Sources: China-linked “Salt Typhoon” hacking campaign potentially accessed US wiretap systems after breaching networks of US ISPs like Verizon, AT&T, and Lumen
AT&T, Verizon are among broadband providers breached in China-linked ‘Salt Typhoon’ hack
Wall Street Journal
Context & Ripple Effects
The report follows a September account that described Salt Typhoon intrusions at a handful of US internet providers in pursuit of sensitive information, moving the story from a network-breach allegation to potential exposure of especially sensitive telecom functions. Earlier reports of the ISP intrusions had already made the providers’ infrastructure the central security concern.
Subsequent coverage that attackers retained access to parts of broadband networks underscores that containment—not merely attribution—was the immediate challenge. Reports of lingering access raise the stakes for providers and investigators trying to establish the campaign’s reach.
First-order effects
AT&T, Verizon, and Lumen face an urgent need to investigate affected network segments and determine whether systems supporting lawful wiretaps were reachable or accessed.
US investigators must treat the incident as a potential compromise of a sensitive interception capability, broadening the incident-response scope beyond ordinary customer-network security.
Second-order effects
Other telecom operators are likely to review comparable administrative and interception-related environments, since the campaign was reported across multiple providers rather than as an isolated breach.
The prospect of access to wiretap systems increases pressure on carriers to separate and monitor high-sensitivity functions more rigorously, potentially redirecting security spending toward telecom-specific controls.
Third-order effects
If repeated intrusions into telecom infrastructure continue, communications networks will be treated increasingly as strategic espionage targets rather than solely commercial IT environments, raising the baseline for sector-wide resilience and oversight.
The pattern could push security policy toward more formal coordination between carriers and government over systems that combine commercial operations with sensitive public-safety functions, though the corpus does not establish what response will follow.
The trend: Salt Typhoon is part of a broader shift toward espionage campaigns targeting telecom infrastructure for access to high-value communications and network-control systems.
China successfully compromised for months the infrastructure used to do wiretaps on the AT&T and Verizon networks. — This is a huge “told you so” moment for the cryptographic community that has been saying that such infrastructure does present a huge risk to national security. …
For 30 years cryptographers have been telling everyone that this is what would happen if US law enforcement and signals intelligence purposefully created backdoors https://www.wsj.com/...
Verizon, AT&T and Lumen Technologies are among those whose networks were breached, the people said. The widespread compromise is considered a potentially catastrophic security breach and was carried out by a Chinese hacking group dubbed Salt Typhoon. https://www.wsj.com/...
You can stack cyber risk management frameworks to the sky if you'd like. But at the end of the day if your adversary has studied your system to the point they know it better than you do, you're going to lose. https://www.wsj.com/...
NEW: A cyberattack tied to the Chinese government penetrated the networks of major U.S. broadband providers and potentially accessed information from systems used for court-authorized wiretapping requests - w/ @dnvolz @aviswanatha @bobmcmillan https://www.wsj.com/...
Damn, apparently China just picked off every federal wiretap request through all the big broadband companies.. Exclusive | U.S. Wiretap Systems Targeted in China-Linked Hack - WSJ https://www.wsj.com/...
Another reminder that lawful access systems (ie, backdoors) can become major sources of personal & national insecurity China🇨🇳operators penetrated networks of Verizon, AT&T & Lumen Tech @bysarahkrouse @dnvolz @aviswanatha @bobmcmillan https://www.wsj.com/... via @WSJ
For months or longer, the hackers may have held access to network infrastructure used to cooperate with lawful U.S. requests for communications data, say people familiar with the matter. They also had access to other more generic internet traffic. https://www.wsj.com/...