Salt Typhoon Hackers Breach Second U.S. Telecom Carrier, Exposing Real-Time Call Metadata for 6 Months
For six months, a threat actor with ties to the Chinese government sat quietly inside a major U.S. telecommunications network — reading call metadata, tracking SMS routing data, and monitoring in near real time as millions of Americans communicated. By the time investigators identified the intrusion, the damage was already done.

Federal investigators have confirmed a second significant U.S. carrier compromise attributed to Salt Typhoon, the Chinese state-linked hacking group that has emerged as one of the most consequential cyber threats to American communications infrastructure. According to officials familiar with the investigation, the attackers maintained persistent access for approximately six months before detection, with an estimated 4 million subscribers potentially affected. The disclosure has triggered emergency hearings at the Federal Communications Commission and renewed urgent questions about whether U.S. telecom security standards are structurally inadequate.
—
What Federal Investigators Have Confirmed
The confirmation of a second carrier breach comes from officials briefed on the investigation, building on prior public disclosures by the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) regarding Salt Typhoon’s broader campaign against U.S. telecommunications providers. While the identity of the second carrier has not been publicly released — standard practice during active national security investigations — officials have characterized the scope of access as serious, encompassing real-time call metadata and SMS routing information rather than message content.
Metadata, often dismissed as less sensitive than content, can be extraordinarily revealing. Call records expose communication patterns, associate individuals with organizations, and — when aggregated over months — can map social and professional networks with high fidelity. For intelligence services, persistent access to that data stream carries operational value that a single intercepted conversation cannot match.
—
Salt Typhoon: A Persistent and Sophisticated Threat

Salt Typhoon is not a new actor. U.S. government agencies have publicly linked the group to Chinese state intelligence operations, and prior reporting — including CISA statements and congressional testimony — has described its focus on telecommunications infrastructure as part of a sustained, long-term collection effort. Security researchers and government officials have noted that Salt Typhoon has exploited vulnerabilities in network edge devices and, in some cases, gained access through lawful intercept systems: the very architecture U.S. carriers are legally required to maintain under the Communications Assistance for Law Enforcement Act (CALEA).
That detail carries particular irony. Infrastructure designed to facilitate authorized government surveillance may have provided an entry vector for unauthorized foreign intelligence collection. It is a tension security researchers have warned about for years — one that the current telecom breach investigations have forced back into the policy spotlight.
—
The FCC Response: Hearings and Baseline Standards
The confirmed second carrier compromise has accelerated action at the FCC, where commissioners have convened emergency hearings focused on carrier security baseline standards. The central policy question before the commission is whether existing regulatory frameworks — largely unchanged since CALEA’s passage in 1994 — are adequate for the threat environment U.S. carriers now face.
FCC cybersecurity oversight has historically been limited in scope, with carriers afforded broad discretion over how they implement security controls. The current hearings represent a potential inflection point, with commissioners and outside experts examining whether that discretion has produced a patchwork of security postures that sophisticated state actors like Salt Typhoon can systematically exploit.
The outcome of those hearings will matter well beyond the immediate incident. Any new baseline standards the FCC establishes will shape how the entire U.S. telecommunications sector approaches network hardening, incident detection, and breach disclosure for years to come.
—
What This Means for Telecom Subscribers
For the estimated 4 million subscribers whose metadata was exposed, the immediate practical concern is limited — call metadata does not include the content of conversations or messages. However, individuals in sensitive professional roles should treat the exposure seriously. Journalists protecting sources, attorneys managing privileged communications, executives conducting merger discussions, and government employees operating outside classified systems are among those for whom metadata exposure carries elevated risk.
Direct remediation options for affected subscribers are limited, as the breach occurred at the carrier infrastructure level rather than on individual devices. The most effective protective measures involve reducing reliance on standard telephony for sensitive communications in favor of end-to-end encrypted alternatives that do not route metadata through carrier systems in the same way.
—
What Enterprise IT and Security Teams Should Do Now
For enterprise security and IT leaders, the Salt Typhoon telecom breach is a concrete prompt to reassess assumptions about carrier-layer security:
– **Audit communication channels**: Identify which business-critical communications rely on standard voice and SMS infrastructure versus encrypted alternatives. – **Accelerate encrypted messaging adoption**: Platforms that provide end-to-end encryption and minimize metadata exposure should be prioritized for sensitive internal and external communications. – **Review third-party telecom dependencies**: Enterprises with significant reliance on carrier services for authentication — particularly SMS-based MFA — should evaluate migration to app-based or hardware token alternatives. – **Monitor FCC proceedings**: Baseline standards emerging from the current cybersecurity hearings will carry direct compliance implications for enterprises operating in regulated industries.
—
The Structural Problem That Won’t Go Away
The Salt Typhoon campaign — spanning multiple confirmed carrier breaches and months of undetected access — is not primarily a story about a single intrusion. It is a story about systemic vulnerability in infrastructure that hundreds of millions of people depend on daily, governed by security standards that have not kept pace with the threat.
The confirmation of a second major carrier compromise should be understood as a signal, not an endpoint. Until the FCC hearings produce enforceable baseline standards, and until carriers are held to consistent, auditable security requirements, the conditions that enabled this breach remain in place. Salt Typhoon exploited them. Other actors are watching.
Send free SMS worldwide
Reach any mobile number in 200+ countries from your browser. No signup, no app.
Send a free SMS →

