Home/Services/Telecom Penetration Testing
security service

Telecom Penetration Testing

Telecom penetration testing for OSS/BSS, self-service portals, VoIP and 5G core. Protect subscriber data. Manual, fixed-price, with a free retest.

Manual, expert-ledEvidence-based findingsFree remediation retest

Telecom penetration testing has to cover far more than a website, because a telco’s attack surface runs from the self-service portal a subscriber logs into all the way down to the provisioning systems, the VoIP platform and the 5G core behind them. We test that full stack by hand, under NDA, so subscriber data and service integrity are protected end to end.

SafetyBis is a European offensive-security team working with operators, MVNOs and service providers across Europe. Telco environments are large, layered and interconnected, and they hold exactly the data attackers want: subscriber identities, call records and the keys to number portability and SIM control. We scope to that reality rather than treating a carrier like an ordinary web shop.

What telecom penetration testing actually covers

Scope tracks the subscriber journey and the systems that support it: the customer-facing portals and apps, the OSS and BSS platforms that provision and bill them, the voice infrastructure, and the network core.

OSS and BSS platforms: provisioning, billing and order management
Subscriber self-service portals and account APIs
SIM and eSIM provisioning and number-portability flows
VoIP and SIP infrastructure, including toll-fraud exposure
5G core and signaling interfaces, tested for exposure and access
Mobile apps for customer self-service, iOS and Android
External network, roaming interconnects and management surfaces

SIM and number-portability flows are the sharpest edge. A weakness that lets an attacker swap a SIM or port a number is the mechanism behind account-takeover fraud that reaches far beyond the telco, into a victim’s banking and email. We treat those flows as high-value targets, not edge cases.

How we test

Telecom penetration testing at SafetyBis is manual and evidence-based. Burp Suite drives the portal and API testing, nmap and ffuf handle discovery, and specialist analysis covers SIP, signaling and the mobile clients. The findings that matter come from an engineer reasoning about how a subscriber, a fraudster or a rogue insider would abuse the system.

Reconnaissance and mapping

We enumerate the external estate: self-service portals, developer and partner APIs, provisioning interfaces, management panels and roaming or interconnect endpoints. Large operators accumulate forgotten systems, and this stage routinely surfaces a legacy portal or an exposed OSS interface that should never face the internet.

Application, API and mobile testing

With subscriber and staff-level accounts we test access control across the portal and its API, the mobile app and its backend, and the provisioning workflows. Subscriber APIs commonly leak other customers’ data through broken object-level authorization, and self-service actions frequently lack proper server-side checks.

Voice, signaling and exploitation

We assess the SIP and VoIP layer for authentication weaknesses and toll-fraud exposure, and evaluate access to signaling and 5G core interfaces where they are in scope. Exploitation is demonstrated safely, proving impact such as unauthorized provisioning or subscriber-data access without disrupting live service.

Reporting

Every finding carries a CVSS score, reproduction and a prioritized fix. Critical issues, especially anything touching SIM control or subscriber data, are escalated the day we confirm them.

48h
typical time to first findings
100%
manual verification across the full stack
Free
retest after you fix

Common vulnerabilities we find in telecom systems

Broken authorization in subscriber APIs

The self-service API returns account, usage or call-record data keyed on a subscriber identifier with no ownership check. This IDOR pattern is the most common serious finding we report for operators, and at telco scale it is a mass-data-exposure risk.

SIM-swap and number-portability abuse

Provisioning and port-out flows that rely on weak verification or lack server-side controls, allowing an attacker to take over a number. The downstream impact (defeating SMS-based authentication for the victim’s other accounts) makes this a top-severity finding.

Authentication and account-takeover flaws

Weak password reset, guessable session tokens, and self-service functions guarded only in the app. We test these against OWASP ASVS rather than assuming the platform got them right.

VoIP toll fraud and SIP weaknesses

SIP endpoints with weak or default credentials and dial-plan flaws that let an attacker place premium or international calls at your expense. Toll fraud is a direct financial loss, sometimes very large, over a single weekend.

Exposed OSS/BSS and management interfaces

Provisioning, billing and management systems reachable from the internet or from a weakly segmented network, giving an attacker use over service and revenue.

Business-logic abuse in plans and top-ups

The flaws unique to how a telco actually bills. A top-up flow that credits an account before the payment clears, a plan-change API that applies a discount the subscriber is not entitled to, a promotional-code endpoint with no server-side limit on redemptions. None of these looks like a classic vulnerability, and a scanner walks straight past them, but each is a direct hit on revenue that only a human testing the workflow will catch.

Insecure mobile-app storage and traffic

Self-service apps that cache tokens or personal data in cleartext on the device, pin certificates weakly or not at all, or trust responses the backend should have validated. A lost phone should never become a lost account, and we test whether that holds under OWASP MASVS-style scrutiny.

Tools and techniques

Burp Suite Professional handles the portal, API and mobile-backend testing, including REST and GraphQL. nmap maps the external and internal network and its segmentation, ffuf drives content and parameter discovery, and we use mobile penetration testing techniques for the iOS and Android self-service apps, inspecting traffic, storage and client-side controls. SIP and signaling get specialist analysis. Findings map to OWASP ASVS and the API Security Top 10, with attack paths described against MITRE ATT&CK.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

What you get

Executive summary framed around subscriber trust and revenue risk
Technical report with CVSS and reproduction per finding
A focused assessment of SIM-swap and account-takeover exposure
Prioritized remediation your platform and network teams can action
An attestation letter for regulators, ISO 27001 and enterprise customers
A free retest once fixes are deployed

For an operator, the report is also a governance document. It gives your board and your regulator evidence that the systems holding subscriber data and controlling numbers have been tested independently.

Compliance and standards

NIS2

Telecom providers are essential entities under NIS2, and many also carry obligations under the earlier telecoms security regimes. A penetration test evidences the risk-management and testing measures those rules require.

GDPR

Subscriber data, call records and location data are personal data of the most sensitive kind. GDPR expects appropriate technical measures and testing of them, and our report is direct evidence of that.

ISO 27001 and PCI DSS

Where you pursue ISO 27001, the report supports Annex A including A.12.6. Where you take card payments for top-ups and bills, it addresses the external-testing expectation of PCI DSS requirement 11.4.

Why manual testing beats a scanner for a telco

A scanner cannot reason about a number-portability workflow, so it will never find the flaw that lets an attacker steal a subscriber’s number. It cannot understand that one subscriber’s API response should never contain another’s call records. The highest-impact telco findings are business-logic and authorization failures across a stack that mixes web, mobile, voice and signaling, and finding them takes engineers who understand how a carrier actually works. A scanner would also risk destabilising sensitive provisioning and voice systems; we test them by hand, carefully, without knocking service over.

The SIM-swap chain is the clearest example of why this matters. An attacker gathers a target’s details from a data breach elsewhere, opens a support or self-service port-out request, and the only thing standing between them and the victim’s number is your verification logic. If that logic can be satisfied with information an attacker can buy, the number moves, the SMS codes follow, and within minutes the victim’s bank and email are open. No signature-based tool models that path, because every individual request in it looks legitimate. Testing it means an engineer role-playing the fraudster against your real workflow and finding the step where a human decision should have blocked them and did not. That is the difference between a report that lists issues and one that prevents the fraud your subscribers would otherwise blame you for.

Who books this and when

Security and platform leaders at operators, MVNOs and service providers come to us before launching a new self-service portal or app, after a fraud incident involving SIM swaps or toll fraud, ahead of a NIS2 or ISO 27001 milestone, or when an enterprise or wholesale customer demands proof of security. If your systems hold subscriber identities or control numbers, and they do, the test is a core part of running the network responsibly.

Pricing

Telecom penetration testing cost depends on scope: how many portals, APIs and apps, whether OSS/BSS, VoIP and signaling are in play, and the size of the network. Every engagement is fixed-price after scoping.

Engagement What’s included Timeline Price
Portal / app Subscriber self-service portal or mobile app plus its API, authentication and access-control testing, full report and free retest 4–8 working days €2,500–€8,000
OSS/BSS and provisioning Provisioning, billing and order-management platforms, SIM/eSIM and number-portability flow testing, business-logic abuse, exec plus technical report 8–12 working days €8,000–€20,000
Voice and network VoIP and SIP toll-fraud testing, internal network and segmentation, signaling and 5G core interface access where in scope from €4,000, typical €4,000–€9,000 €4,000–€9,000
Compliance add-on Mapping and attestation letter for NIS2, ISO 27001, GDPR or PCI DSS with any tier from €800
Custom / carrier estate Full multi-system environment across OSS/BSS, voice and core, scoped to the operator on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a retest is included. Get a fixed quote

FAQ

How much does telecom penetration testing cost?
Portal and app testing runs €2,500–€8,000, OSS/BSS and provisioning work €8,000–€20,000, and voice and network testing from €4,000. The exact cost is fixed after a free scoping call, based on how many systems are in scope.
Do you test for SIM-swap and number-portability abuse?
Yes, and we treat it as a top-priority target. We test whether provisioning and port-out flows can be abused to take over a number, because that undermines SMS-based authentication for the victim’s other accounts.
Can you assess VoIP and SIP for toll fraud?
Yes. We test SIP endpoints and dial plans for weak credentials and misconfigurations that let an attacker place premium or international calls at your expense, which is a direct and sometimes very large financial loss.
Do you do mobile penetration testing of our self-service app?
Yes. Our mobile penetration testing covers the iOS and Android apps and their backend APIs, inspecting traffic, local storage and client-side controls for account-takeover and data-exposure flaws.
Will testing disrupt live service or subscribers?
No. We test provisioning and voice systems by hand and carefully, agree any intrusive checks in advance, and can run them out of hours or against staging so live service is not affected.
Does this satisfy NIS2 and GDPR?
Yes. As an essential entity under NIS2 you must test your risk-management measures, and GDPR expects testing of the technical protection around subscriber data. The report and attestation letter evidence both.
Can you test OSS/BSS and 5G core interfaces?
Yes, where they are in scope. We assess provisioning, billing and order-management platforms and evaluate access to signaling and 5G core interfaces, focusing on exposure and unauthorized access without disrupting the network.
Is the retest included?
Yes, and free. After your teams remediate we retest the findings and update the report and attestation to confirm the fixes hold.
Which telecom-specific systems do you cover, from OSS/BSS to signalling?
We test the customer-facing portals and self-service apps, the OSS/BSS and provisioning back ends, the APIs behind number porting and SIM management, and the signalling and interconnect exposure that enables SIM-swap and toll fraud. Each finding is tied to the fraud or abuse it enables, so your team can prioritise the ones that cost real money.

Related services

Who needs this

Mobile and fixed operators, MVNOs and service providers across Europe running OSS/BSS, self-service portals, VoIP and network core, who hold subscriber data and control numbers and must satisfy NIS2, GDPR and enterprise-customer security demands.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Telecom Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.