Drooid Logo
Back to story perspectives

Full Breakdown

Salt Typhoon: A Coordinated Cyber Espionage Campaign by Chinese Firms

8/29/2025, 12:11:33 AM

Overview of the Salt Typhoon Operation

The Salt Typhoon hacking campaign, attributed to the Chinese government, has emerged as one of the most significant cyber espionage efforts in recent years. A coalition of U.S. intelligence agencies, alongside 12 allied nations, has reported that three private Chinese companies—Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology, and Sichuan Zhixin Ruijie Network Technology—have played crucial roles in facilitating this operation. The campaign, which began in 2021, has targeted telecommunications networks globally, including major U.S. providers such as AT&T and Verizon, potentially compromising sensitive data for millions of individuals.

Scope and Impact of the Campaign

The Salt Typhoon operation has reportedly affected over 80 countries and breached more than 200 organizations, including critical infrastructure and government entities. The FBI has indicated that the hackers gained access to call records, private communications, and location data, enabling them to surveil high-profile individuals, including U.S. political figures like President Donald Trump and Vice President Kamala Harris. The operation's breadth underscores a sophisticated strategy that blends intelligence gathering with digital control over global systems.

Official Statements & Responses

In a joint advisory, U.S. agencies, including the FBI, National Security Agency, and Cybersecurity and Infrastructure Security Agency, emphasized the need for heightened vigilance against such cyber threats. The advisory detailed the hackers' methods, which included exploiting vulnerabilities in telecommunications infrastructure to maintain persistent access. Richard Horne, chief executive of the U.K. National Cyber Security Centre, expressed deep concern over the actions of the implicated companies, stating, “We are deeply concerned by the irresponsible behavior of the named commercial entities based in China that has enabled an unrestrained campaign of malicious cyber activities on a global scale.”

Criticism & Opposition

Critics of the Chinese government's cyber activities have highlighted the unprecedented scale of the Salt Typhoon operation. Brett Leatherman, assistant director of the FBI’s Cyber Division, described it as “one of the more consequential cyber espionage breaches we have seen here in the United States.” The operation has raised alarms about potential disruptions to essential services and the implications for national security, privacy, and economic competitiveness.

Conflicting Reports & Gaps

While the U.S. government and its allies have firmly attributed the Salt Typhoon campaign to Chinese state-sponsored hackers, the Chinese government has consistently denied involvement in such activities. Chinese officials have accused the U.S. and its allies of using these allegations to justify sanctions and trade restrictions. The coalition's statement did not outline further actions beyond existing sanctions against Sichuan Juxinhe, leaving questions about the future of international responses to such cyber threats.

Verbatim Quotes

  • “The data stolen through this activity against foreign telecommunications and Internet service providers (ISPs), as well as intrusions in the lodging and transportation sectors, ultimately can provide Chinese intelligence services with the capability to identify and track their targets’ communications and movements around the world,” — Joint Advisory from U.S. and Allied Agencies
  • “It is inconceivable that the U.S. would ever ask a private company to hack into Xi Jinping’s phone,” — Dakota Cary, China Analyst at SentinelOne

The Salt Typhoon campaign exemplifies the evolving nature of cyber warfare, where state-sponsored operations increasingly leverage private companies to conduct espionage, complicating detection and response efforts globally.