In late 2024, a Chinese state-sponsored hacking group breached the networks of several major US telecommunications carriers. The intrusions, attributed to a group tracked as Salt Typhoon by Microsoft (and as Earth Estries and GhostEmperor by other researchers), were not discovered through defensive monitoring. They were discovered because the FBI notified the carriers that their networks had been compromised.

The affected carriers included AT&T, Verizon, and T-Mobile, along with carriers in dozens of other countries. The attackers had access to systems used for court-ordered wiretapping under the Communications Assistance for Law Enforcement Act - the same infrastructure that US law enforcement agencies use to legally intercept communications. They also had access to metadata for large numbers of calls and texts, and in some cases the actual content of communications involving specific high-value targets.

Salt Typhoon and the Typhoon Naming Convention

Microsoft uses a naming convention that assigns weather-related codenames to state-sponsored threat actor groups based on their country of origin. Chinese groups receive "Typhoon" designations. Salt Typhoon joins a crowded namespace: Volt Typhoon (infrastructure pre-positioning), Flax Typhoon (Taiwan-focused operations), Silk Typhoon (Exchange server exploitation), and others. The proliferation of designations reflects the scale and diversity of Chinese state-sponsored cyber operations rather than any increase in the number of distinct organizations involved.

Salt Typhoon is assessed as a PRC state-sponsored group likely operating under the direction of the Ministry of State Security. The group focuses primarily on intelligence collection against government, defense, telecommunications, and technology targets in the US and allied nations. Prior activity attributed to Salt Typhoon includes targeting Southeast Asian governments and telecommunications providers, consistent with intelligence priorities around the South China Sea and Taiwan Strait.

CALEA: The Surveillance Infrastructure They Accessed

The Communications Assistance for Law Enforcement Act, passed in 1994, required US telecommunications carriers to build interception capabilities into their networks. When a court issues a lawful surveillance order, carriers must be able to provide real-time access to the communications of specified targets. This infrastructure - sometimes called the "lawful intercept" or "CALEA" systems - is a standard part of every major carrier's technical architecture.

The Salt Typhoon intrusions accessed these systems. This is significant for several reasons. First, the lawful intercept database contains the identities of individuals subject to surveillance orders - intelligence agencies, law enforcement, and national security investigations. Second, accessing the intercept infrastructure itself means the attackers could potentially identify who is under surveillance and, in some cases, access the content of intercepted communications. Third, the architecture of CALEA systems, designed to enable interception by authorized parties, creates an interface that an unauthorized party with network access can also reach.

[IOC]
The attackers accessed systems used to fulfill wiretap requests from the FBI and other law enforcement agencies. This gave them visibility into who was being investigated - a counterintelligence capability of significant value to a foreign intelligence service. The FBI notified carriers of the intrusion; carriers had not independently detected it.

Security researchers have noted this irony for decades: mandating that carriers build interception infrastructure creates capabilities that can be turned against the networks themselves. A 2005 incident in Greece illustrated this when the lawful intercept system on Vodafone's network was compromised by unknown attackers who used it to monitor the communications of senior Greek government officials, including the prime minister, for nearly a year. The CALEA architecture embeds the same structural vulnerability into every US carrier's network.

The Scope of Access

The intrusions were described by US officials as "significant and concerning" at congressional briefings in late 2024. Senator Mark Warner, chair of the Senate Intelligence Committee, called it "the worst telecom hack in our nation's history" and said the hack was "much worse than originally reported." The attackers had been inside carrier networks for months, in some cases for over a year.

Beyond the CALEA systems, the attackers accessed metadata - records of which numbers called which numbers, when, and for how long, along with geolocation data associated with the calls. This is the same category of bulk metadata collection that the NSA's domestic surveillance programs collected under Section 215 of the PATRIOT Act. For a foreign intelligence service, bulk call metadata for a significant portion of US communications is extraordinarily valuable for mapping relationships, identifying intelligence sources, and tracking the activities of targets.

Content access - the actual words of specific calls and texts - was more limited. Reporting indicated that the attackers had intercepted communications involving a small number of high-value targets, including individuals involved in national security and policy work, and communications associated with the presidential campaigns of both Donald Trump and Kamala Harris. The targeting of campaign communications drew particular attention given the proximity to the 2024 election.

Technical Entry Points

Public reporting on the specific technical methods used is limited, reflecting the ongoing sensitivity of the investigation. What has been confirmed: the attackers exploited vulnerabilities in carrier network infrastructure, consistent with the group's established pattern of targeting network edge devices and management systems. Cisco routers and network management systems were identified as entry points in some incidents. The attackers demonstrated sophisticated knowledge of carrier network architectures and the location of specific high-value systems within them.

Salt Typhoon has historically been associated with exploitation of network devices - routers, switches, and network management systems that tend to have long patch cycles, run outdated software, and receive less security scrutiny than endpoints. Telecommunications carrier networks, which run legacy infrastructure alongside modern systems and prioritize availability over security patching, represent a particularly rich target environment for this approach.

[WARNING]
CISA and the FBI issued joint guidance in December 2024 recommending that US government and senior political officials move away from SMS and unencrypted voice calls for sensitive communications, specifically because of the Salt Typhoon intrusions. The recommendation was to use end-to-end encrypted messaging applications. This is an unusual public posture - US government agencies typically avoid recommending specific consumer applications.

The Geopolitical Context

Salt Typhoon's telecom campaign does not exist in isolation. It's part of a broader pattern of Chinese state-sponsored operations that US officials have characterized as the most active and sophisticated cyber espionage campaign against the US since at least 2020. Volt Typhoon, a separate group, had been pre-positioning access in US critical infrastructure - power grids, water systems, transportation networks - in what officials assessed as preparation for potential disruptive operations in a crisis scenario involving Taiwan. The combination of intelligence collection (Salt Typhoon) and infrastructure pre-positioning (Volt Typhoon) suggested a comprehensive strategy rather than opportunistic attacks.

China denied responsibility for both campaigns, consistent with its standard response to attribution of state-sponsored cyber operations. The PRC government characterized US attributions as politically motivated and pointed to US revelations about NSA surveillance programs as evidence of hypocrisy. This rhetorical pattern has become standard in cyber diplomacy between the US and China, with little substantive dialogue on norms.

The CALEA Debate Revived

The Salt Typhoon intrusions revived a debate that has recurred periodically since the 1990s: whether building surveillance capabilities into communications infrastructure makes everyone less secure. Law enforcement and intelligence agencies argue that lawful intercept is an essential tool for investigations and national security. Security researchers and civil libertarians have consistently argued that the same infrastructure creates vulnerabilities that will eventually be exploited.

The Salt Typhoon compromise of CALEA systems is the most significant validation of the security-researchers' concern in the history of the debate. The lawful intercept infrastructure that US law enforcement depends on was accessed by a foreign intelligence service. The names of individuals under surveillance were potentially exposed to an adversary. The debate will continue, but the empirical case for the security researchers' position has never been stronger.

In the wake of the disclosures, CISA's recommendation that officials use encrypted applications implicitly concedes that the carrier-level infrastructure cannot be trusted for sensitive communications. This is an extraordinary position for a US government agency - acknowledging that the telecommunications infrastructure at the center of US law enforcement surveillance has been so thoroughly compromised that officials should route around it.

Response and Ongoing Investigation

The affected carriers worked to identify and remediate the intrusions through late 2024 and into 2025. Fully evicting a sophisticated nation-state actor from carrier-grade network infrastructure is a complex, time-consuming process - attackers of this caliber establish multiple persistence mechanisms and are aware of detection and remediation efforts, sometimes shifting to alternate access paths as defenders close others.

The Senate Intelligence Committee and House committees held classified briefings. Proposed legislation to strengthen CALEA security requirements and mandate better network monitoring for carriers did not advance through the legislative process before the end of the 118th Congress. The issue remained active in oversight discussions in 2025, alongside broader questions about Volt Typhoon and the state of US critical infrastructure security.

No individuals have been publicly indicted in connection with Salt Typhoon's telecom operations as of mid-2026. The investigation continues.