Insights · Data foundations

Ransomware crews have worked out where the data is. Have you?

Ransomware attacks on telecom operators nearly quadrupled in three years, and the reason is not that telcos are careless. It is that they hold high-volume subscriber data in a few big systems. Every organisation with a data warehouse is in the same position, and most protect it as if it were just another server.

Consulting News Desk9 January 20264 min readData foundations

The number behind the number

Ninety ransomware attacks on telecom companies in 2025, against twenty-four in 2022. Alongside them, several hundred data-theft incidents and well over a hundred stolen databases offered for sale. The sector’s own analysts put the exposure down to two things: telecoms are critical infrastructure, and they hold high-volume subscriber data.

The second reason is the one that should worry everyone else. Telecom is not special. It is simply an industry where the data is concentrated, well-structured and valuable, held in a small number of systems that many people and many partners can reach. That describes a bank’s customer master, a retailer’s loyalty platform, a hospital’s records system, and almost every enterprise data warehouse we have ever worked in.

The wider figures say the same thing. More than eight thousand organisations were claimed as ransomware targets in 2025, up around a third on the year before, and the number of active crews grew at a similar rate. Attackers are not choosing victims at random. They are going where the data is.

Protected like a server, valued like a business

Here is the gap we see most often. The warehouse, the customer data platform or the analytics lake is treated, operationally, as one more system on the estate: patched on the same cycle, backed up on the same schedule, monitored by the same generic tooling. Meanwhile the business treats it as the single most valuable asset it has, because it is where every customer, every transaction and every relationship is joined together in one place.

Both views are held sincerely, by different teams, and nobody has reconciled them.

The warehouse is where an attacker gets everything in one query. It deserves better than the standard build.

A hospital system in the same week’s news illustrates the failure mode: an intrusion first reported as affecting under eight thousand people, later corrected to nearly half a million, with the stolen records eventually published when no ransom was paid. The first number was wrong because nobody knew what the compromised system actually held. In a warehouse, the answer is usually “everything”.

What readiness looks like for a data platform

The controls are not exotic, but they have to be applied deliberately to the data platform rather than inherited from the standard server build.

  • Backups an attacker cannot reach. Immutable, off-platform copies with separate credentials. Ransomware crews now routinely delete or encrypt backups first; a backup that shares the warehouse’s admin path is not a backup.
  • A restore you have actually rehearsed. The question is not whether the warehouse is backed up. It is how many hours a full restore takes, whether the load pipelines can be replayed from that point, and whether anyone has done it end to end this year. Most organisations have never measured it.
  • An inventory of every path in. Telecom attacks were frequently enabled by internet-facing infrastructure and third-party service dependencies. Warehouses have the same profile: BI tools, ETL services, vendor integrations, analyst notebooks, service accounts nobody has reviewed since the person who created them left.
  • Knowing what you hold. Classification is not just a privacy exercise. If the platform is breached, the difference between a contained incident and a regulatory event is whether you can say, on day one, which tables contain what.

The new path you are about to open

This is where AI changes the picture, and why the timing matters. Every AI initiative worth doing — retrieval over enterprise data, agents that act on records, assistants grounded in the warehouse — needs a new access path into exactly these systems. Those paths are being opened right now, often quickly, often by teams outside the data platform’s ownership.

Standards bodies have noticed. The same week as the telecom figures, the US national standards institute put out a call for practical methods of securing AI agents, with the sharpest concern reserved for agents that touch critical infrastructure and its data. The regulators’ next attack surface is the one enterprises are building today.

The good news is that the right way to wire AI into a data platform is also the secure way: one governed connector that enforces the warehouse’s own permissions, classification and audit, rather than extracts and side channels. Do that and the AI programme inherits the platform’s controls. Skip it and the AI programme becomes the third-party dependency in next year’s breach report.

The question for this quarter

Not “are we backed up” but: if the warehouse were encrypted tonight, how long to restore, from where, and who has rehearsed it? And a second question, before the next AI pilot opens a connection: who owns every path into this platform, and is the new one on the list?

Attackers have already answered the question of where the data is. The organisations that fare best are the ones that answered it first.

Consulting News DeskWeekly notes on AI integration, data foundations, and agentic workflows from the IDMS consulting team — written by the people doing the integration work.