The National Authority for Management and Regulation in Communications (ANCOM) has published the Report on Significant Incidents Affecting the Security of Electronic Communications Networks and Services in 2025. Although the number of incidents increased compared to the previous year, their impact on users decreased, with nearly 27% fewer users affected per incident.
The data indicate an improvement in operators’ ability to mitigate the effects of incidents and restore services more quickly. The decrease in the total number of affected users points to greater resilience of electronic communications networks.
Mobile services, the most affected
As in previous years, mobile communications services were the most affected by incidents reported to ANCOM, with more than 900 incidents disrupting the provision of mobile voice and internet services. In the case of fixed services, the impact was significantly lower: 13 incidents affecting fixed internet services and 5 incidents affecting fixed telephony services were reported.
Power outages and damage to network infrastructure continued to be the leading causes of reported incidents
The collected data show that more than 60% of all incidents (568 out of a total of 938) were caused by power supply issues. These were followed by incidents resulting from third-party works, including accidental fiber-optic cable cuts and deliberate damage to infrastructure (215), system errors (97), unknown causes (41), and natural phenomena (12). The report’s findings confirm that power supply disruptions continue to be the primary factor affecting the security and availability of networks and services, highlighting the need to strengthen energy infrastructure and implement additional redundancy measures.
At the same time, incidents caused by third parties resulting in damage to network segments can generally be prevented through better coordination among authorities, infrastructure and network owners, designers, and contractors, as well as through effective planning and information sharing before infrastructure works commence. Communications infrastructure supports the operation of essential services for citizens and the economy, ranging from emergency calls and digital services (payments, online purchases of goods and services, and banking and financial services) to the activities of public institutions and businesses (payment of taxes and duties, teleworking, and access to online applications and databases). Ensuring its resilience is therefore a shared responsibility.
Distribution of incidents by primary cause

Geographical distribution of incidents
Security incidents were reported across all regions of the country, with the highest numbers recorded in the counties of Vaslui (95 incidents), Buzău (85), Vrancea (83), Iași (79), and Teleorman (78). The Municipality of Bucharest recorded 28 incidents. The fewest incidents were reported in the counties of Botoșani (5 incidents), Arad (8), Covasna (9), Harghita (10), and Suceava (10).
The average remediation time was approximately 11 hours
In 2025, providers resolved the security incidents reported to ANCOM within an average timeframe of approximately 11 hours. From the perspective of the affected infrastructure, most incidents involved mobile network base stations (863 cases), followed by transmission nodes (30 incidents) and underground cables (17 incidents).
The number of affected users continued to decrease
The report data show that the average number of users affected by an incident continued to decline. In 2025, a single incident affected an average of 15,344 users of electronic communications services, compared to 20,915 users in 2024. At the same time, the total number of users of electronic communications services affected by reported security incidents during the year decreased from 18,007,826 in 2024 to 14,392,434 in 2025.
ANCOM report
ANCOM’s Report on Incidents Affecting the Security of Electronic Communications Networks and Services in 2025 was prepared based on information reported by providers of electronic communications networks and services, in accordance with the obligations established under the regulatory framework governing the notification of security incidents. The report presents the evolution of incidents, their causes, their impact on users, and the trends observed during the period under review.
The report is available here.
