Header illustration for "Deep access in the phone company: what telecom APTs mean for Australian users"

"Deep access in the phone company: what telecom APTs mean for Australian users"

Deep access in the phone company: what telecom APTs mean for Australian users

When a state-sponsored group breaches a mobile carrier, the impact runs downhill fast: call records and location metadata for millions of subscribers, the ability to intercept or redirect SMS — including the SMS one-time codes that still guard most banking — and, in the worst cases, live access to the core network itself. Hackers Arise's article on Chinese APT intrusions into mobile networks dissects the anatomy of these operations: patient infiltration of carrier infrastructure, dwelling inside signalling and management systems, and harvesting subscriber data at scale. Australia has spent a decade building policy specifically against this class of threat, and the history is worth knowing.

Australia's telecom supply-chain hardening, briefly

In August 2018, the Morrison government directed Australian carriers not to use Chinese vendors Huawei and ZTE in 5G rollouts, citing high-risk-vendor security concerns — a decision reported at the time by ITNews/ACS coverage and later formalised through security legislation covering telecommunications providers. The 2018 Telecommunications Sector Security Reforms obliged carriers to notify government of security risks, and subsequent critical-infrastructure reforms tightened the regime further. Australia was the first Five Eyes country to move; the US and UK followed within two years.

The rationale has aged well. ASIO Director-General Mike Burgess has said publicly that Chinese state-linked hackers are probing Australia's telecommunications and critical infrastructure for pre-positioning — access that could be used for disruption in a crisis — remarks reported by Reuters and the ABC from his 2025 threat assessments, where he also noted espionage and foreign interference at extreme levels in ASIO's annual reporting.

What it means for an Australian user, practically

You cannot audit your carrier's core network. You can change what a carrier breach would cost you:

Remove SMS as a security anchor. SIM-swap and interception risk means SMS two-factor is the weakest link protecting your banking and email. Move to hardware-backed or app-based factors. A FIDO2 security key (A$39.90, our own stock — disclosed) is phishing-resistant in a way SMS cannot be, and works with every major AU bank's web login that supports passkeys.

Assume metadata sensitivity. Who you call, when, from where — that is the data carriers hold by law under the metadata retention scheme we cover in our metadata explainer. If a relationship or reporting source needs protection, use end-to-end encrypted channels as the default, not the exception.

Diversify identity. A single phone number as the recovery key for everything is a single point of failure. Our degoogled phone comparison covers devices that reduce platform-level exposure; the same logic applies to keeping your number out of as many account records as possible.

The limits of personal action

Consumer hardening does not fix a core-network compromise; that is what the sector-security regime, ASIO and the carriers' own security teams are for. What consumer hardening does is change the blast radius: a carrier breach that nets metadata still leaves your accounts phishing-resistant, and an SMS interception still finds no password-reset path into your email. That is the difference between an incident and a catastrophe.

This article is general information, not legal or security advice. Threat descriptions summarise public statements by Australian government agencies and reputable press reporting.

Sources: Hackers Arise — Chinese APT Intrusions into Our Mobile Networks · Reuters — Australian spy chief on Chinese hackers probing telecoms · ABC News — Burgess threat assessment · ASIO Annual Report · ACS — 2018 Huawei/ZTE 5G exclusion

Header image: Wikimedia Commons, "Mobile phone tower, Gascoyne Junction, July 2020" by Calistemon, CC BY-SA 4.0.

← All posts