{
  "id": "case-salt-typhoon-telecom",
  "slug": "salt-typhoon-telecom-espionage",
  "title": "Salt Typhoon U.S. Telecommunications Wiretap Infrastructure Infiltration",
  "summary": "Chinese state-sponsored espionage campaign (Salt Typhoon / GhostEmperor / FamousSparrow) compromising core routing and lawful intercept infrastructure of major U.S. broadband and wireless carriers (including AT&T, Verizon, and Lumen), gaining persistent access to CALEA court-ordered wiretap requests and unencrypted call metadata of senior government officials.",
  "case_number": "CISA-FBI-JSA-2024-10-SALT",
  "court": "Federal Bureau of Investigation & CISA Joint Investigation",
  "district": "D.D.C.",
  "country": "United States",
  "opened_at": "2024-10-05",
  "status": "investigation",
  "victim_sector": "Telecommunications & Critical Infrastructure",
  "victim_country": "United States",
  "loss_amount_usd": 500000000,
  "loss_amount_note": "National security impact, emergency carrier hardware rip-and-replace, and lawful intercept architectural overhaul.",
  "first_seen_at": "2024-05-01T00:00:00Z",
  "last_updated_at": "2026-10-09T10:00:00Z",
  "actor_slug": "salt-typhoon",
  "defendant_slugs": [],
  "cves": [
    "CVE-2024-21887",
    "CVE-2024-3400"
  ],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Threat actors exploited edge firewall and VPN appliance vulnerabilities to compromise peripheral carrier edge routers.",
      "evidence_locator": "CISA Joint Cybersecurity Advisory on PRC Compromise of Commercial Telecommunications",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Joint Advisory: PRC Salt Typhoon Intrusion",
      "source_url": "https://www.cisa.gov",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1040",
      "evidence_excerpt": "Actors modified Cisco and Juniper router configurations to packet-sniff internal telco switching networks and intercept CALEA legal intercept data streams.",
      "evidence_locator": "FBI/CISA Technical Analysis Bulletin \u00b6 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "FBI Technical Intelligence Bulletin",
      "source_url": "https://www.fbi.gov"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2024-05-15",
      "description": "Salt Typhoon establishes persistence inside major U.S. telecommunications carrier core networks."
    },
    {
      "event_type": "discovery",
      "event_date": "2024-09-25",
      "description": "Investigators discover unauthorized access to lawful intercept CALEA interfaces."
    },
    {
      "event_type": "advisory",
      "event_date": "2024-10-25",
      "description": "FBI and CISA issue joint public warning detailing Chinese state-sponsored targeting of commercial telcos."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2024-21887, CVE-2024-3400) combined with targeted spearphishing and stolen remote access credentials.",
    "blast_radius": "National security impact, emergency carrier hardware rip-and-replace, and lawful intercept architectural overhaul. Impacted Telecommunications & Critical Infrastructure infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Threat actors exploited edge firewall and VPN appliance vulnerabilities to compromise peripheral carrier edge routers.",
        "technical_artifacts": [
          "T1190",
          "Exploit Public-Facing Application",
          "CVE-2024-21887",
          "CVE-2024-3400"
        ],
        "mitre_technique_id": "T1190"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}