Cyber & Digital Crime · GSJ Original

Salt Typhoon, Part 1: The Breach America Still Cannot Fully Measure

Chinese state-linked operators reached deeply into U.S. telecommunications networks, collecting call records tied to millions of customers and communications from a much smaller group of political targets. Nearly two years after the breach became public, the government still has not produced a complete public accounting of its reach.

A matte-black telecommunications chassis on an operator desk beside a call-detail record with blank number columns
Incomplete public accounting, not a claim of current carrier access. Credit: IC DataCom Newsroom

Listen to this article

Narrated · 18:11

Synthetic narration.

In December 2024, the federal government published advice that revealed how seriously it regarded the breach of America’s telephone networks. Guidance from the Cybersecurity and Infrastructure Security Agency urged highly targeted people—senior officials and others likely to possess information of interest to a foreign government—to use end-to-end encrypted communications and to avoid relying on text-message codes as their only protection.1

The warning was not a declaration that every American’s phone had been tapped. It was an acknowledgment that the communications network itself could no longer be treated as a trusted barrier for the people Beijing most wanted to watch.

By then, U.S. officials had confirmed a broad cyber-espionage campaign inside commercial telecommunications infrastructure. The intruders were affiliated with the People’s Republic of China, according to the FBI and CISA. The private sector commonly tracked overlapping activity under the name Salt Typhoon.2

The distinction matters. “Salt Typhoon” is a commercial label, not a criminal indictment or a perfectly bounded government attribution. In a joint advisory published in August 2025, U.S. and allied agencies said the activity only partially overlaps with several industry names, including Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807 and GhostEmperor. The agencies declined to adopt any one of those names for the entire cluster.3

What the government did confirm was serious enough without embellishment.

PRC-affiliated actors compromised networks at multiple telecommunications companies. They stole customer call-record data. They compromised private communications belonging to a limited number of people, primarily those involved in government or politics. And they copied certain information that had been sought by U.S. law enforcement under court orders.4

Those are three different exposures. They should not be collapsed into one.

Call-detail records can reveal who communicated with whom, when and for how long without containing the words spoken. Geolocation and related metadata can map a person’s movements and associations. Communications content—the call or text itself—is more intimate, but the publicly acknowledged number of people whose content was collected was far smaller.

On December 27, 2024, Deputy National Security Advisor Anne Neuberger put the scale into sharper focus during an on-the-record White House briefing. She said China had compromised nine U.S. telecommunications companies. The access, she said, gave the actors the capability to geolocate millions of people and record calls. A large number of people appeared to have been affected at the geolocation and metadata layer, especially in the Washington, D.C., and Virginia region, while the government believed the number subject to actual collection of calls and texts was “probably less than 100.”5

The FBI later supplied a second official formulation. In written testimony to the House Judiciary Committee on September 17, 2025, Director Kash Patel said the actors had broken into telecommunications companies in the United States and abroad and stolen call-record data “related to millions of customers,” while also compromising the private communications of a limited number of people and copying sensitive law-enforcement-related information.6

That is not the same as saying the hackers recorded millions of calls. It is also not a minor breach. Metadata collected at scale can expose networks of relationships: who moves together, who repeatedly calls a particular number, which device enters a sensitive location, and which people may merit closer intelligence collection.

The smaller group subjected to communications-content collection carried extraordinary national-security significance. The FBI-CISA statement said the affected individuals were primarily involved in government or political activity but did not name them.7 Even without names, that narrow category describes the kind of targets a foreign intelligence service would value most.

The operation also reached information connected to court-authorized law-enforcement requests. That fact has often been summarized as a “wiretap-system breach.” The careful public formulation is narrower: the agencies said actors copied certain information that was subject to U.S. law-enforcement requests pursuant to court orders. The public record still does not fully show which systems were reached, which fields were taken, or whether the information exposed active surveillance targets, investigative methods, or both.

For a foreign intelligence service, even partial visibility into lawful-intercept activity could be unusually valuable. It could reveal not only whom the United States was watching, but which communications had drawn investigative attention. That is an inference from the type of information exposed—not a public finding that every court-authorized interception system was controlled or every investigation compromised.

## Nine companies, an incomplete public list

The White House’s count grew from eight affected telecommunications companies to nine after the government distributed a hunting guide describing the attackers’ techniques. Neuberger said the ninth company was identified through that process.8

That statement establishes something important but limited: government-distributed detection guidance helped uncover an additional affected company. It does not establish that every carrier first learned of its compromise from the government, and this story does not claim that it does.

The government has never publicly released a complete, authoritative list of the nine companies. Several carriers issued statements about their own networks, but the wording, dates, scope and level of technical detail varied.

Verizon’s January 10, 2025 statement offers one of the clearest public carrier accounts. The company said an independent cybersecurity firm confirmed containment; that it had not detected the actor in its network “for some time”; and that the incident affected a small number of government or political targets. Verizon also said the actor accessed a small percentage of other customers’ mobile internet-access and mobile call records while pursuing those targets, but that it had no reason to believe those additional customers were themselves targeted.9

That statement is evidence of what Verizon found and was prepared to say at a specific point in time. It is not meaningless. It is also a scoped claim—not a universal certification that every relevant device, route, subsidiary, service or historical artifact had been independently examined and permanently cleared.

That harder verification question belongs at the center of Part 2 of this series. For Part 1, the immediate problem is more basic: the public cannot reconstruct a complete carrier-by-carrier account from the government’s own disclosures.

What the attackers found

The campaign succeeded not because China possessed magic but because important networks contained familiar weaknesses at scale.

The August 2025 multinational advisory said the actors had operated globally since at least 2021. They focused on the large backbone routers used by major telecommunications providers and on provider-edge and customer-edge routers. They exploited publicly known vulnerabilities and other avoidable weaknesses, modified router configurations to preserve long-term access, used compromised devices and trusted connections to move into other networks, and targeted sectors beyond telecommunications—including government, transportation, lodging and military infrastructure.10

Independent telemetry supports the broader technical pattern while complicating any simple claim that Salt Typhoon mainly depended on vulnerability exploitation. Cisco Talos reported that, among the Cisco-device incidents it investigated, it found only one case in which CVE-2018-0171 was likely abused; in the others, initial access came through legitimate victim credentials obtained by the actor. Talos observed persistence across multiple vendors, including one instance lasting more than three years, along with configuration theft, infrastructure pivoting and device changes that included GRE tunnels and alternate SSH services for persistent access.11

Recorded Future’s Insikt Group separately reported observing the Salt Typhoon-aligned group it tracks as RedMike exploit unpatched, internet-facing Cisco IOS XE devices through CVE-2023-20198 and CVE-2023-20273, obtain elevated privileges, change device configurations and add GRE tunnels. The two reports support multiple access paths rather than one universal intrusion recipe. Insikt Group described RedMike as aligned with the Microsoft-named Salt Typhoon cluster; this series does not treat the names as perfectly interchangeable.12

This is the uncomfortable operational lesson. A nation-state campaign can be sophisticated in selection, patience and exploitation while still depending on old vulnerabilities, weak configuration management, exposed management interfaces, legacy equipment and incomplete visibility.

Neuberger described one telecommunications environment in which a single administrator account could reach more than 100,000 routers. Once the account was compromised, she said, the actors inherited that breadth of access.13

That example should not be generalized to every carrier. It demonstrates the leverage created when privileged access is concentrated without sufficient segmentation and control. A single compromised credential or management plane can turn one intrusion into a network-wide intelligence position.

## Response without a complete measurement

The government’s response began with hunting and hardening guidance, sanctions and regulatory action. The Treasury Department sanctioned Sichuan Juxinhe Network Technology Co. on January 17, 2025, saying the China-based company had direct involvement in the Salt Typhoon group.14 The FCC clarified carriers’ cybersecurity obligations under the Communications Assistance for Law Enforcement Act in January 2025 and proposed additional risk-management requirements.15

The response continued into 2026, but it widened beyond the original carrier intrusions. In January, the FCC adopted risk-tiered foreign-adversary-control attestation and disclosure requirements covering specified FCC licenses, leases, authorizations, permits, grants and other approvals.16 In March, acting on an interagency national-security determination, the FCC added foreign-produced consumer-grade routers to its Covered List unless they received a specific conditional approval. The determination cited Salt Typhoon alongside Volt Typhoon and Flax Typhoon as examples of campaigns in which foreign-produced routers had been implicated.17

Those actions show continuing government concern. They do not, by themselves, measure which carrier systems were reached in 2024, what evidence was retained or whether every affected environment satisfied a common remediation standard.

The Congressional Research Service wrote in January 2025 that the attackers’ methods and the specific systems or data targeted had not been fully disclosed publicly. Congress had questions not only about the breach but about the government’s discovery and immediate response, the privacy of Americans’ communications, and the preparedness of the communications sector.18

Those questions have outlived the initial emergency.

## A campaign bigger than the original U.S. carrier breach

By August 2025, the United States and a dozen international partners described a global espionage system rather than a closed incident at a handful of American carriers. The joint advisory linked the activity to multiple China-based technology companies serving Chinese intelligence organizations and said stolen data from telecommunications, internet-service, lodging and transportation targets could help Chinese intelligence identify and track people’s communications and movements around the world.19

The advisory did not provide a public victim ledger or one global number that can safely be treated as a confirmed-compromise count. Later press accounts used materially different verbs—including “targeted,” “impacted,” “hit” and “compromised.” Without a direct record defining those categories, this story does not convert secondary-reported global estimates into confirmed-victim counts.

There is stronger primary evidence that the operational problem persisted beyond the original U.S. disclosures.

On June 19, 2025, the Canadian Centre for Cyber Security said three network devices registered to a Canadian telecommunications company had been compromised by likely Salt Typhoon actors in mid-February 2025. The agency said the actors exploited CVE-2023-20198, retrieved the running configuration files from all three devices and modified at least one configuration to create a GRE tunnel capable of collecting network traffic.20

Norway’s Police Security Service said in its 2026 National Threat Assessment that Salt Typhoon had compromised vulnerable network devices in Norwegian organizations.21

Those disclosures establish campaign-level persistence and continuing international reach. They do not prove that Salt Typhoon remains inside Verizon or any other named U.S. carrier.

## The breach that resists a final number

The temptation with Salt Typhoon is to search for one number that defines it: nine U.S. telecom companies, millions-scale call-record and metadata exposure, or fewer than 100 content targets.

Each number describes a different layer of the operation. None is a complete answer.

The public record does not identify all nine U.S. companies. It does not provide a carrier-by-carrier account of how long the actors remained, which systems they reached, how much data they copied, which customer populations were implicated, or how each company validated containment. The government has published enough to establish a historic counterintelligence breach, but not enough to let the public measure it from end to end.

Senator Mark Warner, then chairman of the Senate Intelligence Committee, called it the “worst telecom hack in our nation’s history—by far” in a November 21, 2024 interview with The Washington Post.22 The language was dramatic. The available record makes clear why he used it.

But the lasting lesson is not that every telephone call is unsafe or that every carrier remains compromised. It is that telephone networks became an intelligence platform for an adversary, and the institutions responsible for those networks have never produced one public, independently testable account of what happened across the sector.

That uncertainty has consequences. It limits what customers can understand about their exposure. It makes congressional oversight dependent on what companies and agencies choose—or are legally able—to provide. It leaves policy arguments vulnerable to selective language: “contained,” “no current activity,” “affected,” “targeted,” “secure.” Each can be accurate within a defined scope while failing to answer the larger question.

Salt Typhoon did not have to intercept every American to alter the security assumptions beneath American communications. It only had to demonstrate that access to the network could yield metadata at national scale, content from selected targets and information tied to lawful surveillance.

The first task is therefore not to declare the breach over or endless. It is to measure it honestly.

Part 2 examines the claims that affected networks were secured, the outside assessments Congress has sought, and whether any institution can independently verify the cleanup without pretending that any complex network can be certified safe forever.

Source notes

Methodology note

This story distinguishes confirmed compromise, targeting, access, metadata exposure and communications-content collection according to each source’s wording. Commercial actor names are not treated as perfect one-to-one equivalents. Campaign-level persistence is not used to claim current access inside any named carrier. Figures reported only through secondary accounts—including the unresolved 200-organization/80-country formulation—are excluded from the factual spine unless a direct record defines them.

1. CISA, Mobile Communications Best Practice Guidance, December 2024: https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf↩︎ 1. FBI and CISA, “Joint Statement … PRC Targeting of Commercial Telecommunications Infrastructure,” November 13, 2024: https://www.cisa.gov/news-events/news/joint-statement-fbi-and-cisa-peoples-republic-china-prc-targeting-commercial-telecommunications↩︎ 1. CISA/NSA/FBI and international partners, AA25-239A, “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System,” last revised September 3, 2025: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a↩︎ 1. FBI and CISA, “Joint Statement … PRC Targeting of Commercial Telecommunications Infrastructure,” November 13, 2024: https://www.cisa.gov/news-events/news/joint-statement-fbi-and-cisa-peoples-republic-china-prc-targeting-commercial-telecommunications↩︎ 1. White House archive, on-the-record briefing with Anne Neuberger, December 27, 2024: https://bidenwhitehouse.archives.gov/briefing-room/press-briefings/2024/12/27/on-the-record-press-gaggle-by-white-house-national-security-communications-advisor-john-kirby-38/↩︎ 1. FBI Director Kash Patel, statement for the record, House Judiciary Committee, September 17, 2025: https://www.fbi.gov/news/speeches-and-testimony/oversight-of-the-federal-bureau-of-investigation-091725↩︎ 1. FBI and CISA, “Joint Statement … PRC Targeting of Commercial Telecommunications Infrastructure,” November 13, 2024: https://www.cisa.gov/news-events/news/joint-statement-fbi-and-cisa-peoples-republic-china-prc-targeting-commercial-telecommunications↩︎ 1. White House archive, on-the-record briefing with Anne Neuberger, December 27, 2024: https://bidenwhitehouse.archives.gov/briefing-room/press-briefings/2024/12/27/on-the-record-press-gaggle-by-white-house-national-security-communications-advisor-john-kirby-38/↩︎ 1. Verizon, “Verizon provides update on Salt Typhoon matter,” January 10, 2025: https://www.verizon.com/about/news/verizon-provides-update-salt-typhoon-matter↩︎ 1. CISA/NSA/FBI and international partners, AA25-239A, “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System,” last revised September 3, 2025: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a↩︎ 1. Cisco Talos, “Weathering the storm: In the midst of a Typhoon,” February 20, 2025: https://blog.talosintelligence.com/salt-typhoon-analysis/↩︎ 1. Recorded Future Insikt Group, “RedMike (Salt Typhoon) Exploits Cisco Vulnerabilities for Cyber Espionage,” February 13, 2025: https://www.recordedfuture.com/research/redmike-salt-typhoon-exploits-vulnerable-devices↩︎ 1. White House archive, on-the-record briefing with Anne Neuberger, December 27, 2024: https://bidenwhitehouse.archives.gov/briefing-room/press-briefings/2024/12/27/on-the-record-press-gaggle-by-white-house-national-security-communications-advisor-john-kirby-38/↩︎ 1. U.S. Treasury, “Treasury Sanctions Company Associated with Salt Typhoon and Hacker Associated with Treasury Compromise,” January 17, 2025: https://home.treasury.gov/news/press-releases/jy2792↩︎ 1. FCC 25-9, Protecting the Nation’s Communications Systems from Cybersecurity Threats, adopted January 15, 2025: https://docs.fcc.gov/public/attachments/FCC-25-9A1.pdf↩︎ 1. FCC 26-2, Protecting Our Communications Networks by Promoting Transparency Regarding Foreign Adversary Control, adopted January 29, 2026: https://docs.fcc.gov/public/attachments/FCC-26-2A1.pdf↩︎ 1. FCC Public Safety and Homeland Security Bureau, DA 26-278, “Addition of Routers Produced in Foreign Countries to FCC Covered List,” March 23, 2026: https://docs.fcc.gov/public/attachments/DA-26-278A1.pdf↩︎ 1. Congressional Research Service, IF12798, Salt Typhoon Hacks of Telecommunications Companies and Federal Response Implications, updated January 23, 2025: https://www.congress.gov/crs-product/IF12798↩︎ 1. CISA/NSA/FBI and international partners, AA25-239A, “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System,” last revised September 3, 2025: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a↩︎ 1. Canadian Centre for Cyber Security, “PRC cyber actors target telecommunications companies as part of a global cyberespionage campaign,” modified June 19, 2025: https://www.cyber.gc.ca/en/guidance/cyber-threat-bulletin-prc-cyber-actors-target-telecommunications-companies-global-cyberespionage-campaign↩︎ 1. Norway Police Security Service, National Threat Assessment 2026, English edition, p. 17: https://www.pst.no/wp-content/uploads/2026/02/National-Threat-Assessment-2026.pdf↩︎ 1. The Washington Post, “Top senator calls Salt Typhoon ‘worst telecom hack in our nation’s history,’” November 21, 2024: https://www.washingtonpost.com/national-security/2024/11/21/salt-typhoon-china-hack-telecom/↩︎