Tech Souls, Connected.

FBI Warns of Ongoing Chinese Cyber Espionage as Scope Widens Globally

Beijing-Backed Hackers Targeted Telecoms and Global Firms to Snoop on U.S. Officials and Harvest Sensitive Network Data


A Massive and Expanding Cyber Threat

The FBI has confirmed that Salt Typhoon, a Chinese state-sponsored hacking group, has breached at least 200 U.S. companies—a significant escalation from previously known incidents involving major telecom providers.

  • The news was confirmed by FBI assistant director Brett Leatherman, who spoke to The Washington Post.
  • Beyond U.S. targets, Salt Typhoon has reportedly infiltrated companies in 80 countries, underscoring the global scope of the cyber espionage effort.

Targeting Telecoms and U.S. Officials

Salt Typhoon was previously linked to intrusions at AT&T, Verizon, Lumen, Charter Communications, and Windstream, among others. But the campaign appears to have gone much further.

  • The group targeted call records to identify communications among senior U.S. politicians and officials.
  • This allowed them to map sensitive relationships, including who was being surveilled by U.S. legal orders.
  • The FBI at one point advised Americans to use encrypted messaging apps due to the severity of the threat.

Tactics: Routers and Network Surveillance

In a newly released joint advisory [PDF] from the FBI and nearly two dozen international cybersecurity agencies, Salt Typhoon is described as:

  • Primarily exploiting company routers to establish persistent access.
  • Siphoning sensitive network traffic, possibly without detection for long periods.
  • Using techniques that make attribution and detection especially difficult.

The advisory includes technical guidance for identifying intrusions and improving defenses against this style of attack.


Why This Matters Now

This is one of the most wide-reaching cyber espionage efforts attributed to China in recent years.

  • It reflects Beijing’s strategy of long-term access and surveillance, rather than immediate disruption.
  • By targeting infrastructure-level assets, Salt Typhoon gains visibility into high-level communications that traditional malware may not expose.

Leatherman emphasized the ongoing nature of the threat, warning that China’s cyber activities remain active and sophisticated.

Share this article
Shareable URL
Prev Post

Gemini, Grok, and Google AI Are Gaining on ChatGPT, Says a16z

Next Post

SpaceX Trades Perfection for Progress in Latest Starship Test

Read next