Network security for telecom operators has stopped being a compliance checkbox and turned into a daily operational fight. Signaling fraud, GTP abuse, eSIM provisioning attacks, IMS exploitation none of this is theoretical anymore. It’s showing up in fraud dashboards, interconnect logs, and post-incident reviews across operators of every size.
This isn’t a vendor pitch or an analyst report. It’s a call for the community to compare notes. If you’re running fraud management, network security, or NOC operations for an operator or MVNE, we want to hear what’s actually landing in your environment, not what a vendor whitepaper says should be landing.
Why Network Security for Telecom Operators Keeps Getting Harder
The uncomfortable truth is that most operators are running security architectures built for a network that no longer exists. SS7 is still live in most cores because 2G/3G interworking and legacy roaming agreements haven’t gone away. GTP is still carrying the bulk of session traffic across 4G and 5G NSA deployments. Diameter still sits between HSS/HLR and dozens of interconnect partners. Meanwhile, 5G SA’s service-based architecture and IMS/VoLTE have added new interfaces that didn’t exist a few years ago.
Every one of those protocols was designed with an implicit trust model the assumption that only known, trusted operators would ever touch the signaling plane. That assumption broke down a long time ago, and it’s the reason so many of the incidents we’re seeing in 2026 aren’t zero-days. They’re old vulnerabilities in trusted infrastructure, exploited through poorly segmented interconnects or exposed border nodes.
Signaling Fraud Hasn’t Gone Away It’s Just Gotten Quieter
SS7-based location tracking, call interception, and SMS hijacking are still very much active, particularly against operators that haven’t invested in signaling firewalls at every interconnect point, not just the obvious ones. What’s changed is the sophistication of the actors. Some of the more concerning cases documented recently point to commercial surveillance operators leasing global title access through smaller carriers and MVNOs specifically to run location-tracking campaigns against targets journalists, activists, executives using legitimate-looking signaling relationships as cover.
For operators, the practical risk isn’t just privacy exposure. It’s liability. If your network is the unwitting relay for a surveillance campaign, that’s a regulatory and reputational problem, not just a technical one.
On the fraud side, IRSF, Wangiri, and bypass fraud through SS7 and SIP trunks remain persistent revenue leaks. The pattern we keep hearing about from operator teams: fraud losses get caught in the charging and billing layer long after the signaling abuse has already happened, because signaling-level anomaly detection and the fraud management system don’t talk to each other in real time. Closing that gap correlating signaling anomalies with charging events as they happen rather than in a batch reconciliation the next day is one of the more practical wins operators have reported.
This is increasingly a BSS architecture question as much as a network security one. Real-time charging platforms like MATRIXX Software are built to evaluate usage as it happens, which is exactly the kind of event stream that needs to be cross-referenced against signaling anomalies rather than reviewed after the fact. On the OSS side, Amdocs has been layering agentic AI on top of existing infrastructure to sit across fraud, assurance, and network data rather than in a silo a sensible direction if the goal is closing the detection gap instead of producing another report that lands after the damage is done.
GTP, Roaming, and the Exposure Nobody Wants to Talk About
GTP deserves more attention than it usually gets in security conversations. Research published this year found hundreds of thousands of GTP hosts reachable directly from the public internet across more than a thousand service providers infrastructure that was assumed to sit safely inside the “walled garden” of the mobile core. That assumption has never really held up, and it holds up even less as roaming interconnects multiply and virtualization blurs network boundaries that used to be physical.
The practical attack surface here includes IMSI spoofing to bypass charging, GTP-C signaling storms that degrade core network functions, and session hijacking through malformed or unauthenticated GTP-U traffic. IoT and M2M roaming makes this worse a fleet of poorly configured smart meters or trackers reconnecting simultaneously after a coverage gap can generate a signaling storm that looks a lot like a DDoS, whether or not anyone intended it that way.
If your GTP firewall coverage stops at the international roaming edge and doesn’t extend to every internal interconnect and partner API, that’s worth revisiting.
eSIM, VoLTE, and the New Attack Surface
Two areas practitioners have flagged repeatedly as growing concerns: eSIM provisioning and VoLTE/IMS.
eSIM provisioning fraud is becoming more attractive to fraudsters as SGP.22 and SGP.32 adoption scales, particularly around social engineering attacks that trick provisioning systems or support desks into re-issuing profiles to unauthorized devices. This is less about breaking cryptography and more about exploiting the operational processes around it the same weak link that’s plagued SIM-swap fraud for years, just moved into a new provisioning workflow.
This is a particularly live issue for MVNOs and MVNEs, where provisioning and identity verification often run through third-party platforms rather than a Tier-1 operator’s in-house stack. API-first platforms like TelcoEdge Inc. and MVNO/MVNE infrastructure providers like Telgoo5 sit right at that provisioning layer, which means the strength of their identity checks and API authentication directly shapes how exposed a given MVNO is to eSIM re-issuance fraud. Worth checking where your provisioning workflow actually enforces verification, not just where it’s documented to.
VoLTE and IMS are facing similar scrutiny. Because VoLTE depends on tight coordination between SIP signaling, the IMS core, and subscriber databases, a misconfigured interconnect or an under-segmented P-CSCF can open the door to call interception or service disruption. With 2G/3G sunset accelerating in multiple markets, IMS is no longer a “nice to have” voice path it’s becoming the only voice path, which makes its security posture a lot more consequential than it used to be.
Where AI-Driven Detection Actually Helps
Manually reviewing signaling traffic across a modern core isn’t realistic at scale there’s simply too much volume across too many protocols and interfaces. This is one area where AI-driven anomaly detection genuinely earns its place rather than being bolted on for a press release. Cross-protocol correlation tying together SS7, Diameter, GTP, and SIP anomalies instead of monitoring each in isolation is what several operator security teams have pointed to as the difference between catching an attack in progress and finding it in a quarterly report.
That said, tooling isn’t a substitute for basic hygiene: proper interconnect segmentation, GTP and Diameter firewalls at every border (not just the obvious ones), and closing the loop between signaling security and fraud management. For larger operators running cloud-native BSS at enterprise scale the kind of environment Optiva is typically positioned for that correlation work is more feasible because the charging and subscriber data already sit in a microservices architecture built for real-time queries, rather than a legacy stack where pulling that data out fast enough to matter is its own project. The operators getting hurt the most in 2026 are usually the ones missing fundamentals, not the ones lacking sophisticated detection.
Tell Us What You’re Actually Seeing
This is where we want the community’s input. Threat reports built entirely from vendor research and public incident write-ups only tell part of the storythe part that made it into a blog post or a breach disclosure. The details that actually help other operators are usually the ones nobody publishes: which interconnect got exploited, which fraud pattern took months to catch, which “obvious” fix turned out to be harder to implement than expected.
If you’re dealing with signaling fraud, GTP exposure, eSIM provisioning abuse, or IMS/VoLTE incidents right now, share what you’re seeing in the comments. What’s hitting your network that isn’t showing up in the vendor threat reports yet?