Salt Typhoon: How China Walked Through America’s Wiretap Backdoor — And Why It Is Still Not Fixed
In 1994 the United States passed a law requiring telephone companies to build surveillance access into their networks. The point was to let the FBI execute court-ordered wiretaps as phone systems went digital.
Thirty years later, a Chinese intelligence operation walked through that access.
That is the Salt Typhoon story in two sentences, and it is why security researchers treat it as something more serious than a large data breach. The group did not defeat American telecom security so much as inherit it. The wiretap capability was already there, mandated, maintained, and connected to the most sensitive traffic on the network. Salt Typhoon found the door and used it.
Two years after the campaign became public, the story is still moving. A House Select Committee report released on 4 August 2026 found that Chinese state-owned telecom firms kept equipment and network ties inside the United States long after regulators tried to push them out. Carriers say they have evicted the intruders. The Senate Commerce Committee and multiple outside researchers say that claim has not been demonstrated.
Here is what Salt Typhoon actually is, how it got in, what it took, where the investigation stands in 2026, and the part almost no coverage gets to — what any of this means for the phone in your pocket.
What Salt Typhoon Is
Salt Typhoon is the Microsoft-assigned name for an advanced persistent threat group that Western intelligence agencies link to China's Ministry of State Security. Other vendors track overlapping activity as Earth Estries, FamousSparrow, GhostEmperor and UNC2286, which is why the same campaign appears under different names depending on whose report you are reading.
It is an espionage operation, not a criminal one. There is no ransomware, no extortion note, no attempt to monetise what was taken. The objective is intelligence: who is talking to whom, from where, and when. That places it in a different category from the infrastructure attacks the industry usually reports, such as the compromise of Hugging Face or OpenAI's model containment breach.
The scale, in the numbers agencies have actually published: a joint advisory issued on 27 August 2025 by the FBI, NSA and CISA together with agencies from twelve partner nations described roughly 600 organisations worldwide notified of potential compromise, including about 200 in the United States, across more than 80 countries. Targeted sectors were listed as telecommunications, government, transportation, lodging and military infrastructure.
Activity has been traced back to at least 2019, and in some assessments earlier. This was not a smash-and-grab. It was a multi-year residency.
The same advisory did something unusual: it named the commercial contractors allegedly supplying the capability. Three China-based companies were identified — Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology and Sichuan Zhixin Ruijie Network Technology — described as providing network technology and offensive cyber services to units of the People's Liberation Army and the Ministry of State Security. State intelligence work outsourced to private vendors is now a documented feature of the model, not a theory about it.
How They Got In — The Boring Answer Nobody Wants
There is no zero-day masterpiece at the centre of this. The initial access method, according to the joint advisory, was overwhelmingly known vulnerabilities in internet-facing edge devices that had not been patched — routers, firewalls and VPN appliances sitting at the boundary of large networks.
The named flaws are ordinary and, in several cases, old:
CVE-2023-20198 — Cisco IOS XE Web UI privilege escalation.
CVE-2018-0171 — Cisco Smart Install remote code execution, disclosed in 2018.
CVE-2024-3400 — Palo Alto Networks GlobalProtect gateway command injection.
Plus known issues in Ivanti Connect Secure and Policy Secure appliances.
Read that list again. A vulnerability first disclosed in 2018 was still viable years later on infrastructure carrying a significant share of American communications. That is the actual finding, and it is more uncomfortable than any exotic exploit would have been.
Once inside, the tradecraft was disciplined. Rather than dropping obvious malware, the group modified the network devices themselves — living in the router rather than on a server:
Persistence through configuration. They added generic routing encapsulation (GRE) tunnels to maintain reachable access, altered access control lists to permit their own addresses, and opened standard and non-standard ports. On Cisco IOS XR devices they created local users with elevated privileges via sshd_operns, listening on TCP/57722. None of that is malware. It is administration — performed by the wrong administrator.
Credential harvesting by packet capture. The actors captured traffic targeting TCP port 49 — TACACS+, the protocol carrying authentication for network equipment, including the credentials of highly privileged network administrators. Capture that, and you no longer need to break in anywhere. You log in.
This is why eviction is so difficult, and why the disputes covered further down are not corporate evasiveness alone. A backdoor implemented as a legitimate configuration change on a trusted device does not look like an infection. It looks like the network.
The CALEA Problem — Why This Breach Is Different
Every large breach produces the same sentence: attackers accessed sensitive customer data. Salt Typhoon earns a different one.
The Communications Assistance for Law Enforcement Act, passed in 1994, requires telecommunications carriers to build their networks so that court-authorised interception is technically possible. As telephony moved from analogue copper to digital switching, CALEA ensured wiretap orders could still be executed. Every major American carrier maintains this capability. It is not optional and it is not secret.
Reporting on the campaign found that Salt Typhoon reached systems associated with that lawful-intercept function at major carriers. The surveillance capability built by legal mandate became a target — and, for a period, an asset held by a foreign intelligence service.
The implication is worth stating plainly, because it is the part that outlives the news cycle. A backdoor does not know who is walking through it. A capability built for lawful access under judicial oversight is, technically, just a capability. It cannot distinguish an FBI agent with a warrant from an intelligence officer in another country who has obtained the same access. Cryptographers have argued this for three decades against proposals for mandated exceptional access. Salt Typhoon converted the argument into an incident report. The wider pattern — surveillance systems deployed faster than the oversight around them — shows up elsewhere too, as it did with the documented error rates in automated police surveillance.
There is a second layer. The FBI's Digital Collection System Network (DCSNet) — the infrastructure the bureau uses to manage court-authorised wiretaps and FISA collection — was itself breached, and senior Justice Department officials classified the event as a FISMA major incident, the statutory category for breaches likely to cause demonstrable harm to national security. Attribution here requires care: the FBI has not publicly confirmed Salt Typhoon was responsible, stating only that the techniques identified are consistent with the group's known tradecraft. Treat that as an open question, not a settled fact.
In December 2024 the consequence arrived in the strangest possible form. The FBI and CISA — the same government that has spent years arguing for lawful access to encrypted communications — advised Americans to stop sending unencrypted SMS and switch to end-to-end encrypted messaging, naming Signal as an example. CISA directed the guidance most urgently at senior government and political figures.
A government telling its citizens to encrypt because it can no longer guarantee the phone network is not a routine advisory. It is a concession.
What Was Actually Taken
Precision matters here, because the coverage has blurred two very different things.
Metadata, at enormous scale. Call detail records — which number called which, when, for how long, and from roughly where. This is the bulk of what was taken, and it is more revealing than people assume. Metadata does not need content to be damaging: a pattern of calls to a specific clinic, a lawyer, a competitor, or a government office describes a life without recording a single word. It is the same principle behind what can be inferred about you from ordinary online activity — the pattern is the payload.
Content, for a small number of targets. Reporting indicated that a limited set of individuals — including people associated with US political campaigns — had communications content accessed. That is the sharpened end of the operation: bulk metadata to identify who matters, targeted collection against the shortlist.
Geolocation and interception-related data. Where devices were, and information tied to the lawful-intercept systems described above.
What this was not: a breach of your bank balance, your passwords or your photos. Nobody is selling your identity on a forum because of Salt Typhoon. The value here was intelligence, and the people whose content was targeted were selected for reasons of state, not opportunity.
That distinction should lower your personal alarm and raise your structural concern, which is roughly the correct response.
Where the Investigation Stands in 2026
This is where most explainers stop, having ended their story in 2024. The last eighteen months are the more interesting part.
The carriers said it was over. AT&T stated it detected no nation-state actor activity in its networks. Verizon's chief legal officer said the company had contained the activities associated with the incident and had not detected threat actor activity for some time.
Very few outside observers accepted that. In December 2025 the Senate Commerce Committee published a blunt assessment: American networks remain vulnerable, and the carriers have not convincingly demonstrated that the intruders were evicted. A researcher at Censys put the technical objection more directly — everybody is rushing to declare the problem solved, and that is neither how security nor how intelligence services work.
The demands for proof went unanswered. In February 2026 Senator Maria Cantwell wrote to the chief executives of AT&T and Verizon asking for documentation showing that the vulnerabilities had actually been remediated. According to the committee, neither company provided it. Declaring an intrusion contained and evidencing it are different exercises, and only one of them has happened publicly.
Then came the August 2026 House report, and it moved the story somewhere new. The House Select Committee on China found that China Mobile, China Telecom and China Unicom retained equipment, data centre space and network ties inside the United States after FCC restrictions were supposed to have removed them. American carriers, the report found, had routine network pathways to data centres and equipment that may have connected to those firms.
The committee's specific findings are worth quoting by the numbers. It identified 58 groups of internet addresses that CISA had associated with Salt Typhoon servers, and found China Mobile International's network appearing in routes to those servers at least 192 times — helping keep attacker infrastructure reachable while American defenders were trying to cut it off. Separately, the analysis counted roughly 109,000 incidents between January 2018 and May 2025 in which Chinese or Hong Kong-linked networks claimed US internet addresses without authorisation, a routing behaviour capable of diverting American traffic through foreign systems.
The committee was careful about what it did not claim, and honest coverage should be too. It does not allege that China Mobile USA employees knew about or participated in the campaign, and it states that the routing evidence does not definitively link the company to Salt Typhoon. The argument is narrower: those remaining network ties created conditions under which malicious infrastructure stayed reachable. Chinese officials and state media have rejected the report as politicised and lacking technical evidence. Attribution claims in this space deserve that scrutiny in both directions — we applied the same test to the 'Dance of the Hillary' threat that circulated widely before anyone checked it.
Meanwhile the FBI has said publicly that the threat from Salt Typhoon is still very much ongoing. Whatever was contained, the campaign was not concluded.
What This Means for You — Honestly
Most articles about Salt Typhoon end with generic security advice that has nothing to do with the breach. Change your password does not help when the compromise was in a carrier's core network. So here is the honest version, split into what you cannot control and what you can.
What you cannot control: the security of your carrier's routers, whether an edge appliance was patched, whether lawful-intercept systems were properly segmented, and whether call records describing years of your phone activity were copied. That happened at a layer you have no access to and no visibility into. No consumer action would have prevented it, and none will undo it.
What you can control is the content of your communications, and that is exactly what the federal guidance addressed.
Stop treating SMS as private. Standard text messages are not end-to-end encrypted. Neither are ordinary phone calls. Both traverse carrier infrastructure in a form the carrier — and anyone with sufficient access to that infrastructure — can read. This was always true. Salt Typhoon simply made it concrete.
Use end-to-end encrypted messaging and calling for anything that matters. Signal is the application CISA named, and it covers messages and voice on both mobile platforms and desktop. Encrypted messaging means the carrier moves ciphertext it cannot read — which is why an intrusion at the network layer does not expose the contents.
Move your two-factor codes off SMS. This is the single highest-value change most readers can make, and it is barely mentioned in the coverage. SMS one-time passcodes travel over the same unencrypted channel. Use an authenticator app or, better, a hardware security key or passkey for important accounts. That change protects you against SIM swapping and phishing too, both far more likely to affect you personally than a state intelligence service.
Accept that metadata remains exposed. Encryption protects what you said. It does not hide that you called a number at a particular time from a particular place — the network needs that information to connect the call. If your circumstances make your contact patterns genuinely sensitive, that requires a different threat model than an app recommendation.
If you run a network, the joint advisory's guidance is unglamorous and specific: patch internet-facing edge devices as an urgent class of their own, monitor device configurations for unauthorised changes rather than trusting them, segment management traffic, enforce multi-factor authentication on administrative access, and retain logs long enough to reconstruct an intrusion that may have started years earlier. Salt Typhoon persisted through configuration changes on trusted equipment. If nothing is watching those configurations, nothing will notice. The same discipline applies further down the stack — enforcing transport security with HSTS headers, protecting name resolution with DNSSEC, and closing the application-layer basics covered in our SQL injection reference.
The Part That Should Actually Worry You
Strip out the geopolitics and three structural facts remain, none of which are specific to China.
First, mandated access mechanisms are permanent attack surface. Any system built so an authorised party can listen is a system where authorisation is the only barrier — and authorisation can be stolen, forged or inherited. This is the argument every serious cryptographer has made against exceptional access, and the current debate over scanning encrypted messages is the same proposal wearing newer clothes.
Second, edge devices are the soft underbelly of large networks. Routers, firewalls and VPN appliances are treated as infrastructure rather than as computers that need patching. They are rarely covered by endpoint tooling, often run outdated firmware, and sit exactly where an attacker most wants to be. A 2018 vulnerability being exploitable years later is not an anomaly; it is the norm. The same blind spot is why perimeter controls like a web application firewall get installed once and never reviewed again.
Third, intrusions at this level may simply not be fully reversible. When persistence is a configuration entry on a trusted device and credentials were harvested wholesale, cleaning up means rebuilding trust in equipment you cannot easily verify. That is why the carriers' assurances and the Senate's scepticism can both be sincere. Detecting no current activity is not the same as proving nothing remains.
Salt Typhoon is not interesting because a foreign government spied. Governments spy — and we cover the fallout across our security coverage. It is interesting because it demonstrated that the surveillance architecture built into ordinary communications infrastructure is available to whoever reaches it first — and that two years on, with congressional attention and international advisories and public commitments to remediate, nobody can convincingly say it has been taken back.
Frequently Asked Questions
What is Salt Typhoon?
Salt Typhoon is a cyber espionage group that Western intelligence agencies link to China's Ministry of State Security. It compromised telecommunications providers and other critical infrastructure across more than 80 countries, reaching systems including those tied to lawful-intercept wiretap capability at major US carriers. Some vendors track the same activity as Earth Estries, FamousSparrow or GhostEmperor.
How did Salt Typhoon hack telecom companies?
Primarily by exploiting known, unpatched vulnerabilities in internet-facing edge devices — routers, firewalls and VPN appliances. Named flaws include CVE-2023-20198 and CVE-2018-0171 in Cisco products and CVE-2024-3400 in Palo Alto GlobalProtect. Once inside, the group persisted by modifying device configurations, adding GRE tunnels and privileged accounts, and captured TACACS+ authentication traffic to harvest administrator credentials.
Which companies did Salt Typhoon breach?
Reporting has named major US carriers including AT&T, Verizon, Lumen and T-Mobile among the affected telecommunications providers. The August 2025 joint advisory described roughly 600 organisations notified worldwide, about 200 of them in the United States, spanning telecommunications, government, transportation, lodging and military infrastructure.
Was my personal data stolen in the Salt Typhoon hack?
If you are a customer of an affected carrier, call metadata associated with your number may have been accessed — which numbers were called, when, for how long, and approximate location. Access to actual call or message content was reported for a much smaller, targeted set of individuals. This was an intelligence operation, not financial crime: passwords, banking details and photos were not the objective.
Is Salt Typhoon still active in 2026?
Yes. An FBI official said in 2026 that the threat is still very much ongoing. AT&T and Verizon have stated they evicted the group from their networks, but the Senate Commerce Committee concluded in December 2025 that networks remain vulnerable and that eviction has not been convincingly demonstrated. Senator Cantwell requested remediation documentation from both carriers in February 2026 and, according to the committee, did not receive it.
What did the August 2026 House report find?
The House Select Committee on China reported that China Mobile, China Telecom and China Unicom retained equipment, data centre space and network ties in the US despite FCC restrictions. It identified 58 groups of internet addresses CISA associated with Salt Typhoon servers, with China Mobile International's network appearing in routes to them at least 192 times, and counted around 109,000 incidents of Chinese or Hong Kong-linked networks claiming US internet addresses without authorisation between January 2018 and May 2025. The committee explicitly did not allege that China Mobile USA staff knew of or participated in the campaign.
Why did the FBI tell Americans to use encrypted messaging apps?
Because standard SMS and voice calls are not end-to-end encrypted and pass through carrier infrastructure that had been compromised. In December 2024 the FBI and CISA advised switching to end-to-end encrypted messaging, naming Signal, with the guidance aimed most urgently at senior government and political figures. Encrypted apps mean the carrier carries ciphertext it cannot read, so a network-layer intrusion does not expose message contents.
What is CALEA and why does it matter here?
The Communications Assistance for Law Enforcement Act of 1994 requires US carriers to build networks capable of court-authorised interception. Salt Typhoon reached systems tied to that capability, which is why the incident is cited as evidence in the wider debate about mandated backdoors: a lawful-access mechanism is technically indifferent to who uses it, so the barrier protecting it is authorisation — and authorisation can be stolen.
How can I protect myself after the Salt Typhoon breach?
Use end-to-end encrypted messaging and calling for anything sensitive, stop treating SMS as private, and move two-factor authentication codes off SMS to an authenticator app, hardware key or passkey. You cannot patch your carrier's routers, and metadata — who you called and when — stays visible to the network regardless. Encryption protects content, not the fact that a call occurred.



0 Comments
Community guidelines
We want the comments to be useful for every reader. Every comment is reviewed before it is published. A comment will not be approved if it is:
Keep it genuine and on-topic and it will be approved quickly. Thank you for helping keep the discussion clean.