Salt Typhoon, Part 2: The Cleanup Nobody Can Independently Verify
AT&T and Verizon say their networks are secure. The Senate Commerce ranking member says the assessments that would let Congress test those claims have not been produced. A seven-day document request from this publication drew an AT&T out-of-office acknowledgment and a Verizon internal handoff — not the requested letters, and not written refusals. Commerce and Mandiant/Google still have not replied on the record. Who controls the evidence.
Listen to this article
AI-generated narration · 21:35
AI-generated narration from the final published article text. No interview or field audio is included.
Part 1 of this series established what the public record can support about Salt Typhoon: PRC-affiliated actors compromised networks at multiple U.S. telecommunications companies; they stole customer call-record data related to millions of people; they compromised private communications belonging to a much smaller group, primarily those involved in government or politics; and they copied certain information sought by U.S. law enforcement under court orders. The government has never published a complete, authoritative list of the nine companies Deputy National Security Advisor Anne Neuberger counted in December 2024.
Part 1 left a harder question on the table. Verizon’s January 10, 2025 statement is one of the clearest public carrier accounts. It is a scoped claim from a specific date. It is not a universal certification that every relevant device, route, subsidiary, service, or historical artifact had been independently examined and permanently cleared. This installment is about that verification problem: who has seen the cleanup evidence, who has not, and what “secure” can mean when the documents stay with the companies.
It is not a finding that AT&T or Verizon remains compromised. That claim is not in the public record this installment uses.
What the carriers have said in public
On January 10, 2025, Verizon said it had contained a cyber incident brought on by a highly sophisticated nation-state threat actor. Vandana Venkatesh, then the company’s chief legal officer, said Verizon had “not detected threat actor activity in Verizon’s network for some time” and that, after considerable work, “Verizon has contained the activities associated with this particular incident.” Verizon said an independent and highly respected cybersecurity firm had confirmed the containment.
That is the company’s own language. It is dated. It is scoped to “this particular incident.” It does not, on its face, hand Congress the underlying assessment.
AT&T’s matching first-party containment page is still not on file for this series. Secondary reports in late December 2024 and January 2025 quoted an AT&T spokesperson saying the company detected no nation-state activity in its networks at that time. Until AT&T’s own text is retrieved, this installment does not put a “secure” quote in AT&T’s mouth.
An unnamed “independent firm” and Mandiant are not treated here as the same assessor unless a primary says so.
What Cantwell put on the committee record
On February 3, 2026, Senator Maria Cantwell, ranking member of the Senate Committee on Commerce, Science, and Transportation, wrote Chairman Ted Cruz asking for an oversight hearing with the CEOs of AT&T and Verizon.
The letter’s load-bearing sentences, quoted:
“For months, I have sought specific documentation from AT&T and Verizon that would purportedly corroborate their claims that their networks are now secure from this attack.”
“Unfortunately, both AT&T and Verizon have chosen not to cooperate, which raises serious questions about the extent to which Americans who use these networks remain exposed to unacceptable risk.”
Cantwell wrote that she had sent letters to AT&T CEO John Stankey and then-Verizon CEO Hans Vestberg; that both companies confirmed the existence of security assessments conducted by Mandiant; and that “both AT&T and Verizon have refused to make these key reports available without any compelling reason to keep them hidden from Congress.”
She then wrote: “I wrote to Mandiant requesting copies of these reports and other relevant documentation. But AT&T and Verizon apparently intervened to block Mandiant from cooperating with my requests.”
A footnote says the Mandiant reply, from Anne Wall, dated August 6, 2025, is on file with Democratic committee staff, and that the companies “apparently intervened to claim attorney-client privilege over these Mandiant reports—despite the fact that neither company previously asserted any such privilege when asked by my staff.”
Those are Cantwell’s characterizations of the replies. The outgoing letters are independently read. The committee-file replies are not public.
What the June 12 letters actually asked
On June 12, 2025, Cantwell wrote AT&T CEO John T. Stankey and then-Verizon CEO Hans Vestberg. The letters are nearly parallel. Each asked, from September 1, 2024, to present, due June 26, 2025:
- A copy of the company’s remediation plan in response to the Salt Typhoon attacks.
- All threat assessments related to the security risk of nation-state actors (AT&T: including FirstNet).
- A list of all vulnerabilities identified that allowed nation-state actors “to gain broad, full access,” and to what extent each had been mitigated or remediated.
- All documents relating to the company’s determination that there was no longer activity by nation-state actors in its networks.
- All records related to the costs and expenses incurred to secure its networks from nation-state actors, including but not limited to a third-party audit.
- (AT&T only, as numbered) All AT&T policies and best practices relating to the encryption of customer data.
The AT&T letter quotes the December 2024 claim that the network was secure and that there was “no activity by nation-state actors in our networks at this time,” citing Reuters, not an AT&T first-party page. The Verizon letter quotes “Verizon has contained the activities associated with this particular incident,” also citing Reuters (Verizon’s own January 10, 2025 page exists separately and is already used in this series).
The letters are requests. They do not contain the replies.
What the July 23 Mandiant letter actually asked
On July 23, 2025, Cantwell wrote Sandra Joyce, then Mandiant’s EVP for Intelligence and Government Affairs. She wrote that “both companies acknowledged they retained Mandiant to conduct a comprehensive assessment of the cyber incident and verify the extent to which the incident has been contained.” That acknowledgment is still Cantwell’s account of company responses this desk has not independently read.
She asked Mandiant, due August 6, 2025, for: (1) all reports, assessments, and analyses Mandiant conducted for AT&T and Verizon in response to the Salt Typhoon attacks; (2) a list of any Mandiant recommendations that have not been fully addressed by AT&T or Verizon; (3) all records related to the costs of that work.
The letter also cites a June 11, 2025 DHS Office of Intelligence and Analysis memo about Salt Typhoon and a state Army National Guard network. That is campaign-level. It does not prove remaining access inside AT&T or Verizon.
Privilege and “intervened” remain Cantwell’s characterization of files this desk has not independently read. Unavailable Mandiant reports are not proof that a named carrier is insecure. They are proof that Congress, on Cantwell’s account, does not have the assessments she asked for.
Comment window: four requests, mixed acknowledgments — not document grants
On August 22, 2026, Groove Street Journal opened a seven-day comment window on a single, narrow ask. Four plain-text letters went out from rich@gsj.app. Each letter requested only existing correspondence Cantwell cited as on file with Democratic committee staff — or a written refusal:
| Recipient | Ask |
|---|---|
| Senate Commerce ranking-member press (Tricia Enright; cc Rob Blumenthal) | Copies of Ferguson (AT&T, June 26, 2025), Fisher (Verizon, July 3, 2025), and Wall (Mandiant, Aug. 6, 2025), or written refusal |
| AT&T media / federal legislative contacts | Copy of the Ferguson June 26, 2025 letter, or written refusal |
| Verizon corporate communications (Rich Young; Kevin Israel) | Copy of the Fisher July 3, 2025 letter, or written refusal |
| Mandiant / Google Cloud press | Copy of the Wall Aug. 6, 2025 letter, or written refusal |
No interviews. No questions about current network status. No request that any party characterize remediation. Deadline in the body of each letter: August 29, 2026.
A native review of the rich@gsj.app mailbox on September 7, 2026, found replies — but not the requested documents, and not written refusals:
| Party | What arrived | What it is not |
|---|---|---|
| AT&T | Auto-reply 2026-08-22 10:56 AM ET from Megan Ketterer (mk045r@exo.att.com): out of office, returns Monday; urgent contact Paige Hill (ph8505@att.com) | Not a grant of the Ferguson letter. Not a written refusal. OOO is not a refusal. |
| Verizon | 2026-08-22 11:54 AM ET from Richard J. Young routing to christopher.debosier@verizon.com (cc Kevin Israel): “Chris. For your handling please.” | Internal handoff. Not the Fisher July 3, 2025 letter. Not a written refusal. |
| Senate Commerce (Enright / Blumenthal) | No reply on record in that native review | Still no document or written refusal |
| Mandiant / Google (press@google.com) | No reply on record in that native review | Still no document or written refusal |
| AT&T GenMedia substantive | No substantive reply beyond the Ketterer OOO auto-reply | Still no Ferguson letter / refusal |
The window did not produce a uniform silence. What arrived was an AT&T out-of-office acknowledgment; a Verizon internal routing note; and continuing silence from Commerce and Mandiant/Google on the record reviewed.
An OOO auto-reply is not a refusal. An internal handoff is not production of the Fisher letter. Silence from Commerce and Mandiant/Google is not proof of compromise. None of those outcomes substitutes for reading the committee-file letters themselves. The same documents Cantwell says sit on committee file still did not arrive here as grants — and neither AT&T nor Verizon issued a written refusal to produce them.
That outcome sits beside Cantwell’s February account, not above it. Her letter says Congress lacks the assessments. Our closed window shows a newsroom asking for the same underlying correspondence received acknowledgments that are not documents. Together they describe who controls the paper trail the public would need to test “secure.”
Who controls the evidence
The public now has three kinds of document-shaped fact, and they do not sit in the same place.
One kind is a carrier statement: contained, no detected activity, customers can use the network normally, details withheld because describing the work would “jeopardize cybersecurity protection methodologies.” That is Verizon’s January 2025 formulation.
The second kind is an outside assessment that, on Cantwell’s account, exists, was confirmed by the companies, and has not been produced to the committee that oversees those networks.
The third kind is still missing: an institution that can independently verify the cleanup without pretending a complex telecommunications network can be certified safe forever. Part 1 said that was the center of this installment. It remains the center. The public record does not identify such an institution. CISA and allied agencies published hunting and hardening guidance. Treasury sanctioned a China-based company. The FCC tightened obligations, then reconsidered them. None of those actions is a public, carrier-by-carrier, independently testable account of remediation.
The official December 2, 2025 hearing transcript is in hand (S. Hrg. 119-319 / CHRG-119shrg62989). Debra Jordan, former chief of the FCC Public Safety and Homeland Security Bureau, said on the record: “From my experience as Bureau Chief, I am not convinced that providers will take sufficient and sustained actions in the wake of Volt and Salt Typhoon without a strong verification regime.” She said the November 20, 2025 FCC reversal “does not cite any process by which the providers will be held accountable to meet specific commitments,” and that “hope is not really a strategy to secure our networks.” In Q&A with Senator Cantwell she added that if providers “are not doing basic hygiene across their networks consistently, then yes, they should be held accountable,” naming patching, default passwords, and encryption, and distinguishing that from an unpredictable nation-state success. That is one witness, on one date. It is not a finding that AT&T or Verizon remains compromised.
The hearing that has not been noticed
Cantwell asked Cruz to convene the CEOs. A committee spokesperson, speaking to Nextgov/FCW on February 3, 2026, said the committee had already discussed Salt Typhoon at the December hearing. A Commerce hearings-index check on September 6, 2026, still listed no noticed Commerce hearing with John Stankey and Dan Schulman on Salt Typhoon. Page listings continue to show the December 2, 2025 “Signal Under Siege” hearing as the Salt Typhoon-related session of record. As of that September 6 check, hearing timing remained the main risk that the public committee record could still change.
What the SEC filings say
Verizon’s FY2024 10-K (filed February 12, 2025) and FY2025 10-K (filed February 17, 2026) use the same risk-factor sentence:
“For example, in September 2024, we became aware that we were one of several telecommunications companies that were the subject of a cyberattack by a highly sophisticated nation-state actor known as Salt Typhoon. In that case, the threat actor was able to access portions of our network as part of what we determined to be a narrowly focused effort to obtain information about a limited number of individuals primarily involved in government or political activity. While we were able to contain the Salt Typhoon attack, we may be unable to contain or mitigate the impacts of a significant cyberattack in the future.”
That is first-party, signed, and scoped. It is not a public production of the Mandiant assessments. It does not name Mandiant.
AT&T’s FY2024 and FY2025 10-Ks do not name Salt Typhoon or the 2024–25 intrusion. Item 1C is generic governance. Absence of a named Salt Typhoon disclosure in those filings is not itself a finding of compromise.
Lumen’s FY2025 10-K discusses nation-state APTs in general and does not name Salt Typhoon. That absence likewise is not itself a finding of compromise.
FCC sequence, briefly
FCC 25-9 (January 16, 2025) declared that CALEA §105 “affirmatively requires telecommunications carriers to secure their networks from unlawful access or interception of communications,” and proposed annual cybersecurity and supply-chain plan certifications.
FCC 25-81 (November 21, 2025) rescinded that Declaratory Ruling and withdrew the NPRM, citing provider agreements and calling the January reading of CALEA unlawful and “ineffective.” Commissioner Gomez dissented. Treat “rollback left networks less secure” as attributed analysis, not a settled causal finding. Jordan’s testimony criticizes the absence of a verification process; it is not proof of named-carrier compromise.
What the public record does not currently support
The public record does not establish that AT&T is currently compromised. The public record does not establish that Verizon is currently compromised. The public record does not establish that Mandiant found remaining access. Mandiant’s reports are not in the public materials this installment relies on. Carrier silence is not treated here as proof of insecurity. Salt Typhoon’s campaign-level persistence abroad is not treated here as proof of named U.S. carrier persistence. This installment does not use the Machtinger quote. This installment does not use Singapore’s four-telecom incident. That is a different cluster. This publication’s OOO acknowledgments, internal handoffs, or unanswered requests are not treated as proof of insecurity.
The claim the public record currently supports is narrower, and it is enough: two of the largest U.S. carriers have told the public their Salt Typhoon incidents were contained; the ranking member of the committee that oversees them says the assessments that would let Congress test those statements have not been produced; a closed comment window for the underlying committee-file letters drew an AT&T out-of-office acknowledgment and a Verizon internal handoff — not the letters, not written refusals — while Commerce and Mandiant/Google still have not replied on the record; and no independent public verifier has closed the gap.
That is a control-of-evidence story. It is not a current-access story.
Sources
- Cantwell to Cruz, Feb. 3, 2026 — U.S. Senate Commerce Committee
- Cantwell to Stankey, June 12, 2025 — U.S. Senate Commerce Committee
- Cantwell to Vestberg, June 12, 2025 — U.S. Senate Commerce Committee
- Cantwell to Mandiant, July 23, 2025 — U.S. Senate Commerce Committee
- Hearing transcript, Dec. 2, 2025 (S. Hrg. 119-319) — GovInfo
- FCC 25-9 — FCC
- FCC 25-81 — FCC
- Verizon Salt Typhoon update, Jan. 10, 2025 — Verizon
- Commerce hearings index — U.S. Senate Commerce Committee
- GSJ Salt Typhoon Part 1 — Groove Street Journal