Chinese state-run hackers Salt Typhoon have breached telecommunications companies in dozens of countries, according to a new White House announcement.

Anne Neuberger, President Biden's deputy national security adviser, told reporters that these breaches affect eight telecommunications companies in the United States.
"The Chinese have breached private companies, exploiting vulnerabilities in their systems. These breaches were part of a global Chinese campaign that has affected dozens of countries around the world," he said.
See also: Cyber espionage on Telecommunications networks by the PRC
"We can't say for sure that the adversary (Salt Typhoon) has been eliminated, because we still don't know the scope of what it's doing. We're still trying to figure it out, along with our partners," a senior CISA official said.
On Tuesday, CISA and FBI officials advised Americans to switch to encrypted messaging apps to minimize the chances of their communications being intercepted.
"Encryption . is your friend, whether it's text messages or voice communication," they said. "Even if an adversary is able to intercept the data, if it's encrypted, they won't be able to read it"
However, T-Mobile 's Chief Security Officer , who had said the company's systems were compromised by the network of an affiliated wireline provider, claims that T-Mobile is no longer seeing any intruder activity on its network.
Salt Typhoon: Telecom companies in the US are breaching
CISA and the FBI confirmed the breaches in late October, following reports that Salt Typhoon had breached the networks of T-Mobile, Verizon, AT&T, and Lumen Technologies.
See also: Salt Typhoon hackers target telecoms with GhostSpider backdoor
Federal agencies later revealed that the attackers had access to “private communications” of a “limited number” of US government officials.
We don't know exactly when the breaches took place, but a Wall Street Journal report says that Chinese hackers had access for "months or more." This allegedly allowed them to steal significant internet traffic from Internet service providers that served American businesses and millions of customers.
On Tuesday, CISA released guidance to help system administrators and engineers strengthen their systems' defenses against the Salt Typhoon hackers.
See also: Liminal Panda hackers use GSM, SIGTRAN protocols to attack telecommunications
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Some of the most important instructions/tips are:
- Immediate device repair and upgrade
- Disable all protocols that do not use authentication and do not implement encryption
- Restricting administrative connections and privileged accounts
- Use and store passwords securely
- Use strong encryption
- For network defenders: Configure systems to log all configuration changes and management connections (and have relevant alerts when something is detected).
- Monitoring traffic from trusted partners, such as wireline providers (T-Mobile was breached through a connected provider, not through devices exposed to the Internet).
Source: www.bleepingcomputer.com
