PANOPTICON stateofsurv salt typhoon
page 2 / 2
AT&T
In late December 2024, AT&T stated: "We detect no activity by nation-state actors in our networks at this time." Note the careful wording: they didn't say data wasn't stolen, just that hackers weren't currently active.
Verizon
Verizon claimed to have "contained the cyber incident brought on by this nation-state threat actor."
T-Mobile
T-Mobile was more transparent, acknowledging initial infiltration but claiming hackers' access was cut off and no customer data was accessed.
What This Means for You
If you use any major U.S. carrier, assume your metadata has been compromised. This includes:
- Who you call and text
- When you communicate
- How long your conversations last
- Your location when making calls
Even if call contents weren't recorded, metadata reveals patterns. Who you talk to, when, and where tells a story.
Protect Yourself
Use Encrypted Messaging
Apps like Signal encrypt messages end-to-end. Even if someone intercepts the data, they can't read the contents. The FBI specifically recommended encrypted communications after Salt Typhoon.
Encrypt Voice Calls
Use Signal or other encrypted calling apps for sensitive conversations. Regular phone calls travel through telecom infrastructure (the same infrastructure Salt Typhoon compromised).
Assume Networks Are Compromised
Don't trust that any telecom network is secure. The attackers stayed hidden for years. There may be other compromises not yet discovered.
Review Your Metadata Footprint
Consider who you communicate with and when. Metadata patterns can reveal as much as content. Use encrypted apps consistently, not just for sensitive topics.
The Bigger Picture
Salt Typhoon exposes two systemic failures:
- Government-mandated backdoors are inherently insecure. CALEA required telecoms to build surveillance capabilities. Those capabilities became vulnerabilities. Every backdoor is also a front door for adversaries.
- Telecom security is dangerously inadequate. These companies hold our most sensitive communications data. They failed to apply basic patches for years. There are no meaningful consequences for this negligence.
China now has detailed knowledge of U.S. surveillance targets, political communications, and military networks. The damage will take decades to assess.
References
- Salt Typhoon - Wikipedia
- Telecoms haven't notified most victims of Salt Typhoon hack - NBC News
- AT&T, Verizon, Lumen confirm Salt Typhoon breach - The Register
- AT&T and Verizon say networks are secure after Salt Typhoon breach - TechCrunch
- Salt Typhoon Hack Shows There's No Security Backdoor That's Only For The "Good Guys" - EFF
- China's Salt Typhoon hackers continue to breach telecom firms despite US sanctions - TechCrunch
- National Guard hacked by Chinese 'Salt Typhoon' campaign - NBC News
- Experts Agree U.S. Communications Networks Remain Vulnerable - Senate Commerce Committee
Related Articles
- FBI Investigating Hack of Wiretap Systems: Another federal surveillance system breached by hackers
- RSA 2026: The Federal Boycott: The panel on "Hunt for China's Typhoons" was cancelled when CISA, FBI, and NSA pulled out
- Daily Briefing: February 20, 2026: Singapore confirms all four telecoms hit; Senator Cantwell demands AT&T/Verizon answers
- Salt Typhoon Hit All Four Singapore Telecoms: 11-month cleanup operation after zero-day breaches
- Norway Confirms Salt Typhoon Attack: First European government disclosure
- CALEA: The Backdoor Law That Broke American Telecoms: How a 1994 law created the vulnerability Salt Typhoon exploited
- FCC Guts Telecom Security Rules: How the FCC revoked cybersecurity requirements after the hack
- Backdoors and Zero-Days: Why security vulnerabilities are inevitable in compromised systems
- Secure Communications with Signal: Protect your conversations with end-to-end encryption
- PRISM and Mass Collection: Government surveillance programs and how they work