Monday, August 3, 2026

Compute & Cloud

China-linked Salt Typhoon compromises 200 global firms

The China-linked Salt Typhoon hacking group has compromised at least 200 companies around the world, stealing tens of millions of phone records.

China-linked Salt Typhoon compromises 200 global firms

The hacking group Salt Typhoon, which is attributed to China, is behind one of the broadest hacking campaigns in recent years. According to officials from the FBI—the FBI being the US federal law enforcement agency—the group has hacked at least 200 companies around the world. The campaign has compromised telecommunications infrastructure, resulting in the theft of tens of millions of phone records.

According to researchers, the hacking group is part of a wider cluster of hackers with the collective aim of helping China prepare for an eventual war with Taiwan. This cluster includes Volt Typhoon, which focuses on destructive cyberattacks, and Flax Typhoon, which operates a botnet of hijacked internet-connected devices. U.S. officials have called China’s potential invasion of Taiwan an “epoch-defining threat.” To gain access, the group targeted devices from Cisco, a networking hardware manufacturer, specifically hacking routers at the edge of networks. This allowed them to compromise surveillance access points that telecom companies use to comply with law enforcement monitoring requests. In response to the threat of intercepted communications, the FBI has urged the use of end-to-end encrypted messaging apps.

The campaign’s geographic footprint spans multiple continents, with confirmed targets and activity across several regions:

  • United States: Hacked entities include phone and internet providers such as AT&T, Verizon, Lumen, T-Mobile, Charter Communications, Windstream, and Consolidated Communications, as well as satellite communications giant Viasat.
  • North and South America: Security firm Recorded Future observed targeting of Cisco devices at universities in Argentina and Mexico, while Canada confirmed hacks at its telecommunications firms. Cybersecurity firm Trend Micro also identified activity in Brazil.
  • Asia, Africa, and Oceania: Recorded Future reported targeting of a telecommunications provider in Myanmar and a South African telecommunications provider, alongside university routers in Bangladesh, Indonesia, Malaysia, and Thailand. Japan, Australia, and New Zealand also reported activity, while Trend Micro identified compromised organizations in Afghanistan, Eswatini, India, Taiwan, and the Philippines.
  • Europe: The United Kingdom, Norway, the Netherlands, Italy, Finland, and Poland have all confirmed or witnessed incidents related to the campaign.

Why it matters

This campaign marks a shift from traditional espionage to the strategic prepositioning of cyber capabilities within critical infrastructure. By compromising core routing and surveillance systems, the actors threaten the integrity of global telecommunications networks and government communications.