Article Details
  • Published Online:
    May  2026
  • Product Name:
    The IUP Journal of Telecommunications
  • Product Type:
    Article
  • Product Code:
    IJTC040226
  • DOI:
    10.71329/IUPJTC/2026.18.2.82-111
  • Author Name:
    Abimbola Abiodun Ogunjinmi
  • Availability:
    YES
  • Subject/Domain:
    Engineering
  • Download Format:
    PDF
  • Pages:
    82-111
Volume 18, Issue 1 & 2, January-March & April-June 2026
Telecommunications as a Strategic Cyber Domain: An Interrupted Time-Series Analysis of State-Sponsored Operations
Abstract

State-sponsored cyber operations targeting telecommunications infrastructure evolved between 2014 and 2025 from discrete espionage incidents into sustained campaigns of strategic significance. Using a telecom-specific extraction from the CISSM Cyber Events Database, this paper applies an ARIMA-based interrupted time-series design around five prespecified geopolitical intervention points: Crimea (2014), Russia’s full-scale invasion of Ukraine (2022), Speaker Pelosi’s Taiwan visit (2022), the Volt Typhoon advisory (2024), and the Salt Typhoon disclosure (2024). The analysis identifies statistically meaningful temporal associations between four of the five interventions and changes in telecom-targeting frequency; the Crimea intervention is directionally consistent but not statistically significant. These associations do not, by themselves, establish causality, but they are robust across alternative specifications and are consistent with Buchanan’s cybersecurity dilemma, which emphasizes the convergence of intelligence collection, prepositioned access, and potential disruption capability in telecommunications networks. The findings also place pressure on restraint-based theories when applied specifically to telecommunications, where incentives for persistent access are unusually strong. A telecom-specific severity index grounded in the CISSM Cyber Disruption Index shows substantial escalation from the preCrimea baseline to the post-Salt Typhoon period. The paper contributes to telecommunications policy by linking geopolitical competition, lawful-intercept architecture, 5G transition risks, and criticalinfrastructure governance within a transparent empirical framework.

Introduction

On December 12, 2023, Sandworm—Russia’s GRU Unit 74455—executed the most destructive cyber operation documented against civilian telecommunications infrastructure. The attack on Kyivstar, Ukraine’s largest mobile operator, destroyed more than 10,000 computers and 4,000 servers, severing mobile and Internet services for approximately 24 million subscribers and disabling air raid warning systems across