Salt Typhoon Persists: CISA Taps Voluntary Commitments as China-Linked Espionage Hits 200 US Carriers
By Tech Desk
Three years after the FBI first confirmed that a China-linked campaign had burrowed deep into the routing backbone of the largest US telecom carriers, the remediation effort remains incomplete. An updated analysis of the 32 largest telecom breaches in history now ranks Salt Typhoon not by records stolen — the figure is deliberately obscure — but by strategic damage. According to the FBI in August 2025, the campaign had hit at least 200 US companies. Yet as of September 2026, no carrier has been fined.
What Salt Typhoon Actually Took
Unlike a typical breach, where stolen records appear on dark-web marketplaces for credit-card fraud and identity theft, Salt Typhoon accessed something far more sensitive: the lawful-intercept infrastructure itself. That gave a foreign service the ability to see which people the US government was surveilling, turning carrier telecom gear into a listening post rather than a breach to be patched.

The attack vector was conventional but effective: exploitation of unpatched internet-facing edge devices — primarily Cisco routers — followed by credential theft, Generic Routing Encapsulation tunneling, and persistence techniques that reused a network's own legitimate tools to stay hidden in core routing infrastructure. Data types exposed included call detail records and subscriber metadata, SMS content, voicemail, router configurations, and access to Communications Assistance for Law Enforcement Act systems that identify who is under US surveillance.
A joint advisory issued in August 2025 by CISA, the NSA, and Five Eyes partners confirmed that the intrusions spanned at least 200 companies. In December 2024, officials said fewer than 150 people had been directly notified that their communications were intercepted. The US Treasury sanctioned a China-based firm in January 2025 described as tied to the Ministry of State Security and to Salt Typhoon.
The CALEA Rollback and Regulatory Response
The US government's regulatory response has been uneven. In January 2025, the FCC treated CALEA as a mandatory cybersecurity duty and issued a declaratory ruling requiring carriers to secure their lawful-intercept systems. Then in November 2025, the FCC rescinded the ruling, moving carriers from enforceable obligations to voluntary commitments instead.
This regulatory shift matters because it reflects a deeper tension: the US approach to telecom security has not caught up to the threat. According to UpGuard's updated analysis of 32 major telecom breaches, most carrier intrusions still stem from unpatched internet-facing devices, reused credentials, or third-party vendors with poor security postures. The firm noted that a single intrusion can either expose tens of millions of subscriber records or serve a much quieter, more dangerous purpose — foreign espionage services hiding within a carrier's routing and lawful-intercept systems to monitor high-value targets.
In contrast, the European Union's Network and Information Security Directive Version Two mandates a phased reporting approach for essential telecoms: an initial early warning within 24 hours, followed by a comprehensive incident notification within 72 hours, with fines of up to 2% of annual turnover or €10 million. The UK's Telecommunications Security Act gives Ofcom authority to fine up to 10% of turnover. Australia's information commission moved against Optus after its 2022 unauthenticated API exposure, raising penalties to the greater of AU$50 million or 30% of benefit obtained from any breach-related gain.
Why Patching Alone Cannot Fix This
The Salt Typhoon campaign exploited the same edge-device vulnerability class that drove the 2023 Comcast Xfinity breach and the Citrix Bleed session-token disclosure flaw. In that pattern, patching alone is insufficient: stolen session tokens or valid credentials continue to grant access even after a fix is applied. Attackers harvested credentials through infostealer malware running on employee endpoints and then reused them against internal tools that lacked multi-factor authentication.

The gap between a patch and effective remediation is where telecom resilience breaks down. A single compromised VPN concentrator or SD-WAN gateway can grant access to an entire carrier-grade network. Persistent access does not disappear when firmware is updated — it persists through cached session tokens, certificate-based authentication paths, and management APIs that bypass standard credential rotation.
CISA's joint advisory with NSA and Five Eyes partners emphasized continuous monitoring of edge-device firmware, mandatory session-token rotation after any compromise indicator, and segmentation of lawful-intercept APIs behind dedicated authentication paths that do not share infrastructure with customer-facing portals.
What Carriers Should Do Now
Teams managing telecom infrastructure face the same patch gap that allowed Salt Typhoon to persist. The underlying exposure — unvalidated edge devices and shared credential paths between management and customer portals — has not been universally resolved. UpGuard's September 2026 analysis warns that the FCC's commitment to voluntary compliance has not stopped the attack surface from expanding.
Continuous monitoring solutions can map the internet-facing footprint — routers, VPN concentrators, remote-access gateways, APIs — and rank findings by the probability of real-world exploitation rather than by raw CVE severity. That ensures an actively exploited flaw surfaces ahead of a theoretical one sitting in a patch queue.
Carriers should audit all internet-facing edge devices for unpatched firmware versions, force session-token rotation and invalidate all cached credentials for carrier-grade network management interfaces, segment lawful-intercept APIs behind dedicated authentication paths that do not share credentials with customer portals, deploy continuous dark-web monitoring for leaked session tokens tied to carrier employee accounts, and reassess quarterly regardless of patch status, since the threat actor reused legitimate tooling rather than novel exploits.
The Strategic Damage
No carrier has been fined specifically over Salt Typhoon. The campaign's strategic damage — the ability to monitor lawful-intercept targets — exceeds what any record-count breach notification would capture. This is why CISA's August 2025 advisory paired its technical guidance with a directive to treat telecom resilience as a national security function, not a compliance checkbox.
The remediation effort is ongoing, and with the FBI reporting intrusions into at least 200 companies during the campaign's extended window, the carrier security model is still adapting to an adversary that operated inside the trusted core long before any public alert surfaced.
For more on enterprise cloud and edge security defenses, see our prior reporting on infrastructure hardening strategies.
References
- UpGuard: Biggest Data Breaches in Telecommunications (Updated September 2026)
- CISA joint advisory on telecom infrastructure hardening (August 2025)
- Qualys analysis of ShieldBreak zero-day
- FCC CALEA declaratory ruling (January 2025) and November 2025 rescission
- EU Network and Information Security Directive Version Two reporting requirements