CISA has urged senior government and political officials to switch to encrypted messaging apps, such as Signal, after a wave of telecommunications breaches in dozens of countries, including eight providers in the United States.
See also: CISA – Issues Best Practices for Securing Microsoft 365 Cloud Environments

CISA and the FBI confirmed these breaches in late October after reports that Salt Typhoon, a Chinese-backed threat group, had breached multiple US telecom providers, including T-Mobile, AT&T, Verizon , and Lumen Technologies. While the timeline of the breaches is unclear, the attackers reportedly had access for “months or more.”
Also known as Ghost Emperor, Earth Estries, FamousSparrow , and UNC2286, Salt Typhoon has been active since at least 2019, breaching telecommunications companies and government entities across Southeast Asia.
While today's guidance applies to high‑targeted individuals who are likely to possess information of interest to Chinese cyber‑spies, the measures can help anyone concerned about telecommunications breaches protect their data and information from hackers who successfully breach mobile carrier systems.
See also: CISA adds Windows kernel vulnerability to KEV List
In its advisory, CISA recommends switching to an end-to-end encrypted messaging app, naming Signal as an alternative for mobile communication across multiple mobile (iOS, Android) and desktop (macOS, Windows, and Linux) platforms.

It also recommends using phishing-resistant Fast Identity Online (FIDO ) multi-factor authentication (MFA ) along with hardware-based FIDO security keys (e.g. Yubico or Google Titan) or passwords to protect Microsoft, Apple, and Google accounts. Where possible, options like Google's Advanced Protection Program (APP) or Apple's Lockdown feature should also be enabled to defend against account compromise and phishing attacks .
Additionally, CISA advises avoiding SMS-based MFA, using a password manager to store and protect passwords from intruders, and setting a PIN or passcode for sensitive functions, such as porting your phone number and blocking SIM swap attempts.
See also: CISA published multiple advisories for ICS
Encrypted messaging apps, such as those recommended by CISA, have become essential tools for secure communication in the modern digital age. These apps use end-to-end encryption to ensure that messages are accessible only to the sender and intended recipient, protecting them from eavesdropping or unauthorized access. Popular examples include Signal, WhatsApp, and Telegram, each of which offers varying degrees of security, such as disappearing messages and two-factor authentication. These technologies are particularly valuable for preserving privacy, promoting safe dialogue, and protecting sensitive information in personal and professional contexts.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
