Recorded Future: Salt Typhoon breached five more telcos and ISPs, including two US telcos, and 12+ universities in December-January by exploiting Cisco routers
Despite high-profile attention and even US sanctions, the group hasn't stopped or even slowed its operation, including the breach of two more US telecoms.
Context & Ripple Effects
Salt Typhoon’s telecom campaign had already expanded from initial ISP intrusions to persistent access in US broadband networks and potential access to wiretap systems. By late December, US officials had identified a ninth affected telecom; this report adds evidence that the activity continued into December and January, rather than being contained.
The new incidents also sharpen the operational link between the campaign and network infrastructure: Cisco routers were the reported entry point across telecom, ISP, and university targets. That follows earlier federal hardening guidance for US telcos issued while officials said the group remained on their networks.
First-order effects
- The five additional telecom and ISP victims, including two US telcos, and more than 12 universities must assess Cisco-router exposure, investigate access, and contain any remaining intrusion paths.
- Cisco customers in these sectors face immediate pressure to prioritize the router weaknesses reportedly used in the campaign, alongside existing incident-response work.
Second-order effects
- Telecom operators’ remediation burden broadens from a limited set of named carriers to a cross-sector network-infrastructure problem, making shared defensive guidance more consequential after the ninth telecom was identified in December.
- Cisco’s enterprise and service-provider customers are likely to demand clearer mitigation and detection support for affected router environments, while universities confront similar operational security demands without being telecom operators.
Third-order effects
- If repeated exploitation of common network equipment persists, communications resilience will depend less on isolating individual victims and more on coordinated vulnerability management across carriers, ISPs, vendors, and public institutions.
- The campaign reinforces a shift toward treating backbone and access-network infrastructure as a strategic espionage surface; the reported continuation despite attention and sanctions suggests deterrence alone may not quickly reduce that exposure.
The trend: Salt Typhoon is one data point in the growing strategic targeting of widely deployed network infrastructure, where a shared device layer can connect telecom and non-telecom victims.