The UK’s National Cyber Security Centre CTO rated telco security as ‘C+ at best’ at MWC 2025, citing default passwords and poor configurations as major risks.
The UK’s National Cyber Security Centre (NCSC) has given telecom security a dismal ‘C+’ rating, warning of AI-generated threats and poor configurations at MWC 2025.
Telco security deemed ‘C+ at best’
During a keynote at Mobile World Congress (MWC) 2025 in Barcelona, the Chief Technology Officer of the UK’s National Cyber Security Centre (NCSC) delivered a stark assessment of global telecom security, rating it as ‘C+ at best.’ The official cited persistent issues like default passwords, misconfigurations, and sluggish patch management as critical weaknesses.
The NCSC’s report, released alongside the announcement, highlights how these vulnerabilities are exploited by both opportunistic hackers and state-linked groups, particularly those with ties to China. The findings were based on data collected from telecom operators and cybersecurity firms over the past year.
AI-generated fakes and emerging threats
Among the newly identified risks, the report emphasizes the growing use of AI-generated deepfakes and voice cloning in phishing and social engineering attacks. ‘Adversaries are no longer just relying on traditional malware—they’re crafting hyper-realistic impersonations to bypass authentication,’ the NCSC CTO stated.
One cited example involved a European telco that lost millions after fraudsters used AI to mimic a senior executive’s voice in a funds transfer scam. The incident was first reported by a cybersecurity blog last month.
Three key areas for improvement
The NCSC outlined three critical focus areas for telecom providers: securing their own networks, protecting enterprise clients, and safeguarding end-users. Recommendations include mandatory multi-factor authentication, automated patch deployment, and AI-driven anomaly detection.
Industry analysts at MWC noted that while some major carriers have adopted these measures, smaller operators lag behind due to budget constraints. A Verizon representative, speaking on a panel, confirmed that the company has already implemented AI-based threat detection but acknowledged that ‘the arms race with attackers never stops.’
As 5G and IoT adoption accelerates, experts warn that without rapid improvements, the ‘C+’ grade could soon slip further. The full NCSC report is available on their official website.