Telecom Penetration Testing
Telecom penetration testing for OSS/BSS, self-service portals, VoIP and 5G core. Protect subscriber data. Manual, fixed-price, with a free retest.
Telecom penetration testing has to cover far more than a website, because a telco’s attack surface runs from the self-service portal a subscriber logs into all the way down to the provisioning systems, the VoIP platform and the 5G core behind them. We test that full stack by hand, under NDA, so subscriber data and service integrity are protected end to end.
SafetyBis is a European offensive-security team working with operators, MVNOs and service providers across Europe. Telco environments are large, layered and interconnected, and they hold exactly the data attackers want: subscriber identities, call records and the keys to number portability and SIM control. We scope to that reality rather than treating a carrier like an ordinary web shop.
What telecom penetration testing actually covers
Scope tracks the subscriber journey and the systems that support it: the customer-facing portals and apps, the OSS and BSS platforms that provision and bill them, the voice infrastructure, and the network core.
SIM and number-portability flows are the sharpest edge. A weakness that lets an attacker swap a SIM or port a number is the mechanism behind account-takeover fraud that reaches far beyond the telco, into a victim’s banking and email. We treat those flows as high-value targets, not edge cases.
How we test
Telecom penetration testing at SafetyBis is manual and evidence-based. Burp Suite drives the portal and API testing, nmap and ffuf handle discovery, and specialist analysis covers SIP, signaling and the mobile clients. The findings that matter come from an engineer reasoning about how a subscriber, a fraudster or a rogue insider would abuse the system.
Reconnaissance and mapping
We enumerate the external estate: self-service portals, developer and partner APIs, provisioning interfaces, management panels and roaming or interconnect endpoints. Large operators accumulate forgotten systems, and this stage routinely surfaces a legacy portal or an exposed OSS interface that should never face the internet.
Application, API and mobile testing
With subscriber and staff-level accounts we test access control across the portal and its API, the mobile app and its backend, and the provisioning workflows. Subscriber APIs commonly leak other customers’ data through broken object-level authorization, and self-service actions frequently lack proper server-side checks.
Voice, signaling and exploitation
We assess the SIP and VoIP layer for authentication weaknesses and toll-fraud exposure, and evaluate access to signaling and 5G core interfaces where they are in scope. Exploitation is demonstrated safely, proving impact such as unauthorized provisioning or subscriber-data access without disrupting live service.
Reporting
Every finding carries a CVSS score, reproduction and a prioritized fix. Critical issues, especially anything touching SIM control or subscriber data, are escalated the day we confirm them.
Common vulnerabilities we find in telecom systems
Broken authorization in subscriber APIs
The self-service API returns account, usage or call-record data keyed on a subscriber identifier with no ownership check. This IDOR pattern is the most common serious finding we report for operators, and at telco scale it is a mass-data-exposure risk.
SIM-swap and number-portability abuse
Provisioning and port-out flows that rely on weak verification or lack server-side controls, allowing an attacker to take over a number. The downstream impact (defeating SMS-based authentication for the victim’s other accounts) makes this a top-severity finding.
Authentication and account-takeover flaws
Weak password reset, guessable session tokens, and self-service functions guarded only in the app. We test these against OWASP ASVS rather than assuming the platform got them right.
VoIP toll fraud and SIP weaknesses
SIP endpoints with weak or default credentials and dial-plan flaws that let an attacker place premium or international calls at your expense. Toll fraud is a direct financial loss, sometimes very large, over a single weekend.
Exposed OSS/BSS and management interfaces
Provisioning, billing and management systems reachable from the internet or from a weakly segmented network, giving an attacker use over service and revenue.
Business-logic abuse in plans and top-ups
The flaws unique to how a telco actually bills. A top-up flow that credits an account before the payment clears, a plan-change API that applies a discount the subscriber is not entitled to, a promotional-code endpoint with no server-side limit on redemptions. None of these looks like a classic vulnerability, and a scanner walks straight past them, but each is a direct hit on revenue that only a human testing the workflow will catch.
Insecure mobile-app storage and traffic
Self-service apps that cache tokens or personal data in cleartext on the device, pin certificates weakly or not at all, or trust responses the backend should have validated. A lost phone should never become a lost account, and we test whether that holds under OWASP MASVS-style scrutiny.
Tools and techniques
Burp Suite Professional handles the portal, API and mobile-backend testing, including REST and GraphQL. nmap maps the external and internal network and its segmentation, ffuf drives content and parameter discovery, and we use mobile penetration testing techniques for the iOS and Android self-service apps, inspecting traffic, storage and client-side controls. SIP and signaling get specialist analysis. Findings map to OWASP ASVS and the API Security Top 10, with attack paths described against MITRE ATT&CK.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you get
For an operator, the report is also a governance document. It gives your board and your regulator evidence that the systems holding subscriber data and controlling numbers have been tested independently.
Compliance and standards
NIS2
Telecom providers are essential entities under NIS2, and many also carry obligations under the earlier telecoms security regimes. A penetration test evidences the risk-management and testing measures those rules require.
GDPR
Subscriber data, call records and location data are personal data of the most sensitive kind. GDPR expects appropriate technical measures and testing of them, and our report is direct evidence of that.
ISO 27001 and PCI DSS
Where you pursue ISO 27001, the report supports Annex A including A.12.6. Where you take card payments for top-ups and bills, it addresses the external-testing expectation of PCI DSS requirement 11.4.
Why manual testing beats a scanner for a telco
A scanner cannot reason about a number-portability workflow, so it will never find the flaw that lets an attacker steal a subscriber’s number. It cannot understand that one subscriber’s API response should never contain another’s call records. The highest-impact telco findings are business-logic and authorization failures across a stack that mixes web, mobile, voice and signaling, and finding them takes engineers who understand how a carrier actually works. A scanner would also risk destabilising sensitive provisioning and voice systems; we test them by hand, carefully, without knocking service over.
The SIM-swap chain is the clearest example of why this matters. An attacker gathers a target’s details from a data breach elsewhere, opens a support or self-service port-out request, and the only thing standing between them and the victim’s number is your verification logic. If that logic can be satisfied with information an attacker can buy, the number moves, the SMS codes follow, and within minutes the victim’s bank and email are open. No signature-based tool models that path, because every individual request in it looks legitimate. Testing it means an engineer role-playing the fraudster against your real workflow and finding the step where a human decision should have blocked them and did not. That is the difference between a report that lists issues and one that prevents the fraud your subscribers would otherwise blame you for.
Who books this and when
Security and platform leaders at operators, MVNOs and service providers come to us before launching a new self-service portal or app, after a fraud incident involving SIM swaps or toll fraud, ahead of a NIS2 or ISO 27001 milestone, or when an enterprise or wholesale customer demands proof of security. If your systems hold subscriber identities or control numbers, and they do, the test is a core part of running the network responsibly.
Pricing
Telecom penetration testing cost depends on scope: how many portals, APIs and apps, whether OSS/BSS, VoIP and signaling are in play, and the size of the network. Every engagement is fixed-price after scoping.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Portal / app | Subscriber self-service portal or mobile app plus its API, authentication and access-control testing, full report and free retest | 4–8 working days | €2,500–€8,000 |
| OSS/BSS and provisioning | Provisioning, billing and order-management platforms, SIM/eSIM and number-portability flow testing, business-logic abuse, exec plus technical report | 8–12 working days | €8,000–€20,000 |
| Voice and network | VoIP and SIP toll-fraud testing, internal network and segmentation, signaling and 5G core interface access where in scope | from €4,000, typical €4,000–€9,000 | €4,000–€9,000 |
| Compliance add-on | Mapping and attestation letter for NIS2, ISO 27001, GDPR or PCI DSS | with any tier | from €800 |
| Custom / carrier estate | Full multi-system environment across OSS/BSS, voice and core, scoped to the operator | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a retest is included. Get a fixed quote
FAQ
How much does telecom penetration testing cost?
Do you test for SIM-swap and number-portability abuse?
Can you assess VoIP and SIP for toll fraud?
Do you do mobile penetration testing of our self-service app?
Will testing disrupt live service or subscribers?
Does this satisfy NIS2 and GDPR?
Can you test OSS/BSS and 5G core interfaces?
Is the retest included?
Which telecom-specific systems do you cover, from OSS/BSS to signalling?
Related services
Mobile and fixed operators, MVNOs and service providers across Europe running OSS/BSS, self-service portals, VoIP and network core, who hold subscriber data and control numbers and must satisfy NIS2, GDPR and enterprise-customer security demands.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.