TL;DR
Chinese state hackers known as Salt Typhoon have breached at least 9 major U.S. telecoms including AT&T, Verizon, and T-Mobile. They exploited the government-mandated wiretap systems (CALEA), accessed metadata from over a million users, and recorded phone calls of Trump and Harris campaign staffers. Senator Mark Warner called it "the worst telecom hack in our nation's history." The FBI is offering $10 million for information. By August 2025, the group had compromised 200+ companies across 80 countries.
What Happened
Starting in 2021, hackers working for China's Ministry of State Security infiltrated American telecommunications infrastructure. By late 2024, U.S. officials confirmed that Salt Typhoon had accessed the computer systems of at least nine major carriers:
- AT&T
- Verizon
- T-Mobile
- Lumen Technologies
- Spectrum (Charter)
- Consolidated Communications
- Windstream
- And at least two others
The hackers didn't just break in. They stayed for years. Cisco reported that in at least one case, Salt Typhoon maintained access for three years before detection.
The Scale of the Breach
9+
U.S. telecom companies compromised
1 Million+
Users whose call/text metadata was accessed
200+
Companies breached globally by August 2025
80
Countries with Salt Typhoon victims
What They Stole
Communications Metadata
Salt Typhoon accessed metadata from over a million users, concentrated in the Washington D.C. metro area. This includes:
- Phone numbers called and received
- Call durations and timestamps
- Text message metadata
- IP addresses
- Location data
Actual Phone Calls
In some cases, the hackers recorded actual audio of phone conversations. Known targets include:
- Staff from the Kamala Harris 2024 presidential campaign
- Phones belonging to Donald Trump
- Phones belonging to JD Vance
The Wiretap List
Most damaging: Salt Typhoon obtained an almost complete list of phone numbers being wiretapped by U.S. law enforcement. This gave China a roadmap of which of their spies the U.S. had identified.
Military and Government Data
From March to December 2024, Salt Typhoon compromised a U.S. state's Army National Guard network for nine months. They stole:
- Administrator credentials
- Network diagrams
- Geographic location maps
- Personal information of service members
- State cyber defense posture information
How They Got In: The CALEA Backdoor
Here's the bitter irony: Salt Typhoon exploited the very systems the U.S. government mandated for surveillance.
The Communications Assistance for Law Enforcement Act (CALEA), passed in 1994, requires all telecom companies to build wiretapping capabilities into their networks. Every phone company must maintain systems that let law enforcement tap calls with a court order.
These CALEA systems became Salt Typhoon's entry point.
As Senator Maria Cantwell stated: "They exploited the wiretapping system that our law enforcement agencies rely on under the Communications Assistance for Law Enforcement Act. These systems became an open door for Chinese intelligence."
The Electronic Frontier Foundation put it bluntly: "There is no backdoor that only lets in good guys and keeps out bad guys."
Critics have warned about this for decades. Every government-mandated backdoor is also a vulnerability. Salt Typhoon proved them right.
Why It Wasn't Stopped
Senior national security officials blamed "rudimentary cybersecurity failures":
- Legacy equipment not updated in years
- Router vulnerabilities with patches available for seven years, never applied
- Some exploited vulnerabilities dated back to 2018
- Basic security measures simply not implemented
The telecoms knew their networks were targets. They just didn't fix them.
The Government Response
Treasury Sanctions
On January 17, 2025, the Treasury Department sanctioned Sichuan Juxinhe Network Technology Co., accusing the Chinese company of direct involvement with Salt Typhoon.
FBI Bounty
In April 2025, the FBI announced a $10 million bounty for information on individuals associated with Salt Typhoon.
Investigation Disrupted
The Cyber Safety Review Board was investigating the breach. In March 2025, the second Trump administration fired all members before they could complete their investigation.
Ongoing Threat
Despite sanctions and public exposure, Salt Typhoon continues operating. Recorded Future documented new breaches of five additional telecom firms between December 2024 and January 2025.
By August 2025, the FBI confirmed Salt Typhoon had hacked at least 200 companies across 80 countries.
Company Responses
AT&T
In late December 2024, AT&T stated: "We detect no activity by nation-state actors in our networks at this time." Note the careful wording: they didn't say data wasn't stolen, just that hackers weren't currently active.
Verizon
Verizon claimed to have "contained the cyber incident brought on by this nation-state threat actor."
T-Mobile
T-Mobile was more transparent, acknowledging initial infiltration but claiming hackers' access was cut off and no customer data was accessed.
What This Means for You
If you use any major U.S. carrier, assume your metadata has been compromised. This includes:
- Who you call and text
- When you communicate
- How long your conversations last
- Your location when making calls
Even if call contents weren't recorded, metadata reveals patterns. Who you talk to, when, and where tells a story.
Protect Yourself
Use Encrypted Messaging
Apps like Signal encrypt messages end-to-end. Even if someone intercepts the data, they can't read the contents. The FBI specifically recommended encrypted communications after Salt Typhoon.
Encrypt Voice Calls
Use Signal or other encrypted calling apps for sensitive conversations. Regular phone calls travel through telecom infrastructure (the same infrastructure Salt Typhoon compromised).
Assume Networks Are Compromised
Don't trust that any telecom network is secure. The attackers stayed hidden for years. There may be other compromises not yet discovered.
Review Your Metadata Footprint
Consider who you communicate with and when. Metadata patterns can reveal as much as content. Use encrypted apps consistently, not just for sensitive topics.
The Bigger Picture
Salt Typhoon exposes two systemic failures:
- Government-mandated backdoors are inherently insecure. CALEA required telecoms to build surveillance capabilities. Those capabilities became vulnerabilities. Every backdoor is also a front door for adversaries.
- Telecom security is dangerously inadequate. These companies hold our most sensitive communications data. They failed to apply basic patches for years. There are no meaningful consequences for this negligence.
China now has detailed knowledge of U.S. surveillance targets, political communications, and military networks. The damage will take decades to assess.
References
- Salt Typhoon - Wikipedia
- Telecoms haven't notified most victims of Salt Typhoon hack - NBC News
- AT&T, Verizon, Lumen confirm Salt Typhoon breach - The Register
- AT&T and Verizon say networks are secure after Salt Typhoon breach - TechCrunch
- Salt Typhoon Hack Shows There's No Security Backdoor That's Only For The "Good Guys" - EFF
- China's Salt Typhoon hackers continue to breach telecom firms despite US sanctions - TechCrunch
- National Guard hacked by Chinese 'Salt Typhoon' campaign - NBC News
- Experts Agree U.S. Communications Networks Remain Vulnerable - Senate Commerce Committee
Related Articles
- FBI Investigating Hack of Wiretap Systems: Another federal surveillance system breached by hackers
- RSA 2026: The Federal Boycott: The panel on "Hunt for China's Typhoons" was cancelled when CISA, FBI, and NSA pulled out
- Daily Briefing: February 20, 2026: Singapore confirms all four telecoms hit; Senator Cantwell demands AT&T/Verizon answers
- Salt Typhoon Hit All Four Singapore Telecoms: 11-month cleanup operation after zero-day breaches
- Norway Confirms Salt Typhoon Attack: First European government disclosure
- CALEA: The Backdoor Law That Broke American Telecoms: How a 1994 law created the vulnerability Salt Typhoon exploited
- FCC Guts Telecom Security Rules: How the FCC revoked cybersecurity requirements after the hack
- Backdoors and Zero-Days: Why security vulnerabilities are inevitable in compromised systems
- Secure Communications with Signal: Protect your conversations with end-to-end encryption
- PRISM and Mass Collection: Government surveillance programs and how they work