Telecom
Beware of Quishing: The New QR Code Scam You Need to Know About – Sophos

Sophos, a global leader of innovative security solutions for defeating cyberattacks, has released the results of Sophos X-Ops research on a new type of threat: quishing.

This new attack vector involves the use of fraudulent QR codes, emailed by threat actors, to bypass the phishing security measures put in place by companies.
This fraudulent QR code, embedded in a PDF document attached to an email, takes the form of a message about payroll, employee benefits, or other forms of official paperwork a business might send to an employee. Because QR codes are not readable by computers, the employee must scan the QR code using their mobile phone.
The QR code links to a phishing page, which the employee may not recognize as malicious since phones usually are less protected than a computer. The goal of the attackers is to capture employees’ passwords and their multi-factor authentication (MFA) tokens in order to access a company’s system by bypassing the security measures in place.
“We spent a considerable amount of time sifting through all the spam samples we had to find examples of quishing,” comments Andrew Brandt, principal researcher at Sophos X-Ops. “Our research has revealed that attacks that exploit this specific threat vector are intensifying, both in terms of volume and sophistication, especially when it comes to the appearance of the PDF document. »
In addition to social engineering tactics, the quality of emails, attachments and QR code graphics, these attacks seem to be growing in terms of organization as well. Indeed, some malicious actors now offer as-a-service tools to run phishing campaigns using fraudulent QR codes. In addition to features such as CAPTCHA bypasses or the generation of IP address proxies to bypass automated threat detection, these criminal organizations provide a sophisticated phishing platform that can capture the credentials or MFA tokens of targeted individuals.
To encourage organizations to better protect systems against this type of attack, Sophos X-Ops shares a list of recommendations:
· Be vigilant about internal emails about HR topics, salaries or company benefits: Sophos X-Ops’ research has found that social engineering tricks exploit these themes to trick employees into scanning fraudulent QR codes from their mobile devices.
· Install Sophos Intercept X for Mobile : Available on Android, iOS and Chrome OS, this solution includes a secure QR code scanner that helps identify known phishing websites and alert if the URL is considered malicious.
· Monitor risky sign-ins: Using identity management tools, organizations can detect unusual sign-in activity.
· Enable Conditional Access: This feature helps enforce access controls based on the user’s location, device status and risk.
· Enable effective access monitoring thanks to sophisticated logs: this type of advanced monitoring allows you to better visualize all access to the system and detect this type of threat in time.
· Implement advanced email filtering: Sophos’ QR code phishing protection solution detects fraudulent QR codes included directly in emails and plans to expand its solution to QR codes in attachments as early as the first quarter of 2025.
· Leverage on-demand email retrieval: Sophos Central Email customers who use Microsoft 365 have this feature to eliminate spam or phishing emails from corporate emails.
· Encourage employees to be vigilant and report incidents: Prompt reporting of anomalies to the incident response team is essential to protect company systems from phishing.
· Revoke suspicious user sessions: It is imperative to have a plan in place to revoke user access that shows signs of compromise.
Despite the continuous development of new attack vectors, organizations can protect themselves from compromised systems by equipping themselves with the right tools, fostering a culture and work environment, and surrounding themselves with security vendors that, like Sophos.
Telecom
NCC Asks Telcos to Make Budgetary Provisions for Cybersecurity

Nigerian Communications Commission (NCC) has directed telecommunications operators to make dedicated budgetary provisions for cybersecurity as part of efforts to strengthen the resilience of Nigeria’s communications infrastructure against the growing wave of cyber threats.

The directive forms part of the Commission’s Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), which introduces new governance, risk management and operational requirements aimed at safeguarding the country’s critical telecommunications infrastructure from increasingly sophisticated cyberattacks.
Under the framework, all licensed telecom operators are expected to establish formal cybersecurity governance structures, dedicate adequate financial resources to cyber resilience programmes, and integrate cybersecurity into their enterprise-wide risk management processes.
The Commission said operators must ensure cybersecurity investments are no longer treated as optional operational expenses but as strategic business priorities necessary to protect network infrastructure, customer information and the country’s digital economy.
According to the NCC, licensees are expected to allocate sufficient budgets to support cyber risk assessments, security technologies, staff training, incident response capabilities, continuous monitoring and compliance with regulatory requirements.
The framework also requires operators to designate senior executives responsible for cybersecurity oversight.
At the same time, boards of directors are expected to provide strategic direction and ensure adequate funding for cyber resilience initiatives.
Speaking on the need for a stronger cybersecurity regime during the unveiling of the framework, Abraham Oshadami, executive commissioner, Technical Services, NCC, said, “Given the increasing digitalisation of services, the rapid growth of data exchange, and the sophisticated nature of modern cyber threats, the need for a robust, adaptive and inclusive cybersecurity framework has become more urgent.”
He added, “Both state and non-state actors are targeting essential sectors—including ours—through coordinated cyber and physical attacks. These attacks frequently target control systems and data integrity, underscoring the critical risks posed to operational technology (OT), especially in our sector.”
“As cyber threats evolve, they endanger not only system performance but also human safety, amplifying the severity and consequences of disruptions to vital communications infrastructure. Cybersecurity now encompasses human safety and must address the real risk to people’s lives when a system is attacked or compromised.”
The Commission further stated that operators are required to develop comprehensive cybersecurity implementation plans, conduct periodic risk assessments, establish business continuity and disaster recovery procedures, and regularly test their cyber defence capabilities.
In addition, the framework makes cyber incident reporting compulsory. Licensees must inform the NCC’s CSIRT of any major cybersecurity breach within four hours of discovery, and provide a thorough post-incident analysis after mitigation is complete.
Telecom
Glo Leads Internet Growth Figures in Nigeria for May

Digital solution provider, Globacom has recorded the highest Internet subscriber growth among Nigeria’s major telecom companies for the month of May.

Data from the Nigerian Communications Commission, NCC, Nigeria’s total Internet users increased to 157 million in May, up from 154.3 million in April. That is a growth of 2.67 million users in one month.
Globacom led the market by adding about 1.2 million new Internet subscribers. This means Glo was responsible for almost half of all new Internet users in May.
The company’s subscriber base grew from 15.5 million in April to 16.8 million in May. Airtel came second with 1.07 million new users, moving from 54.8 million to 55.8 million. MTN added 382,894 users to reach 83.5 million.
T2 Mobile, formerly 9mobile, recorded no growth for the second month in a row. Its subscriber base remained at 802,534. This is despite its roaming agreement with MTN, which was approved almost a year ago to help T2 customers use MTN’s network in areas with poor coverage.
Industry experts say Glo’s strong growth is due to its ongoing network upgrade. Since last year, the company has been building new base stations, expanding its fibre network, and adding thousands of new 4G sites across cities and rural areas.
The upgrades have improved voice and data quality for customers, while Globacom remain committed to providing better network experience and affordable Internet services to more Nigerians.
Telecom
MTN Paid 600Bn in Taxes in H1 2026 – Kadri, MTN CFO

MTN Nigeria’s half-year 2026 performance reflects more than revenue growth, highlighting the wider economic activity generated through tax payments, infrastructure investment and shareholder returns.

Kadri, MTN CFO
Beyond its financial results, the telecommunications operator said it continues to channel substantial resources into expanding network infrastructure, meeting statutory obligations and delivering value across its stakeholder ecosystem.
The company disclosed that it paid more than ₦600 billion in taxes, customs duties, regulatory levies and other statutory obligations over the past year.
It also invested over ₦1.6 trillion in capital expenditure since January 2025 to expand network capacity and improve service quality, while declaring an interim dividend of ₦26 per share for shareholders.
Speaking on Arise News’ Global Business Report, MTN Nigeria’s Chief Financial Officer, Modupe Kadri, explained that the company’s earnings are shared across several stakeholders before returns reach investors. “For every one naira of revenue, about 24 kobo becomes profit.
“The government receives over ₦600 billion through taxes and levies, operating costs account for a significant portion of our revenue, and every participant within the ecosystem benefits from the value we create,” he said.
According to the Nigerian Communications Commission (NCC), telecommunications remains one of the largest contributors to Nigeria’s Gross Domestic Product, supporting digital financial services, education, healthcare, commerce and public services. Continued investment by operators has also been identified as critical to expanding broadband access and improving digital inclusion across the country.
Kadri noted that shareholder returns remain an important part of MTN’s capital allocation strategy, but stressed that they represent only one aspect of the company’s broader economic contribution.
“Even when we declare dividends, the government still receives withholding tax, while we continue investing heavily in our network because sustaining quality service requires ongoing capital commitment,” he said.
E-Business3 days agoKaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware
E-Business3 days agoCMS T&M Launches TMO Rides to Enable a Faster & Cashless Transport Experience for CMS – Ajah Passengers
E-Business3 days agoNigeria Tightens Data Privacy Compliance as FG Issues Directive to MDAs
E-Business3 days agoFirm to recruit over 100 professionals to boost NRS e-Invoicing compliance
Telecom3 days agoFG Commences 90,000km Fibre Optic Rollout within Weeks
E-Financial2 days agoAccess Holdings Deepens Sustainable Finance Impact, Expanding Green Assets to ₦92.14 Billion
Telecom3 days agoDimension Data to Channel Funds to Support Nigerian Fibre Expansion
E-Financial3 days agoZenith Bank Confirms Cyberattack, Says Hackers Accessed Limited Customer Data

















