The FBI and CISA give US telcos best practices to harden their systems against attacks, as senior US officials say Salt Typhoon hackers remain on their networks
- Officials added that they don't yet know the full scope of the intrusions, despite starting the investigation in late spring.
AxiosSam Sabin
Context & Ripple Effects
The guidance arrives after reporting that Salt Typhoon had maintained access to parts of US broadband networks and after an investigation that began with reported anomalies flagged to the government and carriers. The key concern is not just an initial breach, but incomplete visibility into its extent.
Subsequent coverage of additional affected telecom and ISP organizations reinforces that this is a sector-wide defensive problem rather than an isolated carrier incident.
First-order effects
US telecom operators receive a common set of FBI and CISA hardening practices while officials still assess active Salt Typhoon presence on their networks.
Carriers must treat remediation and scoping as ongoing operational work, because investigators have not established the full reach of the intrusions.
Second-order effects
The guidance raises pressure for carriers to align security controls and share findings with federal responders, particularly as prior reporting described continued access to broadband-network systems.
It also strengthens the case for carrier-level accountability measures, alongside the FCC's proposed annual cyber-protection certification framework.
Third-order effects
If repeated intrusions across telecom infrastructure persist, cybersecurity for carriers is likely to be treated less as an internal IT function and more as a shared national-infrastructure defense obligation.
The pattern points toward more formalized baseline controls and oversight, though the effectiveness of that shift will depend on whether operators can detect and remove entrenched access.
The trend: Salt Typhoon is one data point in the shift toward ecosystem-wide cyber defense for communications infrastructure, where persistent compromises require coordinated remediation and stronger operator governance.
The FBI — after contending for years how encryption threatened policing (the “going dark” debate) — is advocating people use encrypted communication apps in light of Salt Typhoon's massive telco hack in which defenders *still* have not kicked them out yet. #infosec www.nbcnews.co…
The FBI has not always been a fan of encrypted apps. — So you know it's serious when “The FBI urges Americans to use encrypted apps amid unprecedented cyberattack” www.nbcnews.com/tech/securit...
The irony, it burns. — Yes, there are tradeoffs to end to end encryption, but it's wild for the FBI to start agreeing with basically the entire security community that it's an often-necessary security message. — www.nbcnews.com/tech/securit...
Oh goodness...schadenfreude? For MEEEE? You shouldn't have. — No, really, you shouldn't have. You should have been listening to us all along when we told you this would happen. A lot. www.nbcnews.com/tech/securit...
amid totally predictable cyber-attack, U.S. government tells Americans to use encrypted messaging apps that U.S. government has been demonizing and trying to outlaw for years www.nbcnews.com/tech/securit...
New: The U.S. government is still trying to kick Salt Typhoon out of telecom networks, officials confirmed today. — No timeline yet for when Salt Typhoon could be completely removed, and officials are still trying to even determine the full scope of the intrusion. — www.axios…
This paragraph about how Salt Typhoon state or state-affiliated attackers from China managed to blow past the defenses of enormous U.S. telcos shouldn't shock you. But (if you're an American) it absolutely should make you really, really angry: https://www.cisa.gov/... [image]
What a mess. “Given where we are in discovering the activity, I think it would be impossible for us to predict a time frame on when we'll have full of eviction” of hackers from the networks, said Jeff Greene, [an official] at CISA. https://www.washingtonpost.com/ ...
CISA & FBI publish guidance for mitigating cyberattacks by Chinese hacker group responsible for telecom company intrusions. It's basic stuff: monitor assets and traffic, manage device configurations, limit access, segment networks, encrypt traffic, etc. https://www.cisa.gov/... […
⚠️ A #PRC-affiliated threat actor compromised networks of major global #telecommunications providers with a broad cyber espionage campaign. Our 🆕 joint guide has guidance to help strengthen visibility & harden network devices against this activity.🔗 https://www.cisa.gov/... [imag…
All @NTCAconnect providers need to stay on high alert for #SaltTyphoon to ensure security for your networks and your consumers. @CISAgov and others have resources if needed or reach out to our team. https://www.washingtonpost.com/ ...