CASE DOSSIER investigation

Salt Typhoon U.S. Telecommunications Wiretap Infrastructure Infiltration

Docket: CISA-FBI-JSA-2024-10-SALT Court: Federal Bureau of Investigation & CISA Joint Investigation Opened: 2024-10-05 Sector: Telecommunications & Critical Infrastructure

Key Facts

Status
INVESTIGATION
Legal disposition
Loss Amount
$500.0 million
National security impact, emergency carrier hardware rip-and-replace, and lawful intercept architectural overhaul.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: INVESTIGATION in Federal Bureau of Investigation & CISA Joint Investigation.
  • Primary Target Sector: Telecommunications & Critical Infrastructure.
  • Documented Financial Loss: $500.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Chinese state-sponsored espionage campaign (Salt Typhoon / GhostEmperor / FamousSparrow) compromising core routing and lawful intercept infrastructure of major U.S. broadband and wireless carriers (including AT&T, Verizon, and Lumen), gaining persistent access to CALEA court-ordered wiretap requests and unencrypted call metadata of senior government officials.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2024-21887, CVE-2024-3400) combined with targeted spearphishing and stolen remote access credentials.

Operational & Financial Fallout

National security impact, emergency carrier hardware rip-and-replace, and lawful intercept architectural overhaul. Impacted Telecommunications & Critical Infrastructure infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: INVESTIGATION
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2024-21887, CVE-2024-3400) combined with targeted spearphishing and stolen remote access credentials.

Adversary Kill Chain Flow

1 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1190 →

Threat actors exploited edge firewall and VPN appliance vulnerabilities to compromise peripheral carrier edge routers.

Artifacts & Tooling: T1190 Exploit Public-Facing Application CVE-2024-21887 CVE-2024-3400
Real-World Blast Radius & Operational Fallout

National security impact, emergency carrier hardware rip-and-replace, and lawful intercept architectural overhaul. Impacted Telecommunications & Critical Infrastructure infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2024-05-15 incident

Salt Typhoon establishes persistence inside major U.S. telecommunications carrier core networks.

2024-09-25 discovery

Investigators discover unauthorized access to lawful intercept CALEA interfaces.

2024-10-25 advisory

FBI and CISA issue joint public warning detailing Chinese state-sponsored targeting of commercial telcos.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Threat actors exploited edge firewall and VPN appliance vulnerabilities to compromise peripheral carrier edge routers." CISA Joint Cybersecurity Advisory on PRC Compromise of Commercial Telecommunications reviewed
T1040
"Actors modified Cisco and Juniper router configurations to packet-sniff internal telco switching networks and intercept CALEA legal intercept data streams." FBI/CISA Technical Analysis Bulletin ¶ 12 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Salt Typhoon U.S. Telecommunications Wiretap Infrastructure Infiltration, No. CISA-FBI-JSA-2024-10-SALT (Federal Bureau of Investigation & CISA Joint Investigation 2024), https://cybercaselibrary.com/cases/salt-typhoon-telecom-espionage/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/salt-typhoon-telecom-espionage" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>