CyberzSOC

Publication detail
← Back to advisories & guidance

Mobile Communications Best Practice Guidance ↗ source

December 18, 2024 CISA Guidance

Summary

1.0 December 18, 2024 Original version positions and introduced enhanced recommendations for securing encrypted communications to counter evolving threats from malicious cyber private messaging applications. In 2025, the Cybersecurity and Infrastructure Security Agency (CISA) further identified a rise in cyber espionage activity conducted by nation-state affiliated cyber threat actors, particularly from the People’s Republic of China (PRC). These actors have targeted commercial telecommunications infrastructure, enabling breaches that resulted in the theft of customer call records and the compromise of private communications for a limited number of highly targeted individuals. While applicable to all audiences, this guidance specifically addresses highly targeted individuals who are in senior government, military, or political positions and likely possess information of interest to these threat actors. CISA initially released this best practice guidance to promote protections for mobile communications from exploitation by PRC-affiliated and other malicious cyber threat actors. The November 2025 update includes additional recommendations for securing end-to-end encrypted communications to empower users in protecting their personal communications amid an increasingly sophisticated threat landscape.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.