/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Recorded Future: Salt Typhoon breached five more telcos and ISPs, including two US telcos, and 12+ universities in December-January by exploiting Cisco routers

Despite high-profile attention and even US sanctions, the group hasn't stopped or even slowed its operation, including the breach of two more US telecoms.

Wired Andy Greenberg

Context & Ripple Effects

Salt Typhoon’s telecom campaign had already expanded from initial ISP intrusions to persistent access in US broadband networks and potential access to wiretap systems. By late December, US officials had identified a ninth affected telecom; this report adds evidence that the activity continued into December and January, rather than being contained.

The new incidents also sharpen the operational link between the campaign and network infrastructure: Cisco routers were the reported entry point across telecom, ISP, and university targets. That follows earlier federal hardening guidance for US telcos issued while officials said the group remained on their networks.

First-order effects

  • The five additional telecom and ISP victims, including two US telcos, and more than 12 universities must assess Cisco-router exposure, investigate access, and contain any remaining intrusion paths.
  • Cisco customers in these sectors face immediate pressure to prioritize the router weaknesses reportedly used in the campaign, alongside existing incident-response work.

Second-order effects

  • Telecom operators’ remediation burden broadens from a limited set of named carriers to a cross-sector network-infrastructure problem, making shared defensive guidance more consequential after the ninth telecom was identified in December.
  • Cisco’s enterprise and service-provider customers are likely to demand clearer mitigation and detection support for affected router environments, while universities confront similar operational security demands without being telecom operators.

Third-order effects

  • If repeated exploitation of common network equipment persists, communications resilience will depend less on isolating individual victims and more on coordinated vulnerability management across carriers, ISPs, vendors, and public institutions.
  • The campaign reinforces a shift toward treating backbone and access-network infrastructure as a strategic espionage surface; the reported continuation despite attention and sanctions suggests deterrence alone may not quickly reduce that exposure.

The trend: Salt Typhoon is one data point in the growing strategic targeting of widely deployed network infrastructure, where a shared device layer can connect telecom and non-telecom victims.

Discussion

  • @mmasnick Mike Masnick on bluesky
    Good thing Trump/Musk fired the folks supposed to be doing the investigation into what happened.  [embedded post]
  • @agreenberg Andy Greenberg on bluesky
    China's Salt Typhoon hackers are still breaching telecom networks worldwide, including two in the US in Dec-Jan, says Recorded Future.  Lately they're exploiting Cisco devices with unpatched 2023 bugs and seem undeterred by high profile exposure and sanctions. www.wired.com/story…
  • r/cybersecurity r on reddit
    China's Salt Typhoon Spies Are Still Hacking Telecoms—Now by Exploiting Cisco Routers
  • r/craftofintelligence r on reddit
    China's Salt Typhoon Spies Are Still Hacking US Telecoms—Now by Exploiting Cisco Routers
  • r/espionage r on reddit
    China's Salt Typhoon Spies Are Still Hacking Telecoms—Now by Exploiting Cisco Routers