Back to blog

Blog Post

Chinese-State Sponsored Group Breaches Global Telecoms Networks

Share on social

Sep 5, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Chinese-State Sponsored Group Breaches Global Telecoms Networks

[Chinese Telecom Breach]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

A state-sponsored hacking group known as Salt Typhoon, operating on behalf of the Chinese Communist Party (CCP), has infiltrated the networks of multiple telecommunications companies worldwide, compromising the personal data of millions of Americans and conducting surveillance of communications, according to U.S. officials.

The FBI confirmed that it has already notified hundreds of U.S. victims, while counterparts in at least 80 countries have also been alerted to Salt Typhoon's activity. The scope of the campaign underscores not only the privacy concerns for individuals but also the broader national security risks.

In response to the threat, the FBI and other global law enforcement agencies released a joint cybersecurity advisory. The advisory provides detailed technical guidance to help organizations detect, mitigate, and prevent attacks associated with Salt Typhoon.

The advisory notes that Salt Typhoon has been tracked under multiple aliases by researchers, including GhostEmperor, Operator Panda, RedMike, and UNC5807.

Salt Typhoon's targeting goes beyond telecommunications, and also includes transportation, lodging, military infrastructure, and government networks. The group uses widely known software vulnerabilities and exploits network routers to establish entry into victim environments.

The FBI and its partners are urging those in critical infrastructure sectors to review the advisory and implement the recommended security measures.

Lizzie Clark
LC

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient