Skip to content
One fifth of telcos' websites wide open to cyber attacks

One fifth of telcos' websites wide open to cyber attacks

Commsbusiness April 14, 2026

A new study by agentic AI pentesting firm Ethiack has found that one fifth (19 per cent) of the web servers used by UK telecoms firms leave crucial security information in plain sight that offers a roadmap to cybercriminals.

Ethiack’s researchers analysed more than 50,000 digital assets, including the customer portals, APIs, email servers and administrative systems of almost 600 telecoms providers operating across Europe.

UK telecoms giants including BT, Vodafone and Three, accounted for more than 8,300 assets - more than any of the 30 countries included in the study.

In total, 19 per cent of the UK web servers tested were found to be inadvertently revealing details of their software type and version in the HTTP response banners displayed by their webpages. UK telecoms firms were found to be less exposed than their foreign counterparts, with the European average standing at 47 per cent of web servers.

The findings come a decade after the UK broadband provider TalkTalk was fined £400,000 after hackers who exploited a vulnerability in its web assets stole the personal data of 157,000 customers, including almost 16,000 people’s bank details.

While leaving details of a server’s software type and version on display isn’t a vulnerability per se, it is a gift to sophisticated cybercriminals, according to Ethiack CEO Jorge Monteiro.

Monteiro said, “Revealing the type and version of the software your server runs gives away vital clues your security posture and can leave you wide open to cyberattack.

“Skilled and state- hackers, who use automation and AI to scan vast numbers of websites for exploitable risks, know how to exploit this information and can use it as a roadmap for an attack.”

The analysis also found that almost two out of five (37 per cent) of the SSL security certificates in use on the websites of European telecom firms are either invalid, expired or misconfigured.

SSL security certificates are supposed to encrypt customer data and verify the authenticity of a telecoms provider’s website. But when customers place an order or log in to a website without a valid SSL certificate, their personal data can be intercepted by hackers. Cybercriminals can also exploit this security vulnerability to impersonate the website and steal from customers.

In total, Ethiack’s analysis identified 1,452 critical assets, including VPNs, admin panels and customer-facing systems, with significant security weaknesses that could pose a direct risk to both the telecoms provider’s operations and customer data.

The findings come after high-profile cyberattacks were made on several of Europe’s telecoms giants, and as Google Cloud data has revealed that cybercriminals have cut the average time taken to exploit vulnerabilities from days to hours.

In January this year, two major French telecom providers were fined a combined €42 million after a cyber breach exposed the personal details of 24 million customers, while in 2024 Spain’s second biggest mobile network Orange was taken offline by a cyberattack.

The cost of such breaches extends far beyond immediate remediation. Regulatory penalties, customer churn, service disruption and loss of stakeholder trust can all have lasting financial consequences for companies operating critical telecoms infrastructure.

For example in 2025, the London-based Colt Technology Services suffered three months of disruption following a ransomware attack. The telco infrastructure provider also had to notify authorities in 27 different countries, filing more than 75 reports to regulators, law enforcement bodies, cybersecurity agencies and emergency services.

Monteiro added, “By definition, telecom providers are among the most connected organisations in the world. That hyperconnectivity is both their strength and their biggest vulnerability.

“Our analysis shows that many telecom firms struggle with basic security hygiene, not through negligence or error, but because their IT systems are highly complex and constantly evolving. The combination of legacy platforms, cloud infrastructure, third-party integrations and shadow IT environments expands the attack surface and creates blind spots for security teams - allowing small misconfigurations to crop up without anyone realising.

“Cybercriminals now use AI to scan and exploit vulnerabilities 24/7, and the time-to-exploit - which tracks the average time between a software patch release and active exploitation - has plunged from days to just hours.

“That’s why cybersecurity teams trying to keep pace with threat actors often feel like they’re running just to stand still, and why periodic security checks are no longer enough to manage rising risk levels.

“If your attack surface is changing every day, your penetration testing needs to operate at the same speed. We’re working with some of the most forward-thinking telecoms brands to deliver continuous attack surface monitoring and testing, enabling them to identify exploitable vulnerabilities and fix them as soon as they emerge.”

Extracted Entities