Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What are the signs that a telecom intrusion…
Cyber Security

What are the signs that a telecom intrusion campaign is still active after initial containment?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Cyber Security

Common warning signs include new access in systems that should be stable, unexplained configuration changes, suspicious administrative activity, and evidence that high-value accounts or lawful intercept systems were touched. A campaign may also continue if only some affected systems were remediated while router weaknesses, phishing exposure, or stolen credentials remain available to the attacker.

What to look for when containment is not actually containment

A telecom intrusion campaign is still active when the attacker’s original foothold, credentials, or access path remain usable somewhere in the environment. The key signal is not just “more alerts,” but evidence that the operator can still move, authenticate, or change state in systems that should now be quiet. In practice, that means watching for fresh administrative activity, repeated changes that undo remediation, and access in places that should have stabilised after the first response.

Activity that keeps reappearing after cleanup usually indicates the campaign was interrupted, not removed. Telecom environments are especially sensitive because attackers may retain access through exposed management interfaces, weak router credentials, or touched accounts and systems that were never fully swept. When one part of the environment keeps behaving normally while a neighbouring control plane remains noisy, assume the intrusion may still be live.

One useful signal is whether the systems touched by the campaign still show a path for the attacker to return. That can be a stolen credential, a lingering configuration weakness, an uncompensated account, or an unmanaged exposed service that was not part of the initial containment scope. If the answer is yes, containment is partial, not complete.

Why telecom campaigns often survive the first response

Telecom intrusions can persist because responders focus on the most visible compromise point while missing adjacent systems that the attacker can still use. A compromised admin account, an unrotated secret, or a vulnerable router can remain enough for re-entry even after the first infected host is isolated. The operational problem is blast radius: if only some affected systems were remediated, the campaign can continue through the residual trust relationships that were left in place.

Salt Typhoon US telecoms breach is a useful reminder that credential abuse and device weaknesses can coexist, so closing only one path does not end the intrusion. In the same way, signs of continued activity often come from the overlap between infrastructure flaws, account compromise, and later-stage persistence.

If you need a concrete example of the persistence pattern itself, Cisco Active Directory credentials breach shows how credential theft can support lateral movement long after the initial event. For broader context on how reused secrets and overprivileged access sustain compromise, the Ultimate Guide to Non-Human Identities is also relevant because telecom operations often depend on machine-facing credentials and service access that must be revoked and rotated quickly.

One statistic that matters here is that 91.6% of secrets remain valid five days after the targeted organisation is notified, which shows how often response is slower than attacker reuse. In an active campaign, that delay is enough to let a foothold survive remediation and reappear as fresh administrative behaviour.

Risk and Threat Considerations

The main risk is false closure: teams may declare containment before every viable access path has been removed, allowing the campaign to resume through untouched credentials, routers, or management systems. In telecom networks, that creates a particularly dangerous condition because the attacker can use legitimate administrative access to blend in with normal operations.

Failure mechanism: A partial cleanup leaves one or more durable attacker enablers in place, such as stolen credentials, persistent configuration changes, exposed management access, or a vulnerable device that was not rebuilt or patched.

Impact: The intruder can re-enter, continue lateral movement, restore access after resets, or touch high-value systems again, which extends dwell time and increases the chance of service disruption or lawful-intercept exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM — Continuous MonitoringTracks anomalous admin activity and unexpected access after containment.
RC.RP — Recovery Plan ExecutionConfirms remediation reaches every affected system, not only the visible initial compromise point.
PR.AC — Identity Management, Authentication and Access ControlResidual credentials or access paths can keep a telecom intrusion active after cleanup.
Recommendation — Monitor for new administrative activity and unexpected system changes until all attacker paths are removed. Validate that recovery actions covered every impacted router, account, and management system. Rotate or revoke any credential or access path that could still authenticate to critical telecom systems.
CIS Controls v85 — Account ManagementStale or overprivileged accounts can preserve attacker access after initial containment.
4 — Secure Configuration of Enterprise Assets and SoftwareUnfixed router weaknesses and lingering config changes can sustain re-entry.
Recommendation — Review and remove any account that can still reach sensitive telecom infrastructure. Harden and verify configurations on routers, management systems, and exposed services.
MITRE ATT&CKT1078 — Valid AccountsStolen credentials let attackers remain active through legitimate authentication.
T1098 — Account ManipulationSuspicious admin changes can indicate the actor is preserving access or restoring footholds.
T1190 — Exploit Public-Facing ApplicationRemaining router or management exposure can allow continued exploitation after partial cleanup.
Recommendation — Hunt for valid-account use that should not occur after containment. Inspect for account or permission changes that could re-enable attacker access. Confirm public-facing telecom management interfaces are patched or removed from exposure.
OWASP Non-Human Identity Top 10NHI-03 — Secrets SprawlResidual secrets and credentials can keep access alive across telecom systems.
NHI-06 — Overprivileged NHIExcessive machine or service privileges widen the attacker’s post-containment options.
Recommendation — Inventory and rotate any secret that may still authenticate to affected infrastructure. Reduce privileges on any non-human identity that could still reach production telecom assets.

Practitioner Guidance

What to verify: Treat containment as unproven until you can show that all known attacker paths are closed, not just the system that first triggered the alert. In this scenario, verify credential rotation, router and management-plane patching, account review, and whether any configuration changes were reversed or reintroduced after cleanup.

Decision rule: If you still see unexplained admin actions, new logins in supposedly stable systems, or evidence that high-value accounts were touched, assume the campaign remains active and continue hunting before declaring recovery. If the same access path can still authenticate or administer production systems, the response is not finished.

Practitioner takeaway: In telecom intrusions, the most important question is not whether the initial host is clean, but whether any attacker-capable access path still exists anywhere in the control plane or adjacent infrastructure.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org