Salt Typhoon executed what U.S. officials have described as the most significant telecommunications breach in the nation's history.
Between 2022 and 2024 the group established deep access inside at least nine U.S. telecommunications providers — reporting has named AT&T, Verizon, Lumen, T-Mobile, and Charter among them — plus dozens of operators worldwide. Rather than breaching handsets or applications, it compromised the carriers themselves: core routers, provisioning systems, and call detail record infrastructure.
The most consequential access was to lawful intercept systems — the CALEA-mandated infrastructure U.S. carriers maintain to service court-ordered wiretaps. Compromising it gave the actor visibility into which individuals U.S. law enforcement and counterintelligence were actively monitoring, a counterintelligence coup independent of any content collected. The group also accessed communications of individuals involved in the 2024 U.S. presidential campaigns and obtained call metadata for large numbers of subscribers, concentrated in the Washington, D.C. area.
Tradecraft centres on network infrastructure rather than endpoints. The group lives on routers and switches, where EDR does not run, telemetry is sparse, and defenders rarely look. It uses stolen credentials, modifies device configurations to create durable access, and in several cases exploited network devices that had been unpatched for years — CVE-2018-0171, a Cisco Smart Install flaw patched in 2018, was still an effective entry point in 2024.
In August 2025 a joint advisory from thirteen countries named three Chinese companies — Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology, and Sichuan Zhixin Ruijie Network Technology — as providers of cyber products and services to Chinese intelligence services in support of this activity.