Cybersecurity

Salt Typhoon breach and the new era of telecom security

Salt Typhoon actors compromised over 600 organizations across 80 countries, including nine U.S. carriers, by exploiting unpatched edge routers. This massive breach of CALEA systems highlights why governments are shifting toward direct control of critical communication infrastructure.

Salt Typhoon breach and the new era of telecom security

The scale of the telecom compromise

Salt Typhoon actors compromised over 600 organizations across 80 countries through commercial telecommunications infrastructure. The campaign reached nine U.S. telecommunications carriers, and six of those specific breaches occurred through credential theft at a single managed-services provider that controlled access to the most sensitive routing components of the carrier infrastructure. These attackers accessed lawful-intercept (CALEA) systems at four carriers to view communications of targeted U.S. government and political officials. The campaign targeted call records, metadata, and communications content. This breach exposes the surveillance apparatus of the country. Investigators found that the threat actors remained undetected for years. Does the ability to bypass the CALEA infrastructure fundamentally change the meaning of national security?

Technical exploitation and persistence

The attackers exploited unpatched edge routers to gain initial access. They used vulnerabilities in Cisco IOS-XE and Palo Alto PAN-OS to bypass authentication. Salt Typhoon utilized "living off the land" tactics such as PowerShell and Windows Management Instrumentation to move laterally through networks. The group used leased IP addresses to hide their origin and evade geofencing rules.

Vulnerability Affected Product Impact
CVE-2023-20198 Cisco IOS-XE Authentication bypass
CVE-2023-20273 Cisco IOS-XE Command injection
CVE-2024-3400 Palo Alto PAN-OS Remote code execution

The actors bypassed the need for custom malware by using legitimate administrative tools. They deployed the GhostSpider modular backdoor and the SnappyBee persistence mechanism to maintain access. The group captured TACACS+ credentials to move from one compromised router to every device in the authentication realm. This method allowed them to reach core infrastructure and CALEA-adjacent systems. The attackers focused on mass harvesting of Call Detail Records for social-graph and mobility analysis. They used automated credential replay for lateral movement and moved into Microsoft Teams environments. The group also used small batch transfers over HTTPS to hide exfiltration.

Government responses and regulation

Governments move from passive oversight to direct control of communication infrastructure. The US released a national cybersecurity strategy in March 2026 that directs providers to replace adversary vendors with domestic technologies. The US also banned Chinese and Russian ownership of subsea cables to bolster cybersecurity standards. Australia strengthened its SOCI Act to mandate direct government oversight of telecom assets. Italy advanced a 22 billion euro restructuring of its national network to separate infrastructure ownership from commercial operations. FCC Chair Jessica Rosenworcel proposed rules that require telecom providers to certify cybersecurity risk management plans annually.

The shift from market-based security to state-directed protection follows the finding that commercial incentives fail to secure infrastructure that governments consider necessary for national security. The Salt Typhoon campaign demonstrated that nation-state actors could remain undetected for years while accessing call records and communications content of officials. The campaign acts as a strategic pre-positioning effort rather than traditional espionage. India designated telecom as critical information infrastructure under its IT Act. Singapore extended its Cybersecurity Act to cover telecom operators directly. GCC states implemented national cybersecurity frameworks for strategic sectors. You should evaluate how changes in telecom ownership or regulation affect your connectivity and data transmission.