Broadband Users on CityFibre’s UK Network Suffer Nokia ONT Problems

Some broadband ISP customers on Cityfibre’s national Fibre-to-the-Premises (FTTP) network, which covers 4 million UK premises, are currently experiencing ongoing connectivity problems due to an unspecified issue that seems to only be affecting those that have one of Nokia’s Optical Network Terminals (ONT) installed inside their building.

Just for context. The ONT / ONU or optical modem device is usually installed inside your home or office (wall hung), near to where the fibre optic cable physically enters your property, and its primary job is simply to take the optical signal and convert it into an electrical one that can be connected to your broadband router via a Local Area Network (Ethernet) port. The standard ONT is usually a very small single port device.

Most of the residential customers on CityFibre’s network are probably connected using the ONT supplied by Calix, which tend to be coloured black (there are several models in circulation, but they’re usually the same colour). By comparison, Nokia‘s ONT is more of a cream white colour and has rounded edges. This is most commonly found in CityFibre’s newer XGS-PON (10Gbps) areas (roll-out update), although Calix also do some of the XGS-PON kit.

However, several of ISPreview’s readers from different parts of the UK have been reporting problems with Nokia’s ONT units since just after 8pm last night, which has also generated a related post on Reddit. As one of our readers (Jonny) said this morning: “My connection went down at 20:30 last night and [my ISP] have confirmed a wider network issue to me in a support ticket. Symptoms are a steady flashing PON light, which is supposedly indicative of a firmware update. Outage has so far been 15 hours.

The fault is not believed to be impacting too many of CityFibre’s connections and as a result we haven’t seen many of their ISPs putting out a notice about it yet, although we did get this from No One Internet (Leetline).

No One Internet Status Update

Jan 09, 10:09 AM

CityFibre is aware of an issue impacting a small number of FTTH and business FTTP customers. We have engaged with our technical teams who are currently investigating to resolve the underlying issue as quickly as possible, and we are also working to minimise impact to those customers who are affected. We apologise for any inconvenience this is causing.

We have asked for a comment from CityFibre too and will report back when one arrives. The hope is that this fault can be rectified remotely, but if it is a problem with a borked firmware update, then those can sometimes only be rectified by a device replacement. But at this time, the specifics are not clear on what has actually gone wrong.

UK Internet Domain Registry Nominet Suffers Cyber Attack

The UK internet domain registry, Nominet, has confirmed to ISPreview that their network has suffered an “unauthorised intrusion” after hackers exploited a “zero-day vulnerability” in the Virtual Private Network (VPN) software they use, which is supplied by Ivanti and enables their people to access systems remotely.

ISPreview first became aware of a problem yesterday after the UK Government’s National Cyber Security Centre (NCSC) put out an urgent bulletin that encouraged organisations to “take immediate action” to mitigate vulnerabilities affecting Ivanti Connect Secure (ICS), Policy Secure and ZTA Gateways (CVE-2025-0282 and CVE-2025-0283).

On top of that, Ivanti themselves said they were “aware of active exploitation” affecting their software, although at the time it was not known who or how many organisations had been targeted. But it was known that this had started “beginning mid-December 2024“.

NSCS Description of the Critical Vulnerabilities

CVE-2025-0282 – A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2025-0283 – A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.

In addition, Google Cloud has also put out a detailed advisory on the vulnerabilities, which adds a lot more context. But unfortunately, it appears as if the UK’s registry for internet domains, Nominet, is one of those organisations to have been attacked, and they’ve shared the following customer notice with us.

Important security update (Nominet)

We want to update you about an ongoing security incident that is currently under investigation.

We became aware of suspicious activity on our network late last week. The entry point was through third-party VPN software supplied by Ivanti that enables our people to access systems remotely.

However, we currently have no evidence of data breach or leakage. We already operate restricted access protocols and firewalls to protect our registry systems.

The unauthorised intrusion into our network exploited a zero-day vulnerability.

As you will recognise, these incidents are always fast-moving and require investigation – but we have NOT uncovered any backdoors or routes onto our network. Aided by external experts, our investigation continues, and we have put additional safeguards in place, including restricted access to our systems from VPN.

Domain registration and management systems continue to operate as normal.

As well as informing members and customers, we have reported this incident to the relevant authorities, including NCSC.

Ivanti has made available patches to address this vulnerability which we are implementing. Those also using Ivanti’s VPN services are encouraged to patch their software immediately.

We will update you when our investigation concludes, or as necessary.

Nominet will not be the only organisation to be dealing with the headaches that have resulted from the latest situation. Sadly, this is not the first time that Ivanti’s VPN solution has faced serious security problems (example), which appears to have been promptly exploited by “Chinese state-sponsored threat actors.”

Toyota completes Phase 1 of Mount Fuji smart city construction

News

At CES 2025, Toyota Motor Corporation announced the completion of Phase 1 construction of Toyota Woven City (“Woven City”), its self-made smart city at the base of Mount Fuji.

The Japanese automaker giant has labelled the city as a “test course for mobility” and plans to launch Phase 1 for late 2025.

Speaking at the CES confrence, Akio Toyoda, Toyota’s Chairman of the Board of Directors (Representative Director), detailed his vision for the city: 

“From personal mobility devices, like a wheelchair race car…to drones that safely escort you home at night, to interactive pet robots that provide support and companionship for the elderly, to flying cars…”

At the official launch of Woven City, approximately 100 residents―primarily Toyota and WbyT staff and their families―are expected to participate in co-creation activities as the first residents. Plans to welcome the general public are in place for 2026.

The Woven City concept was first unveiled in 2020, where it was described as a “living laboratory”.

Woven City is ideated to be where “Inventors” can develop, test, and validate innovative products and services. These inventors include Toyota and Toyota Group companies, such as WbyT, as well as external companies, startups, and individual entrepreneurs.

This article was written by Grace Dawes, Editor of movemnt.net

Also in the news:
VEON and Starlink to launch Direct-to-Cell Satellite connectivity in Ukraine
Swisscom completes acquisition of Vodafone Italia
Equinix to buy BT’s Irish data centre business for €59m

Scam Callers Target Broadband ISP BT’s UK Digital Voice Switchover

Consumer magazine Which? has warned customers of UK broadband ISP BT (inc. EE) to be on alert for phone scammers who are now actively impersonating BT’s support agents in order to exploit the ongoing migration onto digital landlines (Digital Voice). The scammers do this by trying to con customers into sharing their financial (payment) details.

In this case, a growing number of consumers have reportedly been called by fake BT support agents, who will state that they need to confirm your personal and payment information to ensure the phone service can be migrated before a “January 2025 deadline” (this should actually be end of December 2025 for most people and 31st January 2027 for vulnerable users – here and here). But alternatively, they may also demand on-the-spot payments to move the phone service and threaten disconnection if refused.

NOTE: Openreach are withdrawing their old Wholesale Line Rental (WLR) products as part of this change, while BT are retiring their related Public Switched Telephone Network (PSTN).

The wide availability of personal data online, both via public systems and through past data breaches, means that savvy fraudsters may often already know some of your personal details before they call, which can make the scam sound much more convincing. Such scams are not new and have been on the rise over the past couple of years (here).

The reality is that BT’s change to digital voice does not require any changes to your plan or bill, and your number won’t change either. The change itself, for most people, is quite straightforward when providers communicate it properly and support their customers correctly during the transition. But not everybody is as comfortable with the change, and it can be confusing for those who have spent a lifetime plugging their phones into the same old wall socket; particularly if they haven’t previously had a broadband service (your old handsets will now need to be plugged into a router or ATA device).

On top of that, there are still some long-standing problem areas, such as compatibility woes with third-party products and services (e.g. alarms and telecare services), many of which haven’t yet fully adapted to this change. BT and others are providing targeted support to resolve these issues, but it’s obviously also proving to be fertile grounds for scammers to exploit.

Tips to avoid scams include:

  • If you receive a suspicious call, put the phone down and call back on a trusted number to verify the call
  • If you mistakenly give a caller your bank account details, contact your bank immediately
  • If you receive a suspicious call, report the call to BT here
  • Block any suspicious numbers after you have reported them

Remember:

  • Take a moment to stop and think. Trust your instincts. If it sounds too good to be true or is suspicious, there’s probably a catch
  • Don’t stay on the phone unless you’re 100% sure the caller is genuine
  • Don’t give away any of your personal details or give anyone access to your computer

Victims of such scams or fraudulent activity should also report it to Action Fraud on 0300 123 2040 or via their website, and/or contact your local trading standards team.

BT Make Largest Ever UK Commercial EV Fleet Order of 3,500 Vehicles

Telecoms and broadband giant BT Group (inc. Openreach) has today announced the “UK’s largest ever commercial Electric Vehicle (EV) fleet order“, which will see them purchasing around 3,500 new EVs and thus expanding their EV fleet to nearly 8,000 by the time the order is complete in 2026.

The operator, which currently manages the second-largest commercial vehicle fleet in the UK (i.e. more than 27,000 vehicles are used by their engineers across the country), already has around 4,300 electric vehicles, and they’re aiming to upgrade their entire fleet of diesel-powered vans and cars to EVs by the end of March 2031 (supporting their Net Zero target for the same date).

NOTE: Net Zero means a company or organisation that removes as many carbon emissions as they produce. The UK Government has committed to achieve Net Zero by 2050.

The order of the new EVs is part of a larger delivery of 6,000 new vehicles, with more than half of the vans being EVs. All of this will be delivered by four manufacturers over the next two years: Ford, Stellantis, Toyota, and Renault (BT and Openreach have previously also purchased some EVs from Vauxhall).

By the end of FY24, the BT Group had already achieved a 61% reduction in its carbon emissions intensity since FY17. A big contributor to this performance has been the move to more energy-efficient full fibre (FTTP) broadband and 4G / 5G mobile networks, while switching off old legacy networks (e.g. 3G and analogue phone).

Simon Lowth, Chief Financial Officer at BT Group, said:

“By integrating yet more electric vehicles into our operations, we are taking another significant step towards reducing our carbon footprint and supporting the UK’s transition to a greener future. As we extend our full fibre build from 16 million homes and businesses today to 25 million by the end of 2026, having the most efficient, sustainable electric vehicles will give our engineers the edge as they connect customers at pace to our next generation networks. Our modern fleet will help us to be more efficient and deliver a better service for our customers.”

Lilian Greenwood, Future of Roads Minister, said:

“Businesses have a crucial role to play in driving the transition to electric cars and vans. That’s why it’s fantastic to see that BT have made the most of our plug-in van grant to order 3,500 brand new EVs – which means they will have the largest electric commercial fleet in the UK.

“We want to help more businesses decarbonise their operations, and we’ve extended our plug-in van grant with £120 million funding to help roll out more zero emission vans on our roads – part of our £2.3 billion to support industry and consumers switch to EVs and make the transition a success”.

Sadly, BT’s announcement doesn’t contain any details on precisely which models the operator has ordered or how much range each of them will have. Last year we also reported that Openreach had teamed up with ‘Ground Control’ to install an initial 8,500 charging points for Openreach. Many of those will be installed outside engineer’s homes and at key sites, such as exchanges, up and down the country. The broadband network operator is also working with other operators, like First Bus, to share charging infrastructure (here).

Finally, BT’s awkwardly named UK digital incubation team, Etc., last year “powered up” their first Electric Vehicle (EV) charger under a 2-year pilot, which is one of potentially tens of thousands that could be established by repurposing Openreach’s old fixed broadband street cabinets (here) – these can be used by both residents and Openreach’s engineers. The first such conversion went live in Scotland, but the pilot itself is focused on West Yorkshire, with ambitions to scale up to 600 trial sites across the UK.

Nexfibre’s UK Full Fibre Broadband Build Covers 2 Million Premises UPDATE

Network operator nexfibre, which shares some of their parentage with ISP partner Virgin Media (VMO2) and uses the same build teams, has today revealed that the roll-out of their new 10Gbps capable Fibre-to-the-Premises (FTTP / XGS-PON) broadband network has reached its coverage target of 2 million premises on time and is now moving on with the next phase.

Just to recap. Back in 2022 Telefónica, Liberty Global and InfraVia Capital Partners setup nexfibre as a new £4.5bn joint venture (here), which aims to deploy an open access (wholesale) full fibre network to reach “up to” 7 million UK homes (starting with 5m by 2026) in areas NOT served by Virgin Media’s own network of 16m+ premises. The funding reflects £3.3bn of fully underwritten financing and up to £1.4bn in equity commitments.

NOTE: Virgin Media is currently the only ISP on nexfibre’s network via an “exclusive partnership” (here), but more ISPs will be added in the future (here) and Virgin’s own network will also open up to wholesale via NetCo in H1 2025 (here).

The operator previously reported that their full fibre network had been built to 1,557,000 premises as ‘Ready for Service’ at the end of October 2024 (here), which means that they’ve managed to add around 440,000 additional premises over the last two months. But it’s not clear from today’s announcement whether this figure now includes the 2023 acquisition of Upp and its c.175,000 premises.

The business has delivered its network to more premises than any other fibre provider in 2024, except for the incumbent [Openreach], which makes it the UK’s second largest alternative network provider,” said nexfibre’s announcement today. But in fairness, CityFibre’s rival FTTP network has already reached 4 million premises, and we’re certain that Netomnia (YouFibre) has also just passed the 2 million premises mark (not yet official). Hyperoptic aren’t far behind the 2 million figure, either, but their roll-out has slowed.

Rajiv Datta, Chief Executive Officer of nexfibre, said:

“Reaching two million premises is testament to the dedication of our team and the support of our partners and investors. It reflects our commitment to building a network that prioritises underserved communities and creates a real and lasting impact – most of all by driving economic growth and improving living standards across the UK.

This is an outstanding achievement in just two years of operation – making nexfibre the UK’s second largest alternative network. However, our work is far from done. Our mission is to be part of a network platform that drives sustainable, nationwide competition, provides a genuine alternative to Openreach, and transforms access to broadband across the country.”

Sadly, today’s announcement, while extremely positive, doesn’t include a specific build target for the coming year. But given their progress and the future targets, it’s not unreasonable to expect them to do over 1 million premises during the next 12-months as well.

UPDATE 10:18am

Nexfibre has today informed ISPreview that, as the Upp migration exercise is expected to “reach its conclusion in the coming weeks“, the 2 million does include “some” of the Upp homes. But we expect to get a fuller update shortly.

CityFibre Begins Project Gigabit Broadband Roll Out for Sussex

Network operator CityFibre has this morning announced that they’ve begun the roll-out phase of their £108m state-aid supported Project Gigabit contract for the West & East Sussex (Lot 16 & 1) area in England. This will extend their 10Gbps capable FTTP broadband ISP network to an additional 57,000 hard-to-reach rural premises.

The figures given in Cityfibre’s announcement today differ from those they gave when the contract was announced in February 2024 (here), which specified a contract value of £100m and planned coverage for around 52,000 premises. This suggests that a modest extension may have taken place since the deal was signed, which is often due to changes in the commercial plans of rival operators.

NOTE: Project Gigabit aims to help extend 1Gbps capable (download) broadband networks to reach “nationwide” UK coverage (c. 99%) by around 2030 (here) – the UK is currently at about the 86% coverage mark today (here).

Sadly, today’s announcement doesn’t provide any details of where CityFibre are starting to build or how long it will take to complete the deployment, which is a bit disappointing. But hopefully more information will be forthcoming in the future.

The operator, which is supported by various ISPs like Vodafone, TalkTalk, Zen Internet and more (Sky Broadband will follow in 2025), already covers around 4 million UK premises with full fibre broadband – mostly in urban areas – and their ambition is to eventually cover up to 8m (funded by c.£2.4bn in equity, c.£4.9bn debt and c.£800m of BDUK / public subsidy) – representing c.30% of the UK.

Greg Mesch, Chief Executive Officer at CityFibre, said:

“We are excited to bring full fibre connectivity to hard-to-reach homes and businesses across East and West Sussex, opening doors to new possibilities and enabling communities to flourish. This Project Gigabit rollout demonstrates our commitment to bridging the digital divide, ensuring that residents in rural areas can experience the benefits of enhanced connectivity.”

Sir Chris Bryant, UK Telecoms Minister, said:

“It is fantastic to see spades in the ground delivering lightning-fast broadband to hard-to-reach parts of Sussex, and connecting communities that need it most. This government investment delivers faster internet in turn helping businesses to grow, securing more jobs, and ensures everyone has the digital access they need to thrive in the modern world.”

Over the past couple of years CityFibre has secured nine Project Gigabit contracts, totalling over £782m in government subsidies to serve more than 464,000 hard to reach rural premises across Cambridgeshire, Suffolk, Norfolk, Hampshire, Buckinghamshire, Hertfordshire, Berkshire, Leicestershire, Warwickshire, Sussex, Kent, Bedfordshire, Northamptonshire & Milton Keynes.

The network operator has also committed their own funding to help build commercially beyond those contracted areas (i.e. a total of £1.2bn in combined public and private investment or 1.366 million extra premises may be delivered as a result of these contracts).

FCC plans spectrum auction to fund “rip and replace” of Chinese telecoms equipment  

News 

The FCC says the replacement process is more urgent than ever in the wake of the ‘Salt Typhoon’ cyberattacks late last year 

The US Federal Communications Commission (FCC) is pushing ahead with plans for a new spectrum auction to help pay for the removal and replacement of Chinese telecoms equipment from US networks.  

The Rip and Replace program, established in 2019, is an initiative by the FCC designed to help secure the US telco infrastructure by removing and replacing high-risk network equipment made by Chinese companies, particularly Huawei and ZTE.  The project was initially allocated $1.9 billion in public funding to support smaller operators to replace their equipment; however, demand for the funds far outstripped the budget, leaving the FCC with an almost $3.1 billion shortfall to complete the project as planned.  

Following years of pressure from the FCC, late last month the US Senate approved a bill allocating the required funding to the rip and replace initiative. The bill allows the FCC to borrow the required funding from the Treasury on the proviso that the funds are repaid with profits from upcoming spectrum auctions. 

As a result, the FCC is looking to push ahead with an auction of AWS-3 (1,695–1,710 MHz, 1,755–1,780 MHz, and 2,155–2,180 MHz) spectrum left over from previous allocations. 

FCC Chairwoman Jessica Rosenworcel this week urged the commission to “quickly adopt rules” that would allow the spectrum auction to proceed and therefore fund the rip and replace programme “without further delay.” 

The urgency of replacing Chinese equipment from US networks has been highlighted by the high profile ‘Salt Typhoon’ cyberattacks on telecoms operators last year. 

“With ‘Salt Typhoon’ and other recent incidents, we are all acutely aware of the risk posed by Chinese hackers and intelligence services to our privacy, economy, and security,” said Rosenworcel. “Today’s proposal is a critical step toward finally filling the shortfall in the Rip and Replace program. I am confident that the FCC’s world-leading and award-winning auction team will meet this important moment.” 

“The cybersecurity of our nation’s communications critical infrastructure is essential to promoting national security, public safety, and economic security,” she added. “As adversaries grow more sophisticated, we need to modernise our defenses.” 

The Salt Typhoon cyberattacks, first reported in October, exposed the vulnerability of the US telecommunications infrastructure. The hackers exploited weaknesses in systems used for surveillance, giving hackers linked to Chinese state actors access to sensitive data and communications. 

Senate Intelligence Committee Chair Mark Warner called the attack “the worst telecom hack in our nation’s history—by far.” Major companies like AT&T, Verizon, and Lumen were reportedly affected, raising questions about whether current cybersecurity protections are enough to prevent future breaches. 

In response, Rosenworcel recently proposed mandatory rules requiring telecom providers to have robust cybersecurity measures in place. Companies would also need to submit annual certifications proving they are up to date on cybersecurity risk management. 

Join the conversation around US telecoms at this year’s Connected America, 11-12 March in Dallas. Get discounted tickets here! 

Also in the news:
Italy to sign €1.5bn government contract with SpaceX, report suggests
Washington takes T-Mobile to court over 2021 data breach
SK Telecom prepares for North American launch of AI agent Aster

Deutsche Telekom combines domestic and international wholesale under T Wholesale banner 

white red and yellow flags on pole in front of glass building

News 

The new wholesale arm will serve 250 telecommunications providers and resellers in Germany, and over 900 international customers 

Deutsche Telekom has announced that it will consolidate its national and international wholesale activities into one entity, named ‘T Wholesale’. 

The company says that the move “is intended to provide clients with streamlined solutions that address needs both within Germany as well as globally, reflecting the growing demand for integrated telecommunications services.” 

The new structure blends local expertise with international experience, providing strong support for cross-border projects, local regulations, and regional or global access. Telekom says clients can expect streamlined processes, quicker responses, better services, more competitive options, and cost savings. 

The newly combined company will be headed up by Dr. Kerstin Baumgart, the current Head of Wholesale at Deutsche Telekom, Current Head of DT-Global Carrier, Dimitrios Rizoulis, will retain his role, reporting directly to Baumgart. 

“Our partners and customers benefit from our international focus and the synergies that will allow us to better meet the challenges of a rapidly changing market,” said Managing Director Dr. Kerstin Baumgart in a press release. 

“We offer a portfolio from a single source, both in Germany and internationally, creating a seamless customer experience. As always, we remain committed to sustainable and collaborative partnerships with our customers,” she added. 

Keep up with the latest international telecoms news by subscribing to the Total Telecom daily newsletter 

Also in the news:
FCC plans spectrum auction to fund “rip and replace” of Chinese telecoms equipment 
Washington takes T-Mobile to court over 2021 data breach
Is there still a role for the rural ISP in tomorrow’s digital infrastructure? Beyond the Cable discusses

Washington takes T-Mobile to court over 2021 data breach

pink and purple led light

News

The data breach saw the personal details of 79 million T-Mobile customers compromised

The US state of Washington is suing T-Mobile over a massive data breach that affected millions of the state’s residents.

Back in 2021, T-Mobile revealed it had suffered an enormous data breach that saw the personal information of around 79 million of customers and potential customers stolen. Details compromised included customer names, dates of birth, Social Security numbers, and driver’s license information.

While T-Mobile quickly took action to address the security failing, the operator was nonetheless faced with string of related class action lawsuits. In 2022, T-Mobile subsequently agreed to pay out $350 million in compensation to affected customers, as well as pledging to invest $150 million into its cybersecurity infrastructure.

The operator would later be fined $31.5 million by the Federal Communications Commission for its failure to protect customer data during both this incident and other cyberattacks that took place between 2021 and 2023.

In this latest lawsuit, the state of Washington asserts that the data breach, which affected 2 million Washingtonians, could have been avoided.

“T-Mobile knew for years about certain cybersecurity vulnerabilities and did not do enough to address them,” read a statement announcing the lawsuit.

The case also alleges that T-Mobile “failed to properly notify affected Washingtonians of the data breach, downplaying its severity and sending notices to affected consumers that did not disclose all the information that had been compromised”.

“This significant data breach was entirely avoidable,” said Attorney General Bob Ferguson, who filed the case. “T-Mobile had years to fix key vulnerabilities in its cybersecurity systems — and it failed.”

The scale and severity of cybersecurity threats to major telcos have been noticeably increasing alongside geopolitical tensions. Late last year, the US telecoms sector was subject to a major attack by Chinese hacker group ‘Salt Typhoon’, which attacked nine internet service providers in the US.

Senator Mark Warner, chairman of the U.S. Senate Select Committee on Intelligence, called the intrusion the “worst telecom hack in our nation’s history” and is urging telcos to drastically tighten their security.

How is the cyberthreat landscape changing in 2025? Join the operators in discussion at this year’s Connected America conference live in Dallas, Texas

Also in the news:
VEON and Starlink to launch Direct-to-Cell Satellite connectivity in Ukraine
Swisscom completes acquisition of Vodafone Italia
Equinix to buy BT’s Irish data centre business for €59m