The number behind the number
Ninety ransomware attacks on telecom companies in 2025, against twenty-four in 2022. Alongside them, several hundred data-theft incidents and well over a hundred stolen databases offered for sale. The sector’s own analysts put the exposure down to two things: telecoms are critical infrastructure, and they hold high-volume subscriber data.
The second reason is the one that should worry everyone else. Telecom is not special. It is simply an industry where the data is concentrated, well-structured and valuable, held in a small number of systems that many people and many partners can reach. That describes a bank’s customer master, a retailer’s loyalty platform, a hospital’s records system, and almost every enterprise data warehouse we have ever worked in.
The wider figures say the same thing. More than eight thousand organisations were claimed as ransomware targets in 2025, up around a third on the year before, and the number of active crews grew at a similar rate. Attackers are not choosing victims at random. They are going where the data is.
Protected like a server, valued like a business
Here is the gap we see most often. The warehouse, the customer data platform or the analytics lake is treated, operationally, as one more system on the estate: patched on the same cycle, backed up on the same schedule, monitored by the same generic tooling. Meanwhile the business treats it as the single most valuable asset it has, because it is where every customer, every transaction and every relationship is joined together in one place.
Both views are held sincerely, by different teams, and nobody has reconciled them.
A hospital system in the same week’s news illustrates the failure mode: an intrusion first reported as affecting under eight thousand people, later corrected to nearly half a million, with the stolen records eventually published when no ransom was paid. The first number was wrong because nobody knew what the compromised system actually held. In a warehouse, the answer is usually “everything”.
What readiness looks like for a data platform
The controls are not exotic, but they have to be applied deliberately to the data platform rather than inherited from the standard server build.
- Backups an attacker cannot reach. Immutable, off-platform copies with separate credentials. Ransomware crews now routinely delete or encrypt backups first; a backup that shares the warehouse’s admin path is not a backup.
- A restore you have actually rehearsed. The question is not whether the warehouse is backed up. It is how many hours a full restore takes, whether the load pipelines can be replayed from that point, and whether anyone has done it end to end this year. Most organisations have never measured it.
- An inventory of every path in. Telecom attacks were frequently enabled by internet-facing infrastructure and third-party service dependencies. Warehouses have the same profile: BI tools, ETL services, vendor integrations, analyst notebooks, service accounts nobody has reviewed since the person who created them left.
- Knowing what you hold. Classification is not just a privacy exercise. If the platform is breached, the difference between a contained incident and a regulatory event is whether you can say, on day one, which tables contain what.
The new path you are about to open
This is where AI changes the picture, and why the timing matters. Every AI initiative worth doing — retrieval over enterprise data, agents that act on records, assistants grounded in the warehouse — needs a new access path into exactly these systems. Those paths are being opened right now, often quickly, often by teams outside the data platform’s ownership.
Standards bodies have noticed. The same week as the telecom figures, the US national standards institute put out a call for practical methods of securing AI agents, with the sharpest concern reserved for agents that touch critical infrastructure and its data. The regulators’ next attack surface is the one enterprises are building today.
The good news is that the right way to wire AI into a data platform is also the secure way: one governed connector that enforces the warehouse’s own permissions, classification and audit, rather than extracts and side channels. Do that and the AI programme inherits the platform’s controls. Skip it and the AI programme becomes the third-party dependency in next year’s breach report.
The question for this quarter
Not “are we backed up” but: if the warehouse were encrypted tonight, how long to restore, from where, and who has rehearsed it? And a second question, before the next AI pilot opens a connection: who owns every path into this platform, and is the new one on the list?
Attackers have already answered the question of where the data is. The organisations that fare best are the ones that answered it first.
