Major U.S. telecommunications providers have formed the Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC) to strengthen real-time threat sharing and collective defense after the China-linked Salt Typhoon campaign compromised carrier networks in the United States and abroad. The intrusions, described by Sen. Mark Warner as the worst telecom hack in U.S. history, affected multiple major providers including AT&T, Verizon, Lumen Technologies, T-Mobile, and others, with investigators saying the activity has been ongoing since at least 2019 and there is still no clear public evidence the threat actors have been fully removed from communications networks.
Officials and reporting said the espionage campaign enabled attackers to move between telecom networks, exfiltrate large volumes of data, and in some cases listen to audio calls in real time while targeting high-value intelligence, government, and political communications. Investigators also found breaches of U.S. lawful intercept systems used for court-ordered surveillance, while a separate suspected China-linked compromise of an FBI surveillance system likely exposed phone numbers of monitored targets; the campaign has also been linked to exploitation of vulnerabilities in Cisco routers to gain access to telecom infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
21 events from the most recent confirmed update back to the earliest known activity.
Major U.S. telecommunications companies formed the Communications Cybersecurity Information Sharing and Analysis Center to improve real-time intelligence sharing and collective defense in response to persistent threats exposed by the Salt Typhoon campaign.
Sen. Mark R. Warner publicly characterized the China-linked telecom intrusions as the worst telecom hack in the nation's history, highlighting the scale of surveillance and data theft tied to Salt Typhoon.
Recent reporting identified T-Mobile as the latest carrier affected in the Salt Typhoon campaign, following earlier disclosures involving AT&T, Verizon, and Lumen Technologies.
Investigators found that Salt Typhoon breached telecom providers in the United States and abroad, including U.S. lawful intercept systems used for court-ordered surveillance. The campaign was described as enabling real-time call monitoring, movement between telecom networks, and large-scale data theft targeting high-value intelligence communications.
Earlier in 2026, a suspected China-linked breach of an FBI surveillance system was discovered and likely exposed phone numbers of monitored targets.
Reporting said the China-linked Salt Typhoon campaign targeted or compromised a U.S. congressional email system, extending concern beyond telecom networks to core government communications infrastructure. The disclosure highlighted congressional communications as an additional victim set in the broader espionage campaign.
The FBI announced a joint cybersecurity advisory related to the China-linked Salt Typhoon campaign. The advisory marked a formal government guidance and technical disclosure effort intended to help organizations detect, respond to, and defend against the telecom-focused intrusions.
Canadian authorities said telecommunications companies in Canada were breached in a China-linked espionage campaign associated with Salt Typhoon. The disclosure expanded the known victim set beyond previously reported U.S. telecom providers.
Public reporting identified Charter Communications, Consolidated Communications, and Windstream as additional telecommunications companies affected by the China-linked Salt Typhoon campaign. The disclosure added specific victim names after earlier government statements had said more U.S. telecom firms were compromised than had been publicly identified.
Lumen disclosed that it had removed the China-linked Salt Typhoon hackers from its network, marking a public remediation update from one of the affected U.S. telecom providers. The statement indicated the company no longer saw the threat actor in its environment.
Verizon said it had secured its network following a breach by the China-linked Salt Typhoon group. The statement marked a public remediation update from another major U.S. telecom provider affected by the campaign.
The White House disclosed that the China-linked Salt Typhoon hacking campaign had compromised a ninth U.S. telecommunications company. The announcement marked a public escalation in the known scope of the telecom intrusions beyond the previously identified carriers.
The Biden administration moved to ban the remaining U.S. operations of China Telecom Americas, saying its network presence and cloud services posed a national security risk amid the China-linked telecom espionage campaign. Officials described the step as the first publicly announced U.S. response to the Salt Typhoon intrusions.
The White House disclosed that the China-linked Salt Typhoon campaign intercepted and recorded telephone calls involving very senior U.S. government officials. The statement added a concrete impact detail showing the espionage operation reached high-level official communications.
U.S. officials publicly urged the use of encrypted messaging applications in response to the Salt Typhoon telecom intrusions. The guidance reflected an official response aimed at reducing interception risk after the campaign's impact on communications security became clear.
Sen. Mark R. Warner publicly described the China-linked Salt Typhoon intrusion as the worst telecom hack in U.S. history. The statement underscored the severity of the espionage campaign against telecommunications infrastructure.
The FBI and CISA said their investigation uncovered a broad and significant China-linked cyberespionage campaign compromising multiple U.S. telecommunications companies. Officials said the hackers obtained customer call records, accessed communications of a limited number of mostly government or political figures, and sought data tied to lawful U.S. surveillance requests.
Public reporting said the China-linked Salt Typhoon group had compromised systems at Verizon, AT&T, and Lumen Technologies used to support lawful government access to communications data. The disclosure highlighted that surveillance backdoor infrastructure at major U.S. telecom providers had been exploited.
CNN reported that Chinese hackers had gained access to U.S. telecommunications companies, raising concern among U.S. national security officials. The report marked an early public disclosure of the telecom intrusions later linked to Salt Typhoon.
The Register reported that China-linked Salt Typhoon cyber spies were detected deep inside U.S. internet service providers, marking an early public disclosure of the telecom espionage campaign. The report indicated the intrusions affected core provider environments before broader reporting on the operation emerged.
The FBI said the China-linked intrusions associated with Salt Typhoon have been active since at least 2019, marking the start of a long-running campaign against telecommunications providers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
26 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcesdxcentral.com
Open sourcenextgov.com
Open sourcefoxnews.com
Open sourcewashingtonpost.com
Open sourcecnn.com
Open sourcetheregister.com
Open sourcecyber.nj.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.