Salt Typhoon Compromises US Telecom Wiretap Infrastructure
Chinese APT group Salt Typhoon breached the core networks of major US telecom providers — AT&T, Verizon, Lumen and others — reaching CALEA lawful-intercept systems and sustained metadata and audio collection across at least nine carriers.
01Video Presentation & Conference Keynote
02Deep-Dive Technical Analysis
Initial access traced to unpatched edge infrastructure (Cisco and Juniper gear) and reused credentials from prior vendor compromises. Once inside OSS and mediation layers, the actors reached CALEA Lawful Interception gateways, carrier-grade NAT and session border controllers, enabling sustained collection of metadata and real-time audio on targeted individuals. The December 2024 FBI/CISA joint statement urged high-risk users toward end-to-end encrypted communications — an extraordinary official admission that carrier networks themselves could not be trusted.
03Vulnerability & Exploit Flow
Cisco/Juniper router privilege escalation & CALEA gateway control.
04Recommended Defense & Mitigation Protocol
Mandatory multi-party authentication for LI provisioning, hardware root-of-trust router integrity, and network segmentation.
05Security Impact & Geopolitical Consequence
Triggered emergency CISA directives, FCC cybersecurity incident-reporting rules, and a federal review of lawful-intercept architecture — the largest acknowledged compromise of intercept infrastructure in history.
06Authoritative Standards & External References
07Related Topic Cluster Records
Master 5G Core, SS7 Defense & Subsea Cable Auditing
Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.