a nation-state actor. Multiple reports describe the company as a telecom services provider and frame the incident as part of broader targeting of the telecom sector.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcedarkreading.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.