Salt Typhoon attacks may have hit more US firms than previously thought

China denies involvement as more US telecoms providers are revealed to be victims of Salt Typhoon attack.

Salt Typhoon attacks may have hit more US firms than previously thought

ARE YOU TIRED OF LOW SALES TODAY?

Connect to more customers on doacWeb

Post your business here..... from NGN1,000

WhatsApp: 09031633831

ARE YOU TIRED OF LOW SALES TODAY?

Connect to more customers on doacWeb

Post your business here..... from NGN1,000

WhatsApp: 09031633831

ARE YOU TIRED OF LOW SALES TODAY?

Connect to more customers on doacWeb

Post your business here..... from NGN1,000

WhatsApp: 09031633831


  • More victims of Salt Typhoon attack unveiled by WSJ
  • The extent of the damage caused by the attack is still unknown
  • Some telecoms providers have removed the attackers from their systems

The recent Salt Typhoon cyberattacks may have breached more telecommunications providers than previously thought, with Charter Communications, Consolidated Communications, and Windstream all now believed to also have been affected.

The fresh list of victims comes from a new report by the Wall Street Journal, who cited people familiar with the matter.

The attack also exploited Fortinet network devices that did not have up-to-date security software installed, as well as vulnerable Cisco large network routers.

Attack may have started in 2023

The attack against US telecoms providers was first publicized in a joint statement by the Federal Bureau of Investigation (FBI) and the Cybersecurity & Infrastructure Security Agency (CISA) on October 25, 2024 - however, the WSJ report states the attack is believed to have started as far back as fall of 2023 - around the same time US National Security Advisor Jake Sullivan was briefing telecom and tech executives on the depth and breadth of Chinese penetration into US critical infrastructure.

Salt Typhoon is now known to have successfully breached the networks of AT&T, Verizon, Lumen Technologies, and T-Mobile in the attack, but little is known about what data the China-affiliated group was able to access.

Both Lumen and T-Mobile have said that they successfully stopped the group from accessing sensitive customer information, with Verizon confirming that the data of a limited number of high-profile individuals involved in politics was targeted in attacks.

Salt Typhoon also gained access to a ‘lawful interception’ channel used by law enforcement agencies to perform court-ordered wiretaps for national security purposes, with China repeatedly denying any involvement in the attacks and accusing the US of spreading misinformation. China even went so far as to label Volt Typhoon - a similar group believed to be associated with Beijing - as a CIA asset set up to discredit the US’ rivals across the Pacific.

Both Fortinet and Cisco did not comment on the WSJ report, but both organizations have been in the cross hairs of cyber attacks from a range of cyber criminal groups.

Network routers with outdated firmware have been a favorite target as an initial access point for attackers and botnets for several years. Fortinet has also experienced a spate of attacks on its Windows VPN service and Fortigate VPN systems.

You might also like

What's Your Reaction?

like

dislike

love

funny

angry

sad

wow