https://www.theregister.com/2024/12/30/att_verizon_confirm_salt_typhoon_breach/ # # Sign in / up The Register(r) -- Biting the hand that feeds IT # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features The Future of the Datacenter Cybersecurity Month VMware Explore Cloud Infrastructure Month Vendor Voice Vendor Voice Vendor Voice All Vendor Voice Pure Storage Kilka Tech HERE and AWS Vonage GE Vernova with AWS Amazon Web Services (AWS) New Horizon in Cloud Computing DDN Google Cloud Data Transformation Google Gemini Hewlett Packard Enterprise: Edge-to-Cloud Platform Intel vPro VMware (X) Resources Resources Whitepapers Webinars & Events Newsletters [cybercrime] Cyber-crime 27 comment bubble on white More telcos confirm Salt Typhoon breaches as White House weighs in 27 comment bubble on white The intrusions allowed Beijing to 'geolocate millions of individuals' icon Jessica Lyons Mon 30 Dec 2024 // 23:30 UTC # AT&T, Verizon, and Lumen Technologies confirmed that Chinese government-backed snoops accessed portions of their systems earlier this year, while the White House added another, yet-unnamed telecommunications company to the list of those breached by Salt Typhoon. The digital intrusion, which has been called the "worst telecom hack in our nation's history," gave Beijing-backed spies the "capability to geolocate millions of individuals" and "record phone calls at will," Anne Neuberger, deputy national security advisor for cyber and emerging technology, told reporters. In a statement emailed to The Register, AT&T said the foreign spies compromised "a small number" of its customers in the espionage campaign and added that the PRC-backed crew had since been kicked out of its networks. [cybercrime] "We detect no activity by nation-state actors in our networks at this time," an AT&T spokesperson said. [cybercrime] [cybercrime] "Based on our current investigation of this attack, the People's Republic of China targeted a small number of individuals of foreign intelligence interest," the statement added. "In the relatively few instances in which an individual's information was impacted, we have complied with our notification obligations in cooperation with law enforcement." AT&T continues to monitor its networks and work with government officials, other telecom firms, and cybersecurity experts on the investigation, the spokesperson said. [cybercrime] Verizon also confirmed that the Chinese intruders had accessed "a small number of high-profile customers in government and politics." A spokesperson told The Register that it notified these customers, and has since "contained the cyber incident brought on by this nation-state threat actor." An unnamed, "highly respected" cybersecurity company has also confirmed the containment, the Verizon spokesperson added. According to the operator's chief legal officer, Verizon partnered with federal law enforcement, national security agencies, other telecom partners, and security firms upon detecting the network activity. [cybercrime] "We have not detected threat actor activity in Verizon's network for some time, and after considerable work addressing this incident, we can report that Verizon has contained the activities associated with this particular incident," Verizon's Chief Legal Officer Vandana Venkatesh told The Register. Finally, Lumen Technologies, another one of the firms reportedly breached in the attack, told us that it has also booted the Chinese attackers out of its systems, and said it found "no evidence" that customer data was accessed. "An independent forensics firm has confirmed Salt Typhoon is no longer in our network," a spokesperson told The Register. "In addition, our federal partners have not shared any information that would suggest otherwise." T-Mobile's security boss previously spoke to The Register about the espionage campaign that appeared to be "consistent" with Salt Typhoon's snooping attempts and said it thwarted successful attacks on its systems "within a single-digit number of days." A spokesperson, however, told The Reg: "T-Mobile is not one of the nine being referenced by the government." 9 telecom firms compromised, White House says The companies' admissions come as a top White House official added another unnamed firm to the breach, bringing the total thus far to nine. Neuberger previously said eight had been compromised. Only three -- AT&T, Verizon, and T-Mobile US -- have confirmed the intrusion. We believe a large number of individuals were affected by geolocation and metadata of phones; a smaller number around actual collection of phone calls and texts "The Chinese gained access to networks, essentially had broad and full access," Neuberger told reporters. "We believe that's why they had the capability to geolocate millions of individuals, to record phone calls at will, because they had that broad access." In one instance, the spies broke into an admin account that then gave them access to more than 100,000 routers, she added. "So, when the Chinese compromised that account, they gained that kind of broad access across the network," Neuberger said. "That's not meaningful cybersecurity to defend against a nation-state actor." The White House doesn't yet have a number on how many total people were affected by the breach, she added. "We believe a large number of individuals were affected by geolocation and metadata of phones; a smaller number around actual collection of phone calls and texts," Neuberger said. "And I think the scale we're talking about is far larger on the geolocation; probably less than 100 on the actual individuals." Following the intrusion, the White House emphasized the inadequacy of voluntary cybersecurity measures against nation-state threats. The Federal Communications Commission (FCC) launched a public rule proposal requiring basic cybersecurity practices for telecom carriers. The commissioners are expected to vote on the rule by January 15. * Blocking Chinese spies from intercepting calls? There ought to be a law * China's Salt Typhoon recorded top American officials' calls, says White House * Salt Typhoon forces FCC's hand on making telcos secure their networks * T-Mobile US CSO: Spies jumped from one telco to another in a way 'I've not seen in my career' In addition to the FCC's own efforts, US Senator Ron Wyden (D-OR) has also proposed legislation that would require the FCC to issue binding rules for telecom systems. Plus, according to Neuberger, all of the nine telecom CEOs whose companies were hacked have signed on to the government's 60-day Enduring Security Framework. This public-private effort aims to put in place minimum cybersecurity practices that have been agreed upon by intelligence officers, CISA, the FBI, and telecom security experts. (r) Editor's note: This story was amended post-publication to note that T-Mobile US says it is not one of the nine telcos referenced by the government. Get our Tech Resources # Share More about * China * Cybercrime * Security More like these x More about * China * Cybercrime * Security * Telecommunications Narrower topics * 2FA * 5G * Advanced persistent threat * Application Delivery Controller * AT&T * Authentication * BEC * Black Hat * British Telecom * BSides * Bug Bounty * CHERI * China Mobile * China telecom * China Unicom * CISO * Comcast * Common Vulnerability Scoring System * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Cyberspace Administration of China * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * EE * Emergency Services Network * Encryption * Ericsson * Exploit * Firewall * Great Firewall * Hacker * Hacking * Hacktivism * Hong Kong * Identity Theft * Incident response * Information Technology and the People's Republic of China * Infosec * Infrastructure Security * JD.com * Kenna Security * Mobile Network * National Broadband Network * NCSAM * NCSC * NTT * Orange * Palo Alto Networks * Password * Phishing * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * RSA Conference * Semiconductor Manufacturing International Corporation * Shenzhen * Spamming * Spyware * Surveillance * Telecommunications Act of 1996 * TETRA * TLS * Trojan * Trusted Platform Module * Uyghur Muslims * Verizon * Vodafone * Voice over IP * Vulnerability * Wannacry * Zero trust Broader topics * APAC * Sector More about # Share 27 comment bubble on white COMMENTS More about * China * Cybercrime * Security More like these x More about * China * Cybercrime * Security * Telecommunications Narrower topics * 2FA * 5G * Advanced persistent threat * Application Delivery Controller * AT&T * Authentication * BEC * Black Hat * British Telecom * BSides * Bug Bounty * CHERI * China Mobile * China telecom * China Unicom * CISO * Comcast * Common Vulnerability Scoring System * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Cyberspace Administration of China * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * EE * Emergency Services Network * Encryption * Ericsson * Exploit * Firewall * Great Firewall * Hacker * Hacking * Hacktivism * Hong Kong * Identity Theft * Incident response * Information Technology and the People's Republic of China * Infosec * Infrastructure Security * JD.com * Kenna Security * Mobile Network * National Broadband Network * NCSAM * NCSC * NTT * Orange * Palo Alto Networks * Password * Phishing * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * RSA Conference * Semiconductor Manufacturing International Corporation * Shenzhen * Spamming * Spyware * Surveillance * Telecommunications Act of 1996 * TETRA * TLS * Trojan * Trusted Platform Module * Uyghur Muslims * Verizon * Vodafone * Voice over IP * Vulnerability * Wannacry * Zero trust Broader topics * APAC * Sector TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like China's cyber intrusions took a sinister turn in 2024 From targeted espionage to pre-positioning - not that they are mutually exclusive Security31 Dec 2024 | 3 How Androxgh0st rose from Mozi's ashes to become 'most prevalent malware' Botnet's operators 'driven by similar interests as that of the Chinese state' Cyber-crime24 Dec 2024 | 3 US reportedly mulls TP-Link router ban over national security risk updated It could end up like Huawei -Trump's gonna get ya, get ya, get ya Security18 Dec 2024 | 57 Where do European SMEs start when it comes to conquering the world? The answer is in Denmark Sponsored Feature [cybercrime] How Chinese insiders are stealing data scooped up by President Xi's national surveillance system Feature 'It's a double-edged sword,' security researchers tell The Reg Public Sector8 Dec 2024 | 53 Blocking Chinese spies from intercepting calls? There ought to be a law Sen. Wyden blasts FCC's 'failure' amid Salt Typhoon hacks Security11 Dec 2024 | 17 Ransomware scum blow holes in Cleo software patches, Cl0p (sort of) claims responsibility But can you really take crims at their word? Security16 Dec 2024 | 1 It's only a matter of time before LLMs jump start supply-chain attacks Interview 'The greatest concern is with spear phishing and social engineering' Security29 Dec 2024 | 56 How cops taking down LockBit, ALPHV led to RansomHub's meteoric rise Cut off one head, two more grow back in its place Cyber-crime28 Dec 2024 | 4 China's Salt Typhoon recorded top American officials' calls, says White House No word yet on who was snooped on. Any bets? CSO9 Dec 2024 | 24 US names Chinese national it alleges was behind 2020 attack on Sophos firewalls Also sanctions his employer - an outfit called Sichuan Silence linked to Ragnarok ransomware Cyber-crime11 Dec 2024 | 4 Suspected LockBit dev, facing US extradition, 'did it for the money' Dual Russian-Israeli national arrested in August Cyber-crime23 Dec 2024 | 18 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * Ts & Cs * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2024 no-js