M ManySignal

Telecommunications

Detect subscriber data theft and network core compromise before Salt Typhoon-style access

The Salt Typhoon campaign demonstrated that major carriers can be compromised for years without detection. CDR access, lawful intercept platform abuse, and network management system intrusion are the defining threats. ManySignal monitors across OSS/BSS, subscriber systems, and network management layers.

9 carriers

Confirmed Salt Typhoon victims in the US (2023–2024)

2+ years

Estimated dwell time before Salt Typhoon discovery in some networks

$4.8M

Average cost of a telecom sector data breach (IBM, 2023)

24 hrs

NIS2 initial notification requirement for essential service operators

How ManySignal protects telecom operators

SS7 and network core monitoring

Telecom networks face attacks via SS7/Sigtran protocol exploitation, BGP hijacking, and DNS manipulation that allow adversaries to intercept calls, track subscribers, and redirect traffic. ManySignal integrates with telecom security monitoring platforms and correlates signalling plane anomalies with identity and network events on the operations support system (OSS) and business support system (BSS) layers.

  • Abnormal SS7 location queries and subscriber tracking detection
  • BGP route announcement anomalies correlated with DNS hijacking
  • OSS/BSS privileged access anomaly detection

SS7 and network core monitoring

Subscriber data and CDR protection

Call Detail Records (CDRs), subscriber PII, and lawful intercept infrastructure are high-value targets for both criminal actors and foreign intelligence services (Salt Typhoon compromised major US carriers in 2023–24). ManySignal monitors access to CDR systems, subscriber databases, and provisioning APIs — detecting bulk exports, access by non-authorised operations staff, and unusual API calls to subscriber management platforms.

  • CDR system access baselining per operations role
  • Bulk subscriber data export anomaly detection
  • Lawful intercept infrastructure access monitoring

Subscriber data and CDR protection

Network infrastructure change anomaly detection

Adversaries with access to telecom network management platforms (EMS/NMS) can modify routing configurations, redirect traffic, and persist in network equipment for years. ManySignal monitors network management system access, configuration change events, and firmware update activities — detecting unauthorised configuration modifications and maintenance access outside approved change windows.

  • NMS/EMS configuration change monitoring and alerting
  • Firmware update anomalies — unscheduled updates, unexpected sources
  • Network device access from non-management network segments

Network infrastructure change anomaly detection

Regulatory and compliance frameworks supported

FCC CPNI RulesNIS2 Directive (EU)UK PECRGDPRDORA (financial telecoms)NIST SP 800-187 (5G Security)3GPP Security StandardsCISA Telecom Security Advisories

Telecom security — common questions

How does ManySignal address the Salt Typhoon attack patterns documented by CISA?

Salt Typhoon gained access to US carrier networks through compromised network device credentials, enabling wiretapping and subscriber data access. ManySignal detects the specific patterns documented in CISA Advisory AA24-038A: unusual authentication to network management systems, configuration changes to lawful intercept platforms, and data transfers from subscriber management databases to external endpoints.

Can ManySignal monitor telecom-specific protocols like SS7 and Diameter?

ManySignal integrates with specialist telecom security platforms (P1 Security, Positive Technologies Telecom Attack Discovery) that monitor SS7, Diameter, and GTP protocol layers. These platforms detect signalling-layer attacks (subscriber tracking, call interception, SMS redirection) and forward structured alerts to ManySignal, where they are correlated with OSS/BSS access events in the entity graph.

What regulatory requirements apply to telecom operators, and how does ManySignal support them?

Telecom operators face: CPNI (Customer Proprietary Network Information) rules enforced by the FCC in the US, GDPR for EU subscriber data, UK PECR for communications metadata, and NIS2 for operators of essential services in the EU. ManySignal monitors CDR access for CPNI compliance, tracks GDPR breach notification timelines, and generates NIS2 incident reports within the 24-hour and 72-hour reporting windows.

How does ManySignal handle monitoring for 5G core network environments?

ManySignal ingests logs from 5G core network functions — AMF, SMF, PCF, and UDM — via their syslog and structured log outputs. It monitors API calls to 5G service-based architecture (SBA) interfaces, authentication events for NF consumers, and network slice access control events. The entity graph correlates network function identity with the subscriber management and billing systems to detect cross-function access anomalies.

Does ManySignal provide monitoring for MVNO operators sharing infrastructure with MNOs?

Yes. ManySignal can monitor the logical boundary between MVNO and MNO systems — tracking MVNO access to shared subscriber management APIs, billing system integration events, and CDR sharing. For MVNOs, this provides monitoring over their specific subscriber population without requiring access to the MNO's full network monitoring infrastructure.

See telecom threat detection in action

Walk through Salt Typhoon pattern detection, OSS/BSS access baselining, and CPNI compliance monitoring — in one session with our telecom security team.