Observed Signal · Mar 9, 2026 · Cyberattack · Source: techcrunch · Impact: 4/5 · Sentiment: Negative
Salt Typhoon: Global Espionage Campaign Targets Telecom Giants
Security researchers and U.S. officials attribute a broad espionage campaign to a China-linked hacking group known as Salt Typhoon. The group has targeted telecom and internet providers worldwide, exploiting Cisco routers at network edges and compromising surveillance devices that enable lawful intercept. Researchers and the FBI say Salt Typhoon has hacked at least 200 companies and stolen tens of millions of phone records, including call records, texts and captured phone audio from senior U.S. officials. Confirmed U.S. victims include AT&T, Verizon, CenturyLink (now Lumen), Viasat, Charter Communications (Spectrum), Windstream and Consolidated Communications; T-Mobile reported it was targeted but said customer communications were not accessed. Security firms Recorded Future and Trend Micro have observed activity across the Americas, Europe, Asia, Africa and Oceania, and the FBI urged U.S. users to adopt end-to-end encrypted messaging.
A large-scale compromise of global telecom and internet infrastructure risks mass data exposure, national-security implications, service disruption, increased regulatory and operator security scrutiny, and accelerated adoption of stronger encryption—impacting communications and related technology sectors.
Track T-Mobile Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Salt Typhoon is attributed to China and is linked to an extended espionage campaign against telecom and internet companies.
- Researchers and the FBI say Salt Typhoon stole tens of millions of phone records, including call logs, text messages, and captured phone audio of senior U.S. officials.
- The group targeted Cisco routers at network edges and took control of surveillance devices used for lawful intercept.
- FBI officials reported Salt Typhoon hacked at least 200 companies worldwide.
- Confirmed U.S. victims include AT&T, Verizon, CenturyLink (now Lumen), Viasat, Charter Communications (Spectrum), Windstream, and Consolidated Communications; T-Mobile said it was targeted but customer communications were not accessed.
Connected Companies & Entities
7 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
T-Mobile Technician Cuts Cable to Thwart Salt Typhoon Hack
Bloomberg reports that T-Mobile's cybersecurity team ended a Salt Typhoon espionage attack by physically cutting a cable at a data center in Chicago. In autumn 2024, the Chinese hacking campaign infiltrated nine major US telecoms, including Verizon, AT&T, and T-Mobile, compromising routers and accessing metadata of millions of customers. T-Mobile's security team traced a suspicious signal to a manipulated router in Chicago that was spoofed as a T-Mobile device, operated by attackers. A technician drove to the site and cut the router's cable with scissors, halting the attack. The attackers only gained access to external networks, not customer data, according to T-Mobile's CIO Jeff Simon. The severed cable is now displayed in a frame at T-Mobile as a memento of the physical response to cyber threats.
T-Mobile Cut a Cable to Expel Chinese Hackers
Reporting says a 2024 state-linked espionage campaign known as Salt Typhoon, widely attributed to the Chinese Ministry of State Security, compromised more than 200 targets in roughly 80 countries and infiltrated nine major U.S. telecommunications firms, including AT&T, Verizon and T‑Mobile. T‑Mobile personnel, led by executive Jeff Simon, located a compromised device at a carrier data‑center site (accounts variously cite Bellevue, WA and Chicago), physically severed its external connection and seized the hardware to isolate the intrusion. The campaign targeted edge networks to collect phone records and information on senior U.S. officials; Simon and others said intruders could observe metadata but did not obtain customer data.
FBI Networks Breached: Hackers Target Surveillance Systems
TechCrunch reports that hackers breached FBI networks, reportedly affecting a system used to manage wiretaps and foreign intelligence surveillance warrants, according to CNN. The FBI told TechCrunch it identified and addressed suspicious activity on its networks and used technical capabilities to respond but declined to provide details. The article places the incident in the context of recent major intrusions into U.S. government and corporate systems, noting prior breaches of the U.S. Treasury, the National Nuclear Security Administration, and the U.S. Courts’ filing system. The piece also cites the FBI saying the Chinese government-linked hacking group Salt Typhoon has compromised at least 200 U.S. companies, with confirmed victims including AT&T, Verizon, Lumen, Charter Communications and Windstream.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
