Following cyber espionage by PRC-affiliated actors against multiple US-based telcos, #CISA and partners have released guidance for telcos, which offers some clues as to what might have happened. The espionage campaign by PRC-based actor nicknamed Salt Typhoon (presumed to be PRC MSS), enabled theft of customer call data records, private communications of government and political individuals, and copying of lawful intercept information, from AT&T, Verizon, and Lumen. In other words, Salt Typhoon were presumably able to spy on US government comms, track everyone's movements and calls, and see who is being wiretapped - potentially for several years. The "Enhanced Visibility and Hardening Guidance for Communications Infrastructure" was released on Tuesday by #CISA, #NSA, #FBI, and cyber agencies from Australia, NZ, and Canada, and includes advice on how to defend telco networks. The guidance states up front that "no novel activity" was observed - the threat actors exploited existing vulnerabilities. At a high level, the key points for hardening are: 🔒 Do not expose management interfaces to the Internet, and make sure they do not use default passwords! This seems to be a problem in a lot of critical infra. 🔒 Keep management networks separate from data networks, and default deny inbound and outbound network traffic that is not needed. 🔒 Deploy security patches (especially on vulnerable Cisco hardware) - note that these attackers are not using 0-days. 🔒 Log authn, configuration changes, and network traffic on critical interfaces, then send logs encrypted to a central logging system (SIEM). 🔒 Use only strong, approved encryption algorithms. 🔒 Use phishing resistant MFA for accounts accessing sensitive systems. For telco customers (ie. everyone!) this means we need to take attacker-in-the-middle threats seriously. The FBI and CISA have warned that SMS and phone calls are not secure, and you should use an end-to-end encrypted messaging app (eg. iMessage/FaceTime, Signal, WhatsApp). I never thought I would see the day!
US Telecom Response to China VoltTyphoon Threat
Explore top LinkedIn content from expert professionals.
Summary
The US telecom response to the China VoltTyphoon threat involves actions taken by American telecommunications companies to address and secure their networks following cyberespionage attacks by a China-linked group known as Salt Typhoon. VoltTyphoon refers to a group of hackers associated with China’s Ministry of State Security targeting critical infrastructure in the US, with telecom companies like AT&T and Verizon working closely with government agencies and cybersecurity experts to investigate, contain, and prevent future breaches.
- Strengthen network security: Make sure to separate management and data networks and avoid exposing critical interfaces to the internet, reducing the risks of unauthorized access.
- Monitor and update: Regularly track network activity, apply security patches promptly, and use strong encryption to protect sensitive data from external threats.
- Communicate transparently: Keep customers and stakeholders informed about security incidents and improvements, building trust and awareness around cyber risks and prevention.
-
-
AT&T, Verizon targeted by Salt Typhoon cyberespionage operation, but networks are now secure. The Chinese-linked Salt Typhoon cyberespionage operation targeted AT&T and Verizon's (VZ.N) systems, but the wireless carriers' U.S. networks are now secure as they work with law enforcement and government officials, the companies said on Saturday in their first acknowledgment of the attacks. "We detect no activity by nation-state actors in our networks at this time. Based on our current investigation of this attack, the People's Republic of China targeted a small number of individuals of foreign intelligence interest," an AT&T spokesperson said. While only a few cases of compromised information were identified, AT&T was monitoring and remediating its networks to protect customers data, and continues to work with authorities to assess and mitigate the threat, the spokesperson said. "We have not detected threat actor activity in Verizon's network for some time, and after considerable work addressing this incident, we can report that Verizon has contained the activities associated with this particular incident," Verizon's Chief Legal Officer said in a statement. An independent and highly respected cyber security firm has confirmed the containment, Verizon said. On Friday, U.S. officials added a ninth unnamed telecom company to the list of entities compromised by the Salt Typhoon hackers and said the Chinese involved gained access to networks and essentially had broad and full access, giving them the capability to "geolocate millions of individuals, to record phone calls at will." The U.S. Department of Defense and the Federal Communications Commission did not immediately respond to Reuters' requests for comment on the company statements. China's foreign ministry could not immediately be contacted for comment. https://lnkd.in/gsxKFeCc #cybersecurity #telecoms #SaltTyphoon #China #ATT #Verizon
-
In cyber, it's always worse than the first report. AT&T and Verizon are withholding crucial information from over a million customers By World of Software; 14 Dec 2024 Telecom companies aren’t notifying most customers impacted by the intrusion of their systems by Chinese hackers. Salt Typhoon, a hacker group believed to be associated with China’s Ministry of State Security, has reportedly been inside US networks for months and it still hasn’t been expelled. A new NBC News report says that AT&T and Verizon, two companies that were hit the hardest by the hack, have only alerted customers whose call and text content was eavesdropped on. These customers constituted a relatively small number of victims, the vast majority of whom had their metadata stolen. Salt Typhoon hackers accessed metadata for over a million people, most in the Washington, D.C., area. Metadata is the data collected about phone calls and messages, such as the numbers of the participants, timing, and location information. ... The FBI is putting no pressure on AT&T and Verizon to notify customers whose metadata was accessed, and the two are unlikely to do so. https://lnkd.in/ezcrgHcV
-
A U.S. senator has now contacted Mandiant (part of Google Cloud) to determine whether Verizon Communications and AT&T have fully removed the #cyberespionage group known as #SaltTyphoon from their networks. Maria Cantwell sent letters to both #telecom providers requesting documentation on their response efforts. In reply, each company confirmed that Mandiant had been brought in to conduct a comprehensive assessment and verify the incident’s containment. Mandiant is now being asked to produce documents detailing its findings and actions related to the breach. Cantwell, a Washington Democrat and ranking member of the Senate Commerce, Science, and Transportation Committee, wrote this week to Sandra Joyce, executive vice president at Mandiant Intelligence and Government Affairs, requesting that Mandiant provide relevant documents in its possession that are responsive to her concerns. “Notwithstanding AT&T’s and Verizon’s December 2024 statements, recent reports indicate broad, ongoing doubts among cybersecurity experts that Salt Typhoon has been fully eradicated from our #telecommunications networks.” #CriticalInfrastructure
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development