Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
telecommunications-sector-threatstate-sponsored-espionagelateral-movement-methoddata-exfiltration-method

U.S. Telecoms Launch C2 ISAC After Salt Typhoon Breached Carrier Networks

Updated 1mo agoFirst seen May 19, 202626 sources

Major U.S. telecommunications providers have formed the Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC) to strengthen real-time threat sharing and collective defense after the China-linked Salt Typhoon campaign compromised carrier networks in the United States and abroad. The intrusions, described by Sen. Mark Warner as the worst telecom hack in U.S. history, affected multiple major providers including AT&T, Verizon, Lumen Technologies, T-Mobile, and others, with investigators saying the activity has been ongoing since at least 2019 and there is still no clear public evidence the threat actors have been fully removed from communications networks.

Officials and reporting said the espionage campaign enabled attackers to move between telecom networks, exfiltrate large volumes of data, and in some cases listen to audio calls in real time while targeting high-value intelligence, government, and political communications. Investigators also found breaches of U.S. lawful intercept systems used for court-ordered surveillance, while a separate suspected China-linked compromise of an FBI surveillance system likely exposed phone numbers of monitored targets; the campaign has also been linked to exploitation of vulnerabilities in Cisco routers to gain access to telecom infrastructure.

Share:
U.S. Telecoms Launch C2 ISAC After Salt Typhoon Breached Carrier Networks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

21 events from the most recent confirmed update back to the earliest known activity.

21 EVENTS
May 19, 20261mo ago

Telecom firms launch the C2 ISAC information-sharing group

Major U.S. telecommunications companies formed the Communications Cybersecurity Information Sharing and Analysis Center to improve real-time intelligence sharing and collective defense in response to persistent threats exposed by the Salt Typhoon campaign.

May 12, 20262mo ago

Sen. Warner calls Salt Typhoon the worst telecom hack in U.S. history

Sen. Mark R. Warner publicly characterized the China-linked telecom intrusions as the worst telecom hack in the nation's history, highlighting the scale of surveillance and data theft tied to Salt Typhoon.

T-Mobile identified as latest known telecom victim

Recent reporting identified T-Mobile as the latest carrier affected in the Salt Typhoon campaign, following earlier disclosures involving AT&T, Verizon, and Lumen Technologies.

Salt Typhoon compromises telecom providers and lawful intercept systems

Investigators found that Salt Typhoon breached telecom providers in the United States and abroad, including U.S. lawful intercept systems used for court-ordered surveillance. The campaign was described as enabling real-time call monitoring, movement between telecom networks, and large-scale data theft targeting high-value intelligence communications.

Feb 17, 20264mo ago

Suspected China-linked breach of FBI surveillance system is discovered

Earlier in 2026, a suspected China-linked breach of an FBI surveillance system was discovered and likely exposed phone numbers of monitored targets.

Jan 8, 20266mo ago

Salt Typhoon attack on U.S. congressional email system reported

Reporting said the China-linked Salt Typhoon campaign targeted or compromised a U.S. congressional email system, extending concern beyond telecom networks to core government communications infrastructure. The disclosure highlighted congressional communications as an additional victim set in the broader espionage campaign.

Salt Typhoon attack on US congressional email system ‘exposes how vulnerable core communications systems remain to nation-state actors’ | IT Pro
Aug 22, 202510mo ago

FBI announces joint cybersecurity advisory on Salt Typhoon

The FBI announced a joint cybersecurity advisory related to the China-linked Salt Typhoon campaign. The advisory marked a formal government guidance and technical disclosure effort intended to help organizations detect, respond to, and defend against the telecom-focused intrusions.

FBI Announces Joint Cybersecurity Advisory Related to Salt Typhoon - FBI
Jun 23, 20251y ago

Canada says telecom companies were breached in China-linked hacks

Canadian authorities said telecommunications companies in Canada were breached in a China-linked espionage campaign associated with Salt Typhoon. The disclosure expanded the known victim set beyond previously reported U.S. telecom providers.

Canada says telcos were breached in China-linked espionage hacks | TechCrunch
Jan 6, 20251y ago

Report names Charter, Consolidated, and Windstream as Salt Typhoon victims

Public reporting identified Charter Communications, Consolidated Communications, and Windstream as additional telecommunications companies affected by the China-linked Salt Typhoon campaign. The disclosure added specific victim names after earlier government statements had said more U.S. telecom firms were compromised than had been publicly identified.

Three more telcos reportedly join China Salt Typhoon victims
Dec 31, 20241y ago

Lumen says it cleared Salt Typhoon from its network

Lumen disclosed that it had removed the China-linked Salt Typhoon hackers from its network, marking a public remediation update from one of the affected U.S. telecom providers. The statement indicated the company no longer saw the threat actor in its environment.

US telco Lumen says its network is now clear of China's Salt Typhoon hackers | TechCrunch
Dec 30, 20241y ago

Verizon says it secured its network after Salt Typhoon breach

Verizon said it had secured its network following a breach by the China-linked Salt Typhoon group. The statement marked a public remediation update from another major U.S. telecom provider affected by the campaign.

AT&T and Verizon say networks are secure after being breached by China-linked Salt Typhoon hackers | TechCrunch
Dec 27, 20242y ago

White House says Salt Typhoon hit a ninth U.S. telecom firm

The White House disclosed that the China-linked Salt Typhoon hacking campaign had compromised a ninth U.S. telecommunications company. The announcement marked a public escalation in the known scope of the telecom intrusions beyond the previously identified carriers.

Chinese hacking campaign hit a 9th U.S. telecom firm, White House says | PBS News
Dec 16, 20242y ago

U.S. moves to ban China Telecom Americas after telecom hacks

The Biden administration moved to ban the remaining U.S. operations of China Telecom Americas, saying its network presence and cloud services posed a national security risk amid the China-linked telecom espionage campaign. Officials described the step as the first publicly announced U.S. response to the Salt Typhoon intrusions.

Biden Administration Takes First Step to Retaliate Against China Over Hack - The New York Times
Dec 9, 20242y ago

White House says Salt Typhoon recorded calls of senior U.S. officials

The White House disclosed that the China-linked Salt Typhoon campaign intercepted and recorded telephone calls involving very senior U.S. government officials. The statement added a concrete impact detail showing the espionage operation reached high-level official communications.

Salt Typhoon recorded 'very senior' US officials' calls
Dec 4, 20242y ago

U.S. urges use of encrypted messaging apps after Salt Typhoon hack

U.S. officials publicly urged the use of encrypted messaging applications in response to the Salt Typhoon telecom intrusions. The guidance reflected an official response aimed at reducing interception risk after the campaign's impact on communications security became clear.

US urges use of encrypted messaging apps following Salt Typhoon hack - SiliconANGLE
Nov 21, 20242y ago

Sen. Warner calls Salt Typhoon the worst telecom hack in U.S. history

Sen. Mark R. Warner publicly described the China-linked Salt Typhoon intrusion as the worst telecom hack in U.S. history. The statement underscored the severity of the espionage campaign against telecommunications infrastructure.

Top senator calls Salt Typhoon “worst telecom hack in our nation’s history” - The Washington Post
Nov 13, 20242y ago

FBI and CISA warn of broad Chinese telecom espionage campaign

The FBI and CISA said their investigation uncovered a broad and significant China-linked cyberespionage campaign compromising multiple U.S. telecommunications companies. Officials said the hackers obtained customer call records, accessed communications of a limited number of mostly government or political figures, and sought data tied to lawful U.S. surveillance requests.

Investigation into Chinese hacking reveals 'broad and significant' spying effort, FBI says | AP News
Oct 9, 20242y ago

Reports link Salt Typhoon to breaches of telecom lawful-intercept systems

Public reporting said the China-linked Salt Typhoon group had compromised systems at Verizon, AT&T, and Lumen Technologies used to support lawful government access to communications data. The disclosure highlighted that surveillance backdoor infrastructure at major U.S. telecom providers had been exploited.

Salt Typhoon Hack Shows There's No Security Backdoor That's Only For The "Good Guys" | Electronic Frontier Foundation
Oct 5, 20242y ago

CNN reports Chinese hackers accessed U.S. telecom firms

CNN reported that Chinese hackers had gained access to U.S. telecommunications companies, raising concern among U.S. national security officials. The report marked an early public disclosure of the telecom intrusions later linked to Salt Typhoon.

Chinese hackers access US telecom firms, worrying national security officials | CNN Politics
Sep 25, 20242y ago

The Register reports Salt Typhoon inside U.S. ISPs

The Register reported that China-linked Salt Typhoon cyber spies were detected deep inside U.S. internet service providers, marking an early public disclosure of the telecom espionage campaign. The report indicated the intrusions affected core provider environments before broader reporting on the operation emerged.

China's Salt Typhoon cyber spies spotted deep inside US ISPs

Salt Typhoon intrusions into telecom networks begin

The FBI said the China-linked intrusions associated with Salt Typhoon have been active since at least 2019, marking the start of a long-running campaign against telecommunications providers.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Threat actors
1 linked
Organizations
9 linked
Verizon CommunicationsAT&TT-Mobile USComcastCox Communications Inc.Charter CommunicationsLumen TechnologiesInstitute for Critical Infrastructure TechnologyZayo Group
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.