Networks & InfrastructureStrikeNetwork SecurityInfrastructure VandalismCable Theft
Network Attacks Climb Past 2025 Levels as STRIKE Members Fight Back
US operators tracked 18,327 network incidents hitting 11.8 million customers in 2025 — already surpassed this year. Comcast's count has doubled; AT&T arrests rose 230% in 90 days.
Networks & InfrastructureWhy it matters
- 18,327 incidents affecting 11.8 million customers tracked in 2025; surpassed by September 2026.
- Comcast logged ~408 incidents this year (~40/month), roughly double the 2025 pace.
- AT&T saw a 230% increase in arrests in the last 90 days.
- STRIKE created a critical infrastructure protection subcommittee at its July meeting.
- Comcast is deploying AI-assisted fiber sensing to pinpoint cuts and identify causes.
The story
US operators tracked 18,327 network vandalism and theft incidents affecting about 11.8 million customers in 2025 — and that figure was already surpassed by September of this year. Rikin Thakker, CTO of the NCTA–The Internet & Television Association, called the 2025 numbers conservative and said broadband networks remain "under attack" and need a unified policy response.
The figures came last week at the SCTE TechExpo in Atlanta, where executives from STRIKE member companies described both the worsening threat picture and the first signs that enforcement is working. STRIKE — the Strategic Threat Response & Infrastructure Knowledge Exchange — launched last fall as a cable industry initiative and went cross-industry earlier this year with backing from AT&T, T-Mobile and Verizon. Its goals include intelligence sharing, operational protocols and a unified policy strategy that frames certain infrastructure attacks as potential national security threats.
How bad is it for each operator?
Comcast has logged roughly 408 incidents this year, about 40 per month on average — approximately double the count at the same point in 2025, according to Tony Speller, SVP of network operations at Comcast.
AT&T has already recorded more network-related theft and vandalism incidents in 2026 than in all of last year, said Alisha Remek, AT&T's VP of access construction and engineering – HQ wireline, wireless and ACE systems. "It's definitely intentional, definitely rampant … They're attacking us on all fronts," she said, noting that criminals are willing to pop manhole covers and climb into watery conduits to reach central office equipment.
Spectrum has seen incident numbers double and spread into new regions, including the southeast, according to Tom Monaghan, EVP of field operations. He said activity is starting to slow in Texas, where enforcement has strengthened — a "ray of hope."
T-Mobile reports criminals "going straight for cell towers," yanking down fiber and stealing electronics from cabinets, said Lori Ames, SVP of network infrastructure and operations. Verizon's Leo Perreault, VP of network engineering and operations, said the level of "aggression" keeps rising, with California — Los Angeles in particular — remaining a hotspot. Verizon's focus on the area helped take down what Perreault called a "mini crime ring" in Los Angeles.
Are arrests finally catching up with attackers?
Yes, at least at AT&T. Remek said the company has recorded a 230% increase in arrests in the last 90 days alone, helped by growing support from local law enforcement. T-Mobile credits its work with police with collecting the evidence needed to catch and prosecute offenders.
Spectrum, meanwhile, continues to label attacks on networks serving military bases, hospitals and 911 centers as "domestic terrorism."
On the policy side, STRIKE is gaining traction at local, state and federal levels, though incident volumes have not slowed. SCTE CEO Maria Popo said a critical infrastructure protection subcommittee was created at the July meeting. It will prioritize areas such as evidence collection, since law enforcement does not always reach the scene before repairs begin, and will examine standards for trenching and how they might limit both accidental and deliberate fiber cuts. Popo also raised the idea of partnering with other organizations on a "rewards pool" for tips that lead to arrests.
What are operators doing technically?
Operators are also working to shrink the "blast radius" of attacks through engineering measures:
- Comcast is adding redundant circuits so a single cut cannot take down an entire site, splitting up areas with high fiber counts (400 or more), and pre-staging fiber splicers for rapid response.
- Comcast is deploying new AI-assisted "fiber sensing technology" that rapidly pinpoints fiber cuts, uses a catalog of alarm signatures to distinguish causes — a jackhammer at a nearby construction site, for example — and can flag issues before severe damage occurs. It is also exploring automatic dispatch of camera-equipped drones to sites where alarms trigger.
- Spectrum is adding third routes to several areas and moving aerial plant underground where possible to harden the network.
- AT&T has introduced 24/7 monitoring of certain infrastructure, including central offices, and is putting locks on manholes.
The immediate outlook is mixed: incident counts keep climbing and 2026 has already overtaken the full-year 2025 total, but stronger enforcement in states such as Texas and rising arrest numbers suggest the cross-industry coalition's coordinated approach — backed by STRIKE's new subcommittee work on standards and evidence collection — may start to bend the curve.
Also reported
Original: corporate.comcast.com
More from Elena Vasquez
Show full bio
Market editor covering consumer brands and retail at Telecom Gazette.
152 articles