U.S. federal agencies have linked a large, long-running cyber‑espionage campaign dubbed “Salt Typhoon” to China’s Ministry of State Security, describing it as a state‑sponsored operation that infiltrated the networks of at least nine U.S. telecommunications providers, including AT&T and Verizon. According to U.S. officials, the hackers targeted core telecom infrastructure and lawful‑intercept systems to access metadata from calls and text messages—such as phone numbers, timing, and routing information—associated with more than a million users, heavily concentrated around Washington, D.C., where many senior government officials live and work. The campaign, active for at least one to two years before discovery, is characterized as cyber‑espionage focused on U.S. government officials and sensitive corporate targets rather than financially motivated crime. Once the Salt Typhoon activity was publicly exposed in late 2024, AT&T and Verizon said they had evicted the intruders and contained the incident, after working with an external incident‑response firm to investigate and remediate the compromise. U.S. cyber and law‑enforcement agencies, led by the FBI and CISA, used the case to underscore the systemic risk posed by weak telecom security and the ability of sophisticated state actors to monitor sensitive communications even without breaking message content encryption. Officials have urged broader adoption of end‑to‑end encrypted messaging and stronger network‑security practices to limit the intelligence value of intercepted traffic, arguing that robust encryption and modern defenses are now a baseline requirement for both individuals and critical infrastructure providers in the face of state‑sponsored threats like Salt Typhoon.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on $LINK

Comments