The Wall Street Journal reported that hackers linked to China, tracked by Microsoft as Salt Typhoon, had breached US broadband providers including Verizon, AT&T, and Lumen, and may have accessed systems used for court-authorised wiretapping.
What happened
- In November 2024 the FBI and CISA said PRC-affiliated actors had stolen customer call records, accessed the private communications of a limited number of people mainly involved in government or political activity, and copied information subject to US law enforcement requests.
- In December 2024 the White House said at least eight US telecoms companies had been affected, along with firms in a few dozen countries, and later that month it said a ninth US company had been identified.
- Phones used by Donald Trump, JD Vance, and people associated with Kamala Harris’s campaign were reported to have been targeted.
- China denied the allegations.
Why it mattered
Senate Intelligence Committee chair Mark Warner called it the worst telecoms hack in US history, and in December 2024 CISA advised senior officials to use end-to-end encrypted messaging.
Lessons for organisations
Harden and patch network edge devices, which are a frequent entry point for state actors, and monitor for unusual administrative access. Sensitive conversations should use end-to-end encrypted tools rather than standard calls and SMS.
Sources: BleepingComputer, The Record
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.