Critical Infrastructure at Risk: Communications

Critical Infrastructure at Risk: Communications

Bottom Line Up Front (BLUF)

The worst telecom hack in US history exploited the wiretap system itself, stayed active for years after exposure - and the FCC just rolled back the rules meant to stop it.

This dossier should be read in conjunction with the CommandEleven Intelligence “The Salt Typhoon Playbook: China’s Cyber Campaign Against Global Infrastructure” dossier previously published to understand how Salt Typhoon has been used against US infrastructure by China.

Key Judgments

  • [CONFIRMED] – Salt Typhoon, a China Ministry of State Security-linked group active since at least 2021 and publicly exposed in late 2024, achieved what Senate Intelligence Committee Chairman Mark Warner has called “the worst telecom hack in our nation’s history” – compromising at least nine major US telecommunications carriers, including AT&T, Verizon, and Lumen, with some intrusions persisting three years before detection.
  • [CONFIRMED] – Salt Typhoon specifically exploited systems built to comply with the Communications Assistance for Law Enforcement Act (CALEA), the 1994 law requiring carriers to maintain court-authorized wiretap capability – accessing metadata from over a million users and, in a smaller subset of cases, actual recorded call audio and text content, including communications of both the Trump and Harris 2024 presidential campaign staff.
  • [CONFIRMED] – As of February 2026, FBI officials publicly confirmed the Salt Typhoon threat remains “still very much ongoing.” Threat-intelligence firm Recorded Future documented continued breaches – five additional telecommunications firms compromised between December 2024 and January 2025 alone – occurring after both public exposure and US sanctions against the group, via exploitation of unpatched Cisco networking equipment across more than 1,000 targeted devices globally.
  • [CONFIRMED] – On November 20, 2025, the FCC, under Chairman Brendan Carr, voted to roll back cybersecurity rules put in place specifically in response to Salt Typhoon, shifting toward voluntary industry “collaboration.” Senate Commerce Committee ranking member Maria Cantwell has stated that AT&T and Verizon failed to provide documentation, when directly requested, proving remediation of ongoing network vulnerabilities.
  • [ASSESSED] – CommandEleven Intelligence assesses communications infrastructure occupies a structurally unique position among the sectors examined in this series: it is a target in its own right, but it is also the enabling layer every other sector depends on – the internet and cellular connectivity underlying the water-sector PLC exposure, grid SCADA remote access, and pipeline monitoring systems examined earlier in this series all ultimately run over the same communications backbone examined here.

The Threat Surface: The Enabling Layer for Everything Else

The Threat Surface: The Enabling Layer for Everything Else

Every vulnerability examined in this series’ prior three installments shares a common dependency this dossier treats as the through-line connecting the entire series: internet and cellular connectivity. The exposed PLCs behind the July 2026 water-sector campaign, Volt Typhoon’s pre-positioning inside grid operational technology, and the remote-monitoring systems underlying pipeline SCADA architecture all function because of the same communications infrastructure examined in this installment. This gives the communications sector a dual analytical significance: a compromise here is not just a sector-specific event, but potentially a force multiplier for attacks against every other sector this series has covered.

Salt Typhoon: The Worst Telecom Hack in US History

Salt Typhoon: The Worst Telecom Hack in US History

Salt Typhoon’s scope and duration distinguish it from every other case examined in this series. Operating since at least 2021 under China’s Ministry of State Security, the group compromised at least nine major US carriers by the time of its late-2024 public exposure – Cisco’s own incident analysis found at least one intrusion had persisted for three years before detection. By August 2025, per public reporting, the group’s confirmed footprint had expanded to more than 200 compromised companies across 80 countries.

The specific target inside these networks is what elevates this case above a conventional data breach: Salt Typhoon exploited systems built to comply with CALEA, the 1994 law requiring telecommunications carriers to maintain court-authorized wiretap access for law enforcement. This gave the group access to metadata on more than a million users, and – in a smaller, more targeted subset – actual recorded call content and text messages, including communications belonging to both major 2024 presidential campaigns’ staff. Senator Mark Warner’s public characterization – “the worst telecom hack in our nation’s history” – reflects both the scale and the specific nature of what was accessed: not commercial data, but the same lawful-intercept infrastructure meant to be among the most tightly controlled systems in the entire telecommunications sector.

Still Ongoing: Compromise After Exposure

Unlike several cases examined elsewhere in this series, Salt Typhoon’s activity did not meaningfully stop once it became public. As of February 2026, FBI Deputy Assistant Director for Cyber Intelligence Michael Machtinger stated publicly that the threat remains “still very much ongoing.” Recorded Future’s tracking (under the designation “RedMike”) documented five additional telecommunications firm compromises between December 2024 and January 2025 alone – after both public exposure and US government sanctions against the group – achieved through exploitation of two specific Cisco IOS XE vulnerabilities (CVE-2023-20198 and CVE-2023-20273) against more than 1,000 targeted devices globally, including telecommunications providers in Italy, South Africa, and Thailand alongside continued US targeting.

The international scope has continued to expand: Singapore confirmed all four of its major telecommunications providers were compromised, requiring an 11-month cleanup operation, and Norway became the first European government to publicly disclose a Salt Typhoon-linked intrusion.

  • [DATA DEFICIT] – This dossier does not have a complete, current accounting of which additional US carriers, beyond the originally confirmed nine, may have been compromised since the initial 2024 disclosure; the sourcing reviewed indicates continued activity without providing a comprehensive updated victim count.

The Regulatory Rollback

The government response has moved in a genuinely contested direction rather than a straightforward hardening. Following Salt Typhoon’s exposure, the FCC under then-Chairwoman Jessica Rosenworcel put in place cybersecurity requirements specifically intended to close the vulnerabilities the group had exploited. On November 20, 2025, the FCC under Chairman Brendan Carr voted to roll those requirements back, shifting toward a voluntary “collaboration” framework with carriers. Senator Cantwell, in a formal Senate Commerce Committee statement, characterized this as undermining the FCC’s ability to hold carriers accountable, and disclosed that despite a direct June 2025 request to AT&T and Verizon’s CEOs for documentation proving their networks had been remediated, “both companies have failed to provide any information.”

  • [ASSESSED] – CommandEleven Intelligence assesses this regulatory reversal – occurring after FBI officials had already confirmed the underlying threat remained active – represents a genuine, documented policy divergence between the confirmed technical threat assessment (Section III) and the regulatory response (this section), rather than a case where policy simply lagged evolving technical understanding. This dossier does not have visibility into the FCC’s specific internal reasoning for the rollback beyond its public “collaboration” framing, and does not speculate on motive beyond what has been publicly stated.

The Broader Government Response

Beyond the FCC’s contested rulemaking, the federal response has included an FBI reward of $10 million for information leading to identification or location of individuals engaged in malicious cyber activity on behalf of the Chinese government tied to critical infrastructure targeting, formal US sanctions against entities linked to the campaign (which Recorded Future’s findings indicate did not stop continued operations), and public guidance from CISA and FBI officials specifically recommending US persons – particularly those in government, political, or otherwise high-value target categories – adopt end-to-end encrypted communication applications rather than relying on standard cellular voice and SMS, which the CALEA-exploitation vector specifically targeted. Notably, a planned “Hunt for China’s Typhoons” panel at the 2026 RSA Conference – intended to bring together CISA, FBI, and NSA officials to discuss Salt Typhoon and related campaigns publicly – was cancelled when all three agencies withdrew, a data point this dossier reports without independently confirming the specific reason for the withdrawal.

Assessment

[ASSESSED] – The communications sector combines the longest-duration confirmed compromise examined anywhere in this series (three-plus years undetected), the most direct targeting of a specifically sensitive government function (lawful intercept infrastructure), and the most explicit, documented policy tension between confirmed ongoing threat and regulatory response of any sector this series has examined. Combined with this sector’s role as the enabling layer for the water, grid, and pipeline vulnerabilities examined in prior installments, this dossier assesses communications security deserves treatment as a foundational rather than parallel concern relative to the rest of this series – a compromised communications backbone does not just represent its own sector’s risk, but potentially amplifies the exploitability of every other sector examined here.

Series Continuity

The final installment in this series examines financial infrastructure – banking and payment systems where “attack” is as often about data integrity or access denial as physical disruption, closing out this series’ sector-by-sector examination before a synthesis piece drawing the full picture together.

CONFIRMED – Primary/Official Record & Direct Reporting:

ASSESSED – Credible Secondary Reporting:

Excluded from this dossier: Specific technical detail on the CALEA-system exploitation methodology or the precise Cisco device vulnerabilities’ exploitation mechanics beyond what is necessary to establish the general threat pattern. This dossier treats such detail as unsuitable for public release.

Protecting Your Household’s Communications: A $500 Baseline

This section is general emergency-preparedness and digital-hygiene guidance, modeled on standard FEMA and CISA public recommendations. It is not specific to any threat actor or incident, and does not depend on or respond to classified or sensitive information.

  • End-to-end encrypted messaging (≈$0): CISA has publicly recommended end-to-end encrypted messaging applications over standard SMS/cellular voice for sensitive communications, given SMS and traditional voice calls route through the same lawful-intercept infrastructure Salt Typhoon exploited. Most reputable encrypted messaging apps are free.
  • A battery/crank-powered emergency radio (≈$40-70): Provides an information channel independent of cellular networks or home internet if either is disrupted, whether from a targeted attack or a conventional outage.
  • A backup cellular/data option (≈$100-200): A low-cost prepaid phone or SIM on a different carrier than your primary provider offers redundancy if your primary carrier experiences an outage or degradation – a modest hedge against any single point of failure.
  • A written, offline contact list (≈$0): Phone numbers for immediate family and emergency contacts, kept on paper or saved offline on a device, since most people no longer memorize numbers stored only in a cloud-synced contacts app that may be unreachable during a communications disruption.
  • General digital hygiene: Keeping phone and router software updated addresses the base configuration errors and known vulnerabilities the FBI has specifically cited as a contributing factor in Salt Typhoon’s success – a free, ongoing practice rather than a one-time purchase.

CommandEleven Intelligence is not a licensed cybersecurity or emergency-preparedness authority; this guidance reflects publicly available CISA/FEMA recommendations and general good practice, not a CommandEleven Intelligence-specific assessment of any household’s individual risk.

The Critical Infrastructure at Risk Series

Linked Entities

Operational Theater

Area of Responsibility Map