The standard breach narrative has a shape to it: data taken, scope defined, remediation performed, lessons documented. You can, in principle, understand what was stolen. You can attempt to bound the damage.
Salt Typhoon doesn’t fit that shape. What was targeted wasn’t a database of customer records or a tranche of intellectual property. It was access to the infrastructure through which governments surveil people, and the intelligence consequences of that access may not be fully understood for years.
The Systems That Were the Target
Every regulated telecommunications carrier is required by law to maintain the capability to intercept specific accounts when presented with a valid legal order. In the United States, that obligation derives from the Communications Assistance for Law Enforcement Act (CALEA), passed in 1994. The UK has equivalent requirements under the Investigatory Powers Act. Every EU member state has its own version.
In practice, this means a dedicated technical capability within the carrier’s network: infrastructure that can capture and route the communications of targeted subscribers (calls, SMS, metadata) to the requesting law enforcement or intelligence agency.
These systems are sensitive by design. They process information about active surveillance operations: the identities of individuals under government investigation, the targets of intelligence collection, the suspects in criminal cases. The identities of those targets are typically classified. The existence of specific surveillance operations is typically not acknowledged publicly.
They’re also, in many carriers, old. Underfunded. Connected to infrastructure built well before sophisticated nation-state actors were a design consideration. CALEA was written for a different era. The threat environment of 2024 was not what the architects of most lawful intercept implementations were building for, and the gap between those two realities is what Salt Typhoon exploited.
How the Compromise Worked
Salt Typhoon, also tracked as GhostEmperor, FamousSparrow, and Earth Estries, has been attributed to Chinese state sponsorship, assessed to operate under PLA or MSS direction. The group has been active since at least 2019, with documented targeting of Southeast Asian government entities and global telecoms companies preceding the 2024 US campaign.
Initial access came through vulnerabilities in internet-facing network edge equipment: Cisco and Fortinet devices sitting at the perimeter of major carrier networks. Unpatched edge infrastructure as the entry point is a pattern that runs through Chinese APT operations consistently, and the fact that major US carriers were running vulnerable perimeter equipment is not a surprise to anyone who’s worked in the sector.
From the perimeter, the group moved laterally through carrier infrastructure over a period of months. Patient, methodical movement toward the highest-value systems. Eventually, they reached the infrastructure managing lawful intercept capability. The access wasn’t detected through normal security operations; disclosure came through a combination of threat intelligence, FBI investigation, and in at least one case, a carrier noticing anomalous traffic patterns associated with the group’s C2 infrastructure.
Who Was Affected
The Wall Street Journal’s October 2024 reporting named AT&T, Verizon, and Lumen Technologies as affected carriers. Subsequent reporting added T-Mobile, Charter Communications, and Consolidated Communications. FBI and CISA briefings to Senate Intelligence Committee members indicated the scope was broader than initial reporting captured.
Outside the US, European carriers have been identified in subsequent intelligence assessments. Attribution and disclosure processes in individual European jurisdictions have moved more slowly than in the US. At least two major European carriers are believed to have had active or recently-active access, as we reported in our earlier flash briefing.
The specific individuals targeted for lawful intercept access have not been fully disclosed publicly. What has been reported suggests a deliberate intelligence operation: Chinese nationals in the US, Chinese-American political donors with connections to both presidential campaigns in 2024, and, most strategically significant, individuals who were themselves targets of US government surveillance operations.
That last category is worth pausing on. If Chinese intelligence could identify which of its operatives were under active US surveillance, the implications for ongoing intelligence operations are severe.
What the Access Was Actually Worth
The intelligence value here is qualitatively different from a conventional data breach. Four things matter.
Counter-surveillance. Knowing which of your operatives, assets, or persons of interest are under US government surveillance allows you to modify their behaviour, protect active intelligence assets, and potentially compromise ongoing investigations. The damage to US human intelligence operations from this specific access is likely years from being fully assessed.
Source and method exposure. Understanding which individuals the US government was watching, through which legal mechanisms, and what that implies about its intelligence collection priorities is significant. It reveals tradecraft. It reveals cooperation. It reveals capability.
US government communications. Reporting indicates that phone calls involving senior US government officials (including individuals associated with political campaigns) were within scope of the access. The content is unknown. The potential value is not.
Negotiating intelligence. Access to communications of individuals involved in US-China diplomatic and commercial interactions would provide meaningful advantage in any ongoing interactions. Precisely what categories of people carry lawful intercept obligations in their carrier infrastructure.
The Structural Problem Nobody Wants to Say Plainly
The Salt Typhoon campaign forces a direct confrontation with a tension that government agencies have spent years trying to avoid discussing publicly.
Governments require that telecommunications carriers maintain lawful intercept capability. This is legitimate: law enforcement and national security investigations depend on it. But the technical infrastructure that implements that requirement is an attack surface. A determined adversary can target it. Salt Typhoon did.
The alternative, end-to-end encrypted communications that the carrier cannot access, is already how much consumer communication works. WhatsApp, Signal, iMessage. These products cannot be reached through traditional lawful intercept mechanisms. Government agencies in the US and UK have been pressing, repeatedly, for regulation requiring these platforms to maintain backdoor access for law enforcement.
Salt Typhoon is the clearest possible argument against that position. A backdoor for law enforcement is a backdoor. It doesn’t stay exclusive to law enforcement. The infrastructure that allows authorised access also creates the attack surface that unauthorised actors target. The policy conversation has been abstract for years. It is no longer abstract.
The Response and What’s Unresolved
CISA and the FBI published detailed guidance for telecommunications operators: network edge security, authentication hardening, specific indicators of compromise associated with Salt Typhoon activity. The FCC has tightened reporting requirements for carriers under incident reporting rules. CISA has expanded its engagement programme with major carriers.
Senate hearings after the disclosure produced testimony suggesting that in some cases carrier security teams had been aware of anomalous network activity for periods before reporting to government. That’s a disclosure obligations conversation that hasn’t finished.
What hasn’t been resolved is the strategic question underneath all of it: what does Western telecommunications security architecture look like when a determined adversary can reach the most sensitive systems that carriers operate? The technical mitigations are important and necessary. They are not an answer to that question. Answering it requires honesty about the trade-offs between intelligence capability, security architecture, and the limits of what technical measures can achieve when the adversary is patient, well-resourced, and operating on a timeline measured in years.
For Communications Sector Leaders
The immediate CISA priorities, endorsed by NCSC for UK operators:
-
Audit all internet-facing network edge equipment (routers, load balancers, VPN concentrators) against the firmware versions and configurations associated with Salt Typhoon access vectors. This is not optional and it is not a one-time exercise.
-
Implement phishing-resistant MFA on all management interfaces. Hardware token or certificate-based authentication. SMS-based 2FA is vulnerable to SIM swapping; using it to protect the most sensitive systems in your network is not a control, it’s a false comfort.
-
Ensure access to lawful intercept systems is logged at the management layer, with those logs stored in a separately segmented environment. If the adversary can reach your lawful intercept infrastructure, they can potentially reach the logs that would document that access.
-
Commission a network segmentation review focused specifically on lateral movement paths from your perimeter to your most sensitive systems. Close the shortest routes. Know what the second-shortest routes are.
The carriers that managed the 2024 disclosures most effectively had invested in comprehensive network logging and had security teams with genuine expertise in carrier infrastructure anomaly detection. Building that capability, for organisations that don’t have it, is the work, and it takes time that attackers are not giving back.