Published Online:May 2026
Product Name:The IUP Journal of Telecommunications
Product Type:Article
Product Code:IJTC040226
DOI:10.71329/IUPJTC/2026.18.2.82-111
Author Name:Abimbola Abiodun Ogunjinmi
Availability:YES
Subject/Domain:Engineering
Download Format:PDF
Pages:82-111
State-sponsored cyber operations targeting telecommunications infrastructure evolved between 2014 and 2025 from discrete espionage incidents into sustained campaigns of strategic significance. Using a telecom-specific extraction from the CISSM Cyber Events Database, this paper applies an ARIMA-based interrupted time-series design around five prespecified geopolitical intervention points: Crimea (2014), Russia’s full-scale invasion of Ukraine (2022), Speaker Pelosi’s Taiwan visit (2022), the Volt Typhoon advisory (2024), and the Salt Typhoon disclosure (2024). The analysis identifies statistically meaningful temporal associations between four of the five interventions and changes in telecom-targeting frequency; the Crimea intervention is directionally consistent but not statistically significant. These associations do not, by themselves, establish causality, but they are robust across alternative specifications and are consistent with Buchanan’s cybersecurity dilemma, which emphasizes the convergence of intelligence collection, prepositioned access, and potential disruption capability in telecommunications networks. The findings also place pressure on restraint-based theories when applied specifically to telecommunications, where incentives for persistent access are unusually strong. A telecom-specific severity index grounded in the CISSM Cyber Disruption Index shows substantial escalation from the preCrimea baseline to the post-Salt Typhoon period. The paper contributes to telecommunications policy by linking geopolitical competition, lawful-intercept architecture, 5G transition risks, and criticalinfrastructure governance within a transparent empirical framework.
On December 12, 2023, Sandworm—Russia’s GRU Unit 74455—executed the most destructive cyber operation documented against civilian telecommunications infrastructure. The attack on Kyivstar, Ukraine’s largest mobile operator, destroyed more than 10,000 computers and 4,000 servers, severing mobile and Internet services for approximately 24 million subscribers and disabling air raid warning systems across