Sen. Maria Cantwell (D-WA), the ranking member of the Senate Commerce Committee, called for congressional hearings and CEO testimony from AT&T and Verizon after alleging the carriers have not cooperated with oversight requests tied to Salt Typhoon, a China-linked hacking group that infiltrated U.S. telecommunications networks. In a public letter to Committee Chair Sen. Ted Cruz (R-TX), Cantwell said she has sought documentation supporting the companies’ claims that their networks are now secure, warning that the lack of cooperation raises questions about whether U.S. customers remain exposed to ongoing risk.
Cantwell specifically said she requested network security assessments produced by Mandiant (Google-owned) and that the firm declined to provide the materials after receiving direction from AT&T and Verizon; she further alleged the carriers acknowledged the existence of assessments detailing vulnerabilities but then blocked both Congress and the assessor from sharing the findings. The reporting also reiterates the broader impact attributed to Salt Typhoon’s telecom intrusions—exposing sensitive communications involving U.S. officials and prompting federal reviews—while noting that some oversight efforts were curtailed, including the termination of the DHS Cyber Safety Review Board investigation; separately, FBI assessments cited in coverage said Salt Typhoon activity affected targets across 80+ countries and led to notifications to hundreds of organizations about potential compromise.

See the actors and campaigns active against you right now.
8 events from the most recent confirmed update back to the earliest known activity.
Cantwell publicly urged congressional hearings requiring the CEOs of AT&T and Verizon to explain how Salt Typhoon breached their networks and what remediation had been completed. She said the companies' repeated lack of cooperation left Americans without clarity on the security of their communications.
Sen. Maria Cantwell said she had sought Mandiant network security assessments for months, but Mandiant declined to provide them after direction from AT&T and Verizon. She argued the lack of cooperation raised questions about whether the carriers' networks were truly secure.
FCC Chair Brendan Carr later pulled back the late-stage telecom cybersecurity rules, arguing that voluntary collaboration with industry was sufficient. Critics said they had seen no evidence that such collaboration was occurring.
Under outgoing Chair Jessica Rosenworcel, the FCC issued emergency rules intended to hold telecoms accountable under federal wiretapping laws and require annual cybersecurity certifications. The rules were described as addressing gaps such as the lack of multifactor authentication.
A Department of Homeland Security Cyber Safety Review Board investigation into the Salt Typhoon breaches was stopped after the Trump administration eliminated the advisory body. The move curtailed a federal oversight effort into the incident.
The FBI assessed that Salt Typhoon targeted more than 80 countries and that roughly 600 organizations were notified of potential compromise. This expanded the understood global scope of the campaign.
The Senate Commerce Committee held a hearing on Salt Typhoon and broader threats to communications networks. The hearing formed part of Congress's early oversight response to the telecom intrusions.
The China-linked group known as Salt Typhoon breached U.S. telecommunications networks, including AT&T and Verizon, in an intrusion described as occurring more than a year before February 2026. Reporting said the operation compromised lawful intercept systems and exposed sensitive communications involving senior U.S. officials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberscoop.com
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.