2024 — Multiple U.S. broadband providers, including Verizon,…
Data compromised
Personal, Other
Technical writeup
Multiple U.S. broadband providers, including Verizon, AT&T, and Lumen Technologies, have been breached by a Chinese hacking group tracked as Salt Typhoon, the Wall Street Journal reports. The Wall Street Journal reports that T-Mobile’s network was breached in a Chinese cyber-espionage campaign targeting U.S. and international telecom firms. Hackers linked to Chinese intelligence aimed to spy on cellphone communications of high-value targets. It’s unclear if T-Mobile customers’ data, including calls or communication records, was compromised. The cyber campaign is attributed to the China-linked APT group Salt Typhoon, which is also known as FamousSparrow, UNC2286, and GhostEmperor. Salt Typhoon is a China-linked APT group active since at least 2019. The Chinese APT focuses on government entities and telecommunications companies in Southeast Asia. According to the WSJ, the group used sophisticated methods to infiltrate American telecom infrastructure through vulnerabilities including Cisco Systems routers, and investigators suspect the hackers relied on artificial intelligence or machine learning to further their espionage operations , people familiar with the matter said. The attackers penetrated at least some of that infrastructure over eight months or more. Salt Typhoon’s latest victims include Charter, Consolidated, and Windstream, underscoring the widening scope of China's cyberespionage campaign against critical US infrastructure.
Root cause
Hacking: Exploit vuln
References
- https://securityaffairs.com/171127/apt/t-mobile-victim-chinese-breach-of-telco-firms.html
- https://www.bleepingcomputer.com/news/security/t-mobile-confirms-it-was-hacked-in-recent-wave-of-telecom-breaches/
- https://www.bleepingcomputer.com/news/security/atandt-verizon-reportedly-hacked-to-target-us-govt-wiretapping-platform/
- https://www.theregister.com/2024/10/07/verizon_att_lumen_salt_typhoon/
- https://techcrunch.com/2024/11/14/us-confirms-china-backed-hackers-breached-telecom-providers-to-steal-wiretap-data/
- https://content.govdelivery.com/accounts/USDHSCISA/bulletins/3c1b400
- https://www.reuters.com/technology/cybersecurity/large-number-americans-metadata-stolen-by-chinese-hackers-senior-official-says-2024-12-04/
- https://www.csoonline.com/article/3632044/more-telecom-firms-were-breached-by-chinese-hackers-than-previously-reported.html