PANOPTICON stateofsurv salt typhoon
page 1 / 2
State of Surveillance — Salt Typhoon: The Worst Telecom Hack in American History
retrieved 2026-07-11
archived for offline mesh reading
------------------------------------------------------------
Skip to main content
Salt Typhoon: Inside America's Worst Telecom Hack
By State of Surveillance Published: 2025-12-18 Last reviewed: 2026-06-06
TL;DR
Chinese state hackers known as Salt Typhoon have breached at least 9 major U.S. telecoms including AT&T, Verizon, and T-Mobile. They exploited the government-mandated wiretap systems (CALEA), accessed metadata from over a million users, and recorded phone calls of Trump and Harris campaign staffers. Senator Mark Warner called it "the worst telecom hack in our nation's history." The FBI is offering $10 million for information. By August 2025, the group had compromised 200+ companies across 80 countries.
What Happened
Starting in 2021, hackers working for China's Ministry of State Security infiltrated American telecommunications infrastructure. By late 2024, U.S. officials confirmed that Salt Typhoon had accessed the computer systems of at least nine major carriers:
- AT&T
- Verizon
- T-Mobile
- Lumen Technologies
- Spectrum (Charter)
- Consolidated Communications
- Windstream
- And at least two others
The hackers didn't just break in. They stayed for years. Cisco reported that in at least one case, Salt Typhoon maintained access for three years before detection.
The Scale of the Breach
9+
U.S. telecom companies compromised
1 Million+
Users whose call/text metadata was accessed
200+
Companies breached globally by August 2025
80
Countries with Salt Typhoon victims
What They Stole
Communications Metadata
Salt Typhoon accessed metadata from over a million users, concentrated in the Washington D.C. metro area. This includes:
- Phone numbers called and received
- Call durations and timestamps
- Text message metadata
- IP addresses
- Location data
Actual Phone Calls
In some cases, the hackers recorded actual audio of phone conversations. Known targets include:
- Staff from the Kamala Harris 2024 presidential campaign
- Phones belonging to Donald Trump
- Phones belonging to JD Vance
The Wiretap List
Most damaging: Salt Typhoon obtained an almost complete list of phone numbers being wiretapped by U.S. law enforcement. This gave China a roadmap of which of their spies the U.S. had identified.
Military and Government Data
From March to December 2024, Salt Typhoon compromised a U.S. state's Army National Guard network for nine months. They stole:
- Administrator credentials
- Network diagrams
- Geographic location maps
- Personal information of service members
- State cyber defense posture information
How They Got In: The CALEA Backdoor
Here's the bitter irony: Salt Typhoon exploited the very systems the U.S. government mandated for surveillance.
The Communications Assistance for Law Enforcement Act (CALEA), passed in 1994, requires all telecom companies to build wiretapping capabilities into their networks. Every phone company must maintain systems that let law enforcement tap calls with a court order.
These CALEA systems became Salt Typhoon's entry point.
As Senator Maria Cantwell stated: "They exploited the wiretapping system that our law enforcement agencies rely on under the Communications Assistance for Law Enforcement Act. These systems became an open door for Chinese intelligence."
The Electronic Frontier Foundation put it bluntly: "There is no backdoor that only lets in good guys and keeps out bad guys."
Critics have warned about this for decades. Every government-mandated backdoor is also a vulnerability. Salt Typhoon proved them right.
Why It Wasn't Stopped
Senior national security officials blamed "rudimentary cybersecurity failures":
- Legacy equipment not updated in years
- Router vulnerabilities with patches available for seven years, never applied
- Some exploited vulnerabilities dated back to 2018
- Basic security measures simply not implemented
The telecoms knew their networks were targets. They just didn't fix them.
The Government Response
Treasury Sanctions
On January 17, 2025, the Treasury Department sanctioned Sichuan Juxinhe Network Technology Co., accusing the Chinese company of direct involvement with Salt Typhoon.
FBI Bounty
In April 2025, the FBI announced a $10 million bounty for information on individuals associated with Salt Typhoon.
Investigation Disrupted
The Cyber Safety Review Board was investigating the breach. In March 2025, the second Trump administration fired all members before they could complete their investigation.
Ongoing Threat
Despite sanctions and public exposure, Salt Typhoon continues operating. Recorded Future documented new breaches of five additional telecom firms between December 2024 and January 2025.
By August 2025, the FBI confirmed Salt Typhoon had hacked at least 200 companies across 80 countries.
Company Responses