Logo of the website creation company Stack & Co.
Secura

Solutions

Salt Typhoon: How China hacked US telecommunications networks undetected for 18 months

Reading time: 8 minutes

a laptop computer sitting on top of a desk

Salt Typhoon: How China Hacked US Telecommunications Networks Undetected for 18 Months

In late 2024, US authorities confirmed one of the most significant intelligence-related security breaches in US history. A Chinese state-sponsored hacking group, dubbed "Salt Typhoon," had infiltrated the networks of at least nine major US telecommunications providers — including AT&T, Verizon, and Lumen Technologies — and maintained persistent access for a period of up to 18 months.

What Did Salt Typhoon Do?

The intrusion was extraordinarily sophisticated. Salt Typhoon targeted lawful interception systems — the infrastructure that US telecom operators are legally required to maintain to enable court-ordered government wiretaps. By compromising these systems, the attackers gained access to:

  • Phone call metadata for millions of Americans

  • Real-time call interceptions of senior US government officials and political figures

  • Text messages of individuals under active FBI surveillance

  • Intelligence on US wiretap targets – potentially revealing ongoing espionage operations

This intrusion is believed to have provided Beijing with a comprehensive mapping of US counterintelligence activities.

How Did They Get In?

Investigators established that the initial access stemmed from unpatched security vulnerabilities in Cisco network equipment, combined with the exploitation of legitimate administrator credentials obtained during previous supply chain compromises. Once inside the system, the attackers used "living off the land" techniques, operating exclusively via legitimate system tools to avoid triggering security alerts.

The Geopolitical Fallout

The intrusion prompted an emergency meeting of the US Senate Intelligence Committee and an urgent review of telecommunications security standards by the FCC. CISA and the FBI issued a joint advisory urging telecom operators to:

  • Immediately audit all privileged access credentials

  • Review and strengthen access controls to lawful interception systems

  • Deploy enhanced network traffic monitoring

  • Apply all pending Cisco IOS patches without delay

The incident also reignited the debate over the security risks of maintaining mandatory government backdoors in communications infrastructure — an issue security experts have been warning about for decades.

What Businesses Should Learn

  • Assume that nation-states are targeting your supply chain, not just your perimeter.

  • Privileged Access Management (PAM) is indispensable.

  • Network segmentation limits the blast radius of any intrusion.

  • Proactive threat hunting — not just passive monitoring — is essential to detect persistent threats.

Salt Typhoon is not an isolated incident. This operation is part of a broader trend of Chinese cyber espionage, which also includes the pre-positioning of Volt Typhoon within US critical infrastructure. The question is no longer whether sophisticated actors have penetrated corporate networks, but whether organizations possess the visibility necessary to detect them.

Don't wait for a security breach.

The average cost of a data breach is $4.88 million.

Create a free website with Framer, the website builder loved by startups, designers and agencies.