Inside Salt Typhoon | Secure In Security

Threat Intelligence Analysis

Inside Salt Typhoon

By Kali Agent

How China compromised America’s telecom backbone — and what the breach reveals about deferred patching, weak segmentation, and the risks of lawful-intercept infrastructure.

Document IDSIS-CTI-011
CategoryThreat Intelligence Analysis
Reading Time~8 minutes
TagsAPT · Nation-State · Telecom · Critical Infrastructure · CALEA
Version / Date1.0 — 2026

About This Reference

A practitioner analysis of the Salt Typhoon campaign against U.S. telecommunications carriers: the intrusion path, what was accessed, the systemic failures that enabled it, and the defensive lessons. Descriptive threat intelligence for security professionals and network architects.

This post unpacks what Salt Typhoon did, how they did it, what they accessed, and — critically — what the breach reveals about the systemic cybersecurity failures that made it possible. Because understanding Salt Typhoon is not just a matter of geopolitical interest. For every security professional, network architect, and organizational leader, it is a case study in the consequences of deferred patching, inadequate monitoring, and the invisible attack surfaces hiding inside legacy infrastructure.

Who Is Salt Typhoon?

Salt Typhoon is the designation assigned by Microsoft — and subsequently adopted by the U.S. government — to a Chinese state-sponsored cyber-espionage actor believed to be operated directly by the MSS, China’s principal civilian intelligence and security service. The group is not a newcomer: analysts have traced its operational origins as far back as 2019, with evidence of sustained, methodical targeting of telecommunications companies, hotels, and government agencies across more than 80 countries and 200+ confirmed targets globally.

Unlike destructive threat actors who deploy ransomware for financial gain, Salt Typhoon is a precision intelligence collection operation. Its targeting is deliberately focused on counterintelligence value — understanding who the U.S. government is watching, what communications assets intelligence agencies rely on, and which individuals in the Washington, D.C. ecosystem are of interest. Former NSA analyst Terry Dunlap described the group as a “component of China’s 100-year strategy” — a characterization that underscores the long-term, patient nature of its operations.

KEY CONTEXT

Three Chinese state-sponsored groups dominate U.S. national security concerns: Volt Typhoon (pre-positioning inside critical infrastructure for potential wartime sabotage), Salt Typhoon (telecommunications and counterintelligence espionage), and Flax Typhoon (targeting overseas Chinese diaspora). Together, they represent a coordinated, multi-domain cyber campaign against U.S. interests.

The Attack: How Salt Typhoon Got In

Salt Typhoon’s entry into U.S. telecommunications networks was not the result of a single, novel zero-day exploit. It was the result of chronic, systemic security failures that left America’s most critical communications infrastructure exposed to an adversary that moved slowly, quietly, and with surgical precision.

Exploiting Unpatched Cisco Devices

A pivotal technical entry point was CVE-2023-20198, a critical privilege escalation vulnerability in the web user interface of Cisco IOS XE software — the operating system running on a vast proportion of enterprise and carrier-grade network infrastructure globally. Salt Typhoon (tracked as “RedMike” by Recorded Future’s Insikt Group) paired this with a second flaw, CVE-2023-20273, to achieve root-level access on targeted devices. Between December 2024 and January 2025 alone, researchers observed the group attempting to compromise more than 1,000 Cisco edge devices worldwide. The patches for these vulnerabilities were publicly available. Some affected router configurations had been left unpatched for seven years.

Congressional investigators would later highlight what became the defining indictment of the telecoms’ security posture: investigators found legacy equipment not updated in years, router vulnerabilities with patches available for seven years that were never applied, and hackers acquiring credentials through weak passwords. These were not sophisticated exploitation techniques requiring nation-state resources. They were basic, well-known security failures — the kind that Security+ covers in its first module.

Compromising the CALEA Wiretapping Infrastructure

The most alarming aspect of the Salt Typhoon breach was not the breadth of the initial intrusion — it was what the attackers reached after establishing persistence. The group gained access to systems implementing CALEA: the Communications Assistance for Law Enforcement Act of 1994, the federal statute requiring telecommunications providers to build lawful intercept capabilities into their networks so that law enforcement agencies can execute court-authorized wiretaps.

In other words, Salt Typhoon accessed the backdoor the government mandated telecoms build. The very architecture designed to enable authorized surveillance of foreign intelligence targets and criminal suspects became a surveillance capability for Chinese intelligence. This gave Salt Typhoon the ability not only to intercept communications, but potentially to monitor which individuals and organizations were themselves under U.S. federal investigation — the intelligence equivalent of reading the other side’s playbook.

CRITICAL SECURITY INSIGHT

The CALEA compromise is a foundational argument in the long-running cryptography debate: any mandatory backdoor or lawful intercept system creates an attack surface that adversaries will target. There is no architecture that allows only “authorized” access while remaining immune to exploitation. Salt Typhoon proved this empirically, at national scale.

What Was Accessed and What It Means

The scope of what Salt Typhoon accessed across at least nine confirmed U.S. telecommunications providers — including AT&T, Verizon, T-Mobile, Lumen Technologies, Consolidated Communications, Windstream, and Spectrum — was staggering:

  • Metadata for more than one million users, primarily located in the Washington, D.C. metropolitan area, including call timestamps, source and destination IP addresses, phone numbers, and device identifiers
  • Audio recordings of telephone calls made by high-profile individuals, including staff of the 2024 presidential campaigns of Kamala Harris and Donald Trump, as well as devices belonging to Trump and JD Vance
  • Access to CALEA systems, giving visibility into which individuals were subjects of federal law enforcement or intelligence surveillance — a target list of America’s counterintelligence operations
  • Network infrastructure details including routing configurations, topology maps, and subscriber management systems

Matthew Pines, director of intelligence at SentinelOne, characterized the intelligence value starkly: the breach “gives MSS bread crumbs to trace back to and cauterize strategically critical U.S. sources and methods.” If Chinese intelligence can identify individuals the FBI, CIA, or NSA are monitoring — by reading the surveillance target lists embedded in CALEA infrastructure — those intelligence operations are effectively burned. The human intelligence value alone may exceed that of the 2015 Office of Personnel Management (OPM) breach, which exposed security clearance records for 21.5 million Americans.

Critically, as of late 2025, Senate Commerce Committee hearings confirmed that the intrusion had still not been fully remediated from telecommunications networks. When Senator Cantwell wrote to the CEOs of AT&T and Verizon demanding documentation of remediation, neither company provided it. The FCC’s own ruling acknowledged that vulnerabilities exploited in the breach “are still being exploited.”

The Systemic Security Failures Behind the Breach

Salt Typhoon did not succeed because China fielded an unstoppable technical capability. It succeeded because of a predictable, documented, and preventable set of organizational and technical failures that the cybersecurity community has been warning about for decades.

Legacy Infrastructure and Deferred Patching

Telecommunications carriers operate some of the oldest and most complex network infrastructure in the world. Legacy systems persist because replacements are operationally risky and expensive. But deferred patching is not a risk management decision — it is a risk transfer decision, transferring that risk to every user, institution, and government agency whose communications traverse those networks. Salt Typhoon exploited Cisco IOS XE vulnerabilities for which patches had been available for years. This is not a sophisticated attack. It is opportunistic exploitation of chronic negligence.

Inadequate Segmentation of Sensitive Systems

CALEA systems and lawful intercept infrastructure were often managed separately from customer-facing platforms — a design choice that may have been intended to isolate sensitive surveillance operations. Instead, it created blind spots outside the more mature cybersecurity governance frameworks protecting subscriber data. Salt Typhoon leveraged this isolation against the organizations that implemented it, operating undetected within CALEA infrastructure for extended periods while standard security monitoring focused elsewhere.

Credential Hygiene and Access Control Failures

Multiple entry points were achieved through weak credentials — passwords that failed to meet even basic complexity standards. In 2024, on infrastructure of national security significance, this failure should not exist. Multi-factor authentication, privileged access management (PAM), and credential vaulting are not advanced security capabilities; they are table stakes. Their absence on systems with CALEA access represents a governance failure that goes beyond technical oversight.

LESSON FOR SECURITY TEAMS

Every organization should ask: if a sophisticated nation-state adversary began probing our perimeter today using known, patched CVEs — CVEs that our vendors disclosed with remediation guidance — would they find unpatched devices? The answer for U.S. telecommunications in 2024 was yes. The answer for many enterprises today remains yes.

The Government Response and What It Signals

The U.S. government’s response to Salt Typhoon has been multi-layered, though critics argue it has been too slow and too constrained. In January 2025, the Treasury Department sanctioned Yin Kecheng and Sichuan Juxinhe Network Technology Co. Ltd. for direct involvement in the breaches. CISA, the FBI, and cybersecurity agencies from twelve partner nations jointly released detailed hardening guidance for communications infrastructure. The FCC proposed new mandatory cybersecurity requirements for telecommunications carriers.

In August 2025, a comprehensive joint Cybersecurity Advisory (CSA) — informed by contributions from AWS Security, Cisco Talos, CrowdStrike, Google Mandiant, Microsoft, and PwC Threat Intelligence — publicly detailed Salt Typhoon’s full tactics, techniques, and procedures (TTPs) and formally linked the group to the MSS. This level of public attribution, coordinated across twelve nations and the private sector’s most capable threat intelligence organizations, represents a significant step in building international accountability for state-sponsored cyber operations.

However, two structural tensions persist. First, the CALEA architecture at the center of this breach remains a regulatory requirement. Carriers cannot simply remove it. Any meaningful security improvement requires either a fundamental redesign of how lawful intercept is implemented in modern networks — a years-long undertaking — or accepting that a known-compromised architecture continues to operate. Second, the agencies best positioned to defend against Salt Typhoon — CISA and NSA’s cybersecurity mission — have faced budget pressure and organizational restructuring in 2025, at precisely the moment sustained adversarial operations demand sustained institutional response.

What Security Professionals Must Take Away

Salt Typhoon is not a warning about the future. It is documentation of the present. Its lessons apply directly to every organization that operates network infrastructure, handles sensitive data, or relies on commercial telecommunications:

  • Patch aggressively and on schedule — CVE-2023-20198 was disclosed and patched in 2023. Cisco issued explicit guidance urging immediate remediation. Carriers ignored it. Establish patch SLAs for critical network infrastructure based on CVSS score and attack surface exposure, not operational convenience.
  • Monitor your management plane — Salt Typhoon operated undetected for one to two years in part because lawful intercept systems existed outside standard monitoring frameworks. Every privileged management interface, every administrative access point, must be logged, monitored, and anomaly-detected. If it’s not in your SIEM, an attacker can live there indefinitely.
  • Credential architecture is not optional — Weak passwords on carrier-grade infrastructure with CALEA access represent a national security failure. MFA, PAM with session recording, just-in-time privileged access, and regular credential audits must be non-negotiable for all systems with sensitive access.
  • Rethink architectural trust assumptions — Salt Typhoon exploited the assumption that physically separate or logically isolated systems are inherently more secure. Zero Trust architecture — verify every request, regardless of origin — is the appropriate model for sensitive systems where the consequences of undetected lateral movement are catastrophic.
  • Threat hunting cannot wait for alerts — Nation-state actors are designed to evade signature-based detection. Proactive threat hunting using behavioral indicators, network flow analysis, and endpoint telemetry is the only approach that can surface a patient, low-and-slow adversary like Salt Typhoon within a reasonable detection window.

Conclusion: The Perimeter Was Never Enough

Salt Typhoon has forced a reckoning that the U.S. telecommunications sector — and the broader information security community — has long deferred. The idea that critical infrastructure is inherently defended by its regulatory complexity, its physical separation from the public internet, or its sheer scale has been disproven at every level. A persistent, patient adversary with state resources and a multi-year time horizon will find the unpatched router, the weak credential, the monitoring gap, and the legacy system that nobody owns.

The breach did not require an exotic zero-day. It required time, discipline, and a target environment that had not taken basic hygiene seriously on infrastructure of extraordinary national sensitivity. That is the most unsettling part of the Salt Typhoon story — not the sophistication of the attacker, but the straightforwardness of the entry.

For cybersecurity and information security professionals, the question Salt Typhoon poses is direct: do we know where our CALEA equivalent lives — the system that is architecturally isolated, politically complicated to change, managed by a different team, and therefore assumed to be someone else’s problem? Because that is exactly where a sophisticated adversary will look first.

FINAL THOUGHT

Senator Warner’s assessment — that Salt Typhoon makes Russian cyber operations “look like child’s play by comparison” — should not be read as hyperbole. It should be read as a risk brief. Nation-state cyber espionage has matured to the point where the most dangerous intrusions are the ones that generate no alerts, trigger no playbooks, and live quietly inside infrastructure for years. Defending against that requires a fundamental shift from reactive security to continuous verification, relentless patching, and the organizational culture to sustain both.

Secure In Security | Cybersecurity & Information Security | 2026 | Review Annually