Telecommunications Infrastructure and Corporate Risk
Telecommunications Infrastructure and Corporate Risk can take very different forms — including sanctions, surveillance, corruption, government demands for data or network access, allegations arising from armed conflict, and human-rights litigation.
Companies operating in politically unstable, conflict-affected or highly regulated environments can face significant legal, regulatory, reputational and financial risks arising from the environment in which they operate.

EMFSA | 23 September 2026
This article aims to distinguish between allegations, investigations, regulatory findings, court judgments, settlements and admissions. Where we discuss allegations, we attribute them to the relevant source and identify the legal or investigative status of each case where known.
We examine:
- Operations in armed-conflict zones
- Allegations of complicity in human-rights abuses
- Civil litigation and criminal investigations
- Government demands for customer data or network access
- Surveillance and law-enforcement capabilities
- Sanctions and export-control violations
- Corruption and politically connected business relationships
➼Telenor — Myanmar
2021–2026 | Customer data, human-rights allegations and investigation
Norwegian police opened an investigation into Telenor concerning allegations relating to customer data and possible complicity in crimes against humanity.
According to Reuters, Norwegian police are investigating Telenor on suspicion that the telecommunications operator aided and abetted crimes against humanity in Myanmar following the 2021 military coup. Telenor sold its Myanmar business following the coup and completed its exit from the country in March 2022. The company said it was cooperating closely with investigators and would do everything in its power to assist in clarifying the case. Reuters, 15 September 2026.
The Open Society Justice Initiative has a detailed account of the underlying civil litigation. It reports that plaintiffs filed a class action in Norway in April 2026 concerning the disclosure of customer data, and that the Asker and Bærum District Court subsequently allowed the case to proceed as an opt-out class action. Open Society Justice Initiative — Telenor case
➼MTN — Afghanistan and Iran
2006–2026 | Anti-Terrorism Act litigation, Iran-related legal issues and U.S. Department of Justice investigation
MTN’s operations in Afghanistan and its minority investment in Iran have been the subject of several separate U.S. legal proceedings and, since 2025, a U.S. Department of Justice investigation. These matters involve different allegations, defendants and legal issues. The existence of a complaint, court proceeding or government investigation does not by itself establish that MTN committed the alleged conduct.
Afghanistan and the U.S. Anti-Terrorism Act
MTN began operating in Afghanistan in 2006. On 27 December 2019, plaintiffs filed a complaint in the U.S. District Court for the District of Columbia under the U.S. Anti-Terrorism Act (ATA). The plaintiffs brought claims on behalf of American service members and civilians, and their families, who were killed or injured in Afghanistan. MTN Group and MTN Afghanistan were among the defendants.
The plaintiffs alleged, among other things, that companies operating in Afghanistan had made protection payments to the Taliban and thereby provided support connected with terrorist attacks. MTN disputed the allegations and sought dismissal, including on jurisdictional and ATA grounds. MTN said it intended to defend its position. Reuters, December 2019; MTN
One of the resulting proceedings is Cabrera v. Black & Veatch Special Projects Corporation, Civil Action No. 1:19-cv-03833 (D.D.C.). In 2021, a magistrate judge recommended dismissal of the claims against the MTN defendants. In March 2024, the district court allowed the plaintiffs to file a Second Amended Complaint, including a new theory concerning MTN’s investment in Iran. The court also vacated the earlier recommendation and stayed the case pending related proceedings concerning the interpretation of the U.S. Anti-Terrorism Act. Cabrera v. Black & Veatch Special Projects Corp. CaseMine (March 28, 2024).
The Cabrera docket records the case as “Unstayed” on 17 September 2026, indicating that the earlier stay had been lifted.
MTN’s 2025 Annual Financial Statements continued to list the Cabrera litigation among its legal matters.
Irancell and Iran
Since 2006, MTN Group has held a 49% minority, non-controlling interest in Irancell. MTN states that Irancell is not under MTN Group’s operational control. It has also stated that, following the re-imposition of U.S. sanctions in 2018, it has not deployed capital into the Iran business or extracted capital or dividends from it. MTN Group FY2025 Annual Financial Statements
MTN’s investment in Irancell has also been relevant to separate U.S. legal proceedings.
In 2021, Zobay v. MTN Group was filed in the U.S. District Court for the Eastern District of New York. The plaintiffs alleged that MTN’s business relationships with Iranian entities, including its investment in Irancell, contributed to support for the Islamic Revolutionary Guard Corps and, indirectly, to attacks against Americans in Iraq and Afghanistan. MTN has contested those allegations.
On 28 September 2023, the court denied MTN Group Limited’s motion to dismiss the ATA claims, while granting MTN Dubai Limited’s motion to dismiss. MTN subsequently sought permission to appeal. MTN stated that the ruling did not mean that it had lost the case or that the court had found that it had violated the law. Zobay court decision
Two related ATA cases, Chand v. MTN and Davis v. MTN Irancell, were filed in the U.S. District Court for the District of Columbia in March 2022. MTN’s published disclosures describe these cases as involving allegations concerning MTN’s investment in Irancell and alleged connections to attacks in Iraq and Afghanistan. MTN Group FY2025 Annual Financial Statements
U.S. Department of Justice investigation — 2025
In August 2025, MTN disclosed that it had been approached through its external U.S. counsel regarding a U.S. Department of Justice grand-jury investigation concerning MTN Group, its former subsidiary in Afghanistan and Irancell.
MTN said that it was cooperating with the Department of Justice and voluntarily responding to requests for information. The company also stated that it had not been charged with any violation of law. MTN exited its Afghanistan business in early 2024.
MTN’s disclosure makes it clear that the investigation is separate from the civil Anti-Terrorism Act proceedings. MTN has not stated that it has been charged with an offence.
U.S.-Origin Technology and Iran
A separate issue concerns the movement of U.S.-origin technology into Iran. In June 2012, Reuters reported that MTN Irancell had obtained U.S.-origin equipment, including products from Sun Microsystems, Hewlett-Packard and Cisco, through a network of technology companies in Iran and the Middle East.
In a follow-up investigation published in August 2012, Reuters reported that internal MTN documents appeared to show that MTN employees had discussed ways of obtaining U.S. technology for MTN Irancell despite U.S. sanctions. Reuters reported that the equipment included products from several U.S. technology companies and that MTN denied wrongdoing.
These were matters reported by Reuters, rather than a U.S. government enforcement finding that MTN had violated sanctions.The distinction is important: the Reuters reporting described evidence and allegations concerning the procurement of U.S.-origin technology, while MTN denied wrongdoing. The reporting should therefore not be presented as a finding by U.S. authorities that MTN violated sanctions.
Reuters, June 2012 — How an Iranian telecom got banned U.S. tech
Reuters, August 2012 — How a telecom giant got round sanctions on Iran
➼Telia — Uzbekistan
2007–2017 | Corruption, telecommunications licences and international enforcement
Telia Company AB’s operations in Uzbekistan became the subject of a major international foreign-bribery investigation. According to U.S. and Dutch enforcement authorities, Telia and its Uzbek subsidiary, Coscom LLC, paid more than $331 million in bribes between approximately 2007 and 2010 to an Uzbek government official who had influence over the country’s telecommunications regulator. Telia and Coscom made the payments to enter and expand Telia’s telecommunications business in Uzbekistan.
The U.S. Department of Justice stated that Telia and Coscom structured and concealed the payments through various transactions, including payments to a shell company beneficially owned by the Uzbek official. The payments enabled Telia and Coscom to obtain telecommunications business and valuable telecom assets and to continue operating in the Uzbek market.
The matter resulted in coordinated enforcement proceedings in the United States and the Netherlands. On 21 September 2017, Coscom pleaded guilty in the United States to conspiracy to violate the anti-bribery provisions of the Foreign Corrupt Practices Act (FCPA), while Telia entered into a deferred prosecution agreement and admitted participating in the charged conspiracy. Telia also reached related resolutions with the U.S. Securities and Exchange Commission and the Dutch Public Prosecution Service.
The combined U.S. and Dutch criminal and regulatory resolution totalled $965,773,949 and included criminal penalties, forfeiture, disgorgement and prejudgment interest. Telia also agreed to strengthen its internal controls and cooperate with the authorities’ continuing investigations. Telia Company AB and Its Uzbek Subsidiary Enter Into a Global Foreign Bribery Resolution of More Than $965 Million for Corrupt Payments in Uzbekistan
Corporate Compliance and Regulatory Risk
The case illustrates a different form of telecommunications-sector corporate exposure from the sanctions, surveillance and human-rights matters discussed elsewhere in this article. Here, the principal risks involved corruption, regulatory influence, telecommunications licences, third-party payments, internal controls, corporate governance and exposure to foreign anti-bribery laws.
The Telia case also demonstrates how telecommunications licences and access to regulated markets can create significant compliance risks where government officials or politically connected intermediaries have influence over market entry or regulatory decisions.
African Union — Digital Infrastructure and Surveillance Risk
2020 | Security cameras, digital infrastructure and suspected cyber-espionage
A further example shows how corporate and infrastructure-related risk can extend beyond conventional telecommunications networks.
In December 2020, Reuters reported suspicious activity at the African Union (AU) headquarters in Addis Ababa. Technology staff found suspected Chinese hackers siphoning footage from the organisation’s security-camera servers. An internal AU memorandum reviewed by Reuters said the cameras covered offices, parking areas, corridors and meeting rooms. Information from Japanese cyber researchers reportedly prompted the investigation.
Reuters also reported that Chinese workers had built the AU’s conference centre and that Chinese technicians continued to assist with the organisation’s digital infrastructure. The Chinese mission to the AU denied that the organisation had reported being hacked and rejected the allegations.
The incident illustrates a broader corporate and infrastructure-security issue. Organisations that rely on externally supplied or maintained digital infrastructure may also need to consider data access, cybersecurity, surveillance capabilities, supply-chain security and control over networked systems.
The report does not establish that the infrastructure supplier was responsible for the alleged cyber intrusion. Rather, it illustrates why organisations may need to consider cybersecurity and control of digital infrastructure when assessing telecommunications and technology projects.
Source: Reuters, “Exclusive-Suspected Chinese hackers stole camera footage from African Union – memo,” 16 December 2020. The Reuters report is reproduced on EMFSA with attribution to Reuters: EMFSA — African Union camera-footage report
Corporate risk is not necessarily the same thing as corporate wrongdoing.
Vodafone provides a different perspective. Its corporate reporting identifies network shutdowns and law-enforcement assistance as human-rights issues and describes procedures for responding to government demands for communications data and network restrictions. Its reporting also illustrates how telecommunications companies may disclose activities involving countries subject to sanctions, even where the company does not operate directly in those countries.
Vodafone, Annual Report/Form 20-F
Company Disclosures
Telecommunications companies operate within increasingly complex financial, sustainability and regulatory reporting frameworks. Depending on the applicable rules and the materiality of an event, companies may need to disclose significant legal, regulatory, operational or financial risks in their corporate reporting. Issues such as surveillance, human-rights litigation, network shutdowns, sanctions and other regulatory matters can therefore have consequences beyond the immediate legal issue. They may also affect a company’s operations, finances, reputation and reporting obligations.
AI Disclosure
AI tools helped prepare this article through language editing, formatting, editorial assistance and research-support tasks. The author reviewed the sources and factual claims, reviewed and approved the final article, and remains responsible for its accuracy, interpretation and presentation.
