Micron Document

PANOPTICON salt typhoon
page 1 / 2

Salt Typhoon
retrieved 2026-07-11

archived for offline mesh reading
------------------------------------------------------------

Salt Typhoon is an advanced persistent threat actor believed to be operated by China's Ministry of State Security (MSS) which has conducted high-profile cyber espionage campaigns, particularly against the United States. The group's operations place an emphasis on counterintelligence targets in the United States and data theft of key corporate intellectual property. The group has infiltrated over 200 targets in over 80 countries. Former NSA analyst Terry Dunlap has described the group as a "component of China's 100 year strategy."


== Organization and attribution ==
Salt Typhoon is widely understood to be operated by China's Ministry of State Security (MSS), its foreign intelligence service and secret police. The Chinese embassy in New Zealand denied all allegations, saying it was "unfounded and irresponsible smears and slanders".
According to Trend Micro, the group is a "well-organized group with a clear division of labor" whereby attacks targeting different regions and industries are launched by distinct actors, suggesting the group consists of various teams, "further highlighting the complexity of the group's operations." The cyberattacks were reported to have commenced since at least 2023.


== History ==


=== 2023 to 2024: Telecommunication Hacks ===

In September 2024, reports first emerged that a severe cyberattack had compromised U.S. telecommunications systems. US officials stated that the campaign was likely underway for one to two years prior to its discovery, with several dozen countries compromised in the hack, including those in Europe and the Indo-Pacific. The campaign was reportedly "intended as a Chinese espionage program focused on key government officials [and] key corporate [intellectual property]."
In late 2024 U.S. officials announced that hackers affiliated with Salt Typhoon had accessed the computer systems of nine U.S. telecommunications companies, later acknowledged to include Verizon, AT&T, T-Mobile, Spectrum, Lumen, Consolidated Communications, and Windstream. The attack targeted U.S. broadband networks, particularly core network components, including routers manufactured by Cisco, which route large portions of the Internet. In October 2024, U.S. officials revealed that the group had compromised internet service provider (ISP) systems used to fulfill CALEA requests used by U.S. law enforcement and intelligence agencies to conduct court-authorized wiretapping.
The hackers were able to access metadata of users' calls and text messages, including date and time stamps, source and destination IP addresses, and phone numbers from over a million users; most of which were located in the Washington D.C. metro area. In some cases, the hackers were able to obtain audio recordings of telephone calls made by high-profile individuals. Such individuals reportedly included staff of the Kamala Harris 2024 presidential campaign, as well as phones belonging to Donald Trump and JD Vance. According to deputy national security advisor Anne Neuberger, a "large number" of the individuals whose data was directly accessed were "government targets of interest."
In March 2025, the United States House Committee on Homeland Security requested that the Department of Homeland Security (DHS) turn over documents on the federal government's response to the hacking.
The second Trump administration fired all members of the Cyber Safety Review Board before it could complete its investigation of the intrusion. In April 2025, the Federal Bureau of Investigation (FBI) announced a US$10 million bounty for information on individuals associated with Salt Typhoon.
In December 2024, Verizon and AT&T announced that they had contained the incident and that the threat actor no longer had access to their networks. On June 12, 2025, Senator Maria Cantwell, the Ranking Member of the Senate Committee on Commerce, Science and Transportation, wrote letters to the CEOs of AT&T and Verizon requesting they provide detailed information regarding the cybersecurity investigations conducted at both companies. Senator Cantwell asked for a list of all vulnerabilities identified that allowed the attackers in, as well as remediation plans and documentation supporting the claim that Salt Typhoon was no longer present in their networks.
8 months later, in February 2026 Senator Cantwell sent a letter to Committee Chairman Ted Cruz requesting he convene a hearing in which the CEOs of AT&T and Verizon would be asked about the current security of their networks. The letter claims that both companies hired Mandiant to conduct security assessments but that Mandiant failed to provide reports generated by these assessments after the reports were requested.


=== 2024 to 2025: National Guard and Congressional committees ===
On June 11, 2025, the DHS published a report entitled Salt Typhoon: Data Theft Likely Signals Expanded Targeting. In the report, the agency describes how the threat actor group compromised the network of an unnamed US state's Army National Guard.


< prev page 1/2 next >