AT&T and Verizon say their networks are now clear after the Salt Typhoon intrusion; AT&T says a few “individuals of foreign intelligence interest” were targeted
- Carriers said hackers targeted political, intelligence figures — White House said nine telecom companies were victims
AT&T and Verizon’s clearance statements matter because the intrusion was tied to political and intelligence-related targets, even though the government said the number of directly affected people was under 100.
First-order effects
AT&T and Verizon can shift from active containment to validating that their networks remain free of the intrusion and addressing any affected accounts or communications paths.
The acknowledgement that foreign-intelligence-interest individuals were targeted focuses the immediate consequences on a limited, sensitive set of users rather than a broad consumer outage.
The episode keeps scrutiny on telecom systems that support lawful-access and other sensitive communications functions, raising the stakes of carrier security reviews.
Third-order effects
If this pattern persists, major telecom networks will be treated less as standalone commercial infrastructure and more as a shared national-security attack surface, with security assurance becoming a core carrier obligation.
The multi-carrier footprint suggests resilience will increasingly depend on coordinated detection and remediation across providers, not solely on each operator declaring its own network clean.
The trend: Salt Typhoon is part of a broader shift in which telecommunications infrastructure is becoming a high-value target for intelligence collection and a focal point for coordinated cyber defense.
Salt Typhoon is a major NatSec breach. In my view, the people attempting to convince us the PRC isn't an enemy come in two flavors; they're either ignorant or actively working against the interests of the United States. 🧵 Deputy NSA for Cyber Anne Neuberger: [image]
The implications of the extent of geolocating that appears to have been done via the PRC Salt Typhoon operation are almost more concerning than the traditional data acquisition and surveillance aspects. Forever caveat: I'm working from publicly available unclassified data.
FISA = Foreign Intelligence Surveillance Act “Selectors” = an identifier such as a phone number associated with an intelligence target In other words, Chinese intelligence might know what American intelligence agencies & law enforcement were searching for on phone networks.
I think the Salt Typhoon hacks will be seen as the worst counterintelligence breach in US history. Though not reported yet, seems likely that the MSS compromised the FISA “selectors” in US telcos. The fallout from this is unfathomable. FBI NSD damage assessment is max pain rn.
This sounds like not only like an audacious intelligence coup for China, but also surprisingly discriminate & narrow collection ("probably less than 100" individuals targeted for follow-on collection)
AT&T acknowledged that it had been hit by the China-linked Salt Typhoon hacking operation but that its networks were now clear from the intrusion https://www.bloomberg.com/...
You know, it probably isn't great the only politicians to note we've been in a cold war with China for the last however many years have had their brains melted by a combination of racism and being old enough to remember the Big Bopper. — apnews.com/article/unit...
I just assumed that everybody was assuming that all telcos of any appreciable size in the US, and many international telcos, have been impacted by Salt Typhoon. [embedded post]
NEW: White House said Salt Typhoon occurred in large part due to telecoms failure to implement basic cybersecurity measures; company victim lists has grown to 9 cyberscoop.com/salt-typhoon... Tip @techmeme.com
Crazy to me that the worst cyber attack in American history has gone pretty much entirely under the radar. The Chinese are probably reading your texts *and listening to your calls* https://www.politico.com/... [image]
Months after revelation of Salt Typhoon, one of the biggest hacks of US critical infrastructure this decade, we get: - @FCC regulations that will take months to years to implement - @USGSA review of federal contracts - @CommerceGov might block China Telecom but TBD Too little,
White House gave a small update on Salt Typhoon: A ninth telco has been added to the victim list (previously there had been 8 known victim companies) WH has sent out a threat-hunting and hardening guide to telcos to try and remove threat actors (how ninth victim surfaced)