Salt Typhoon is a China-linked cyber-espionage group behind one of the most significant intrusion campaigns of 2024-25: deep, prolonged access into US and global telecommunications carrier networks.
Key facts
- Assessed as state-linked and focused on telecommunications providers.
- Reported to have accessed sensitive carrier systems, including data relevant to lawful-intercept and call records.
- Represents a strategic intelligence threat given the reach of telecom infrastructure.
- Prompted urgent government guidance to carriers on hardening networks.
Why it matters
Salt Typhoon shows nation-state actors targeting the backbone of communications. Telecoms and their suppliers must monitor for exposed credentials and access being traded or used.
How DarkThreatX helps
DarkThreatX tracks threat-actor activity, leaked credentials and exposed data across the dark web so security teams can act on early warning. Run a free dark web scan or explore the platform.