Table of Contents
Salt Typhoon's reach more extensive than prior estimates
Defensive measures against Salt Typhoon
Home Technology peripherals It Industry FBI warns 'indiscriminate' Salt Typhoon hacking campaign has hit organizations in more than 80 countries

FBI warns 'indiscriminate' Salt Typhoon hacking campaign has hit organizations in more than 80 countries

Sep 14, 2025 am 12:42 AM

FBI warns 'indiscriminate' Salt Typhoon hacking campaign has hit organizations in more than 80 countries

The FBI has released a critical security alert, warning that the infamous hacking collective known as Salt Typhoon is intensifying its cyber operations worldwide.

According to the agency, this Chinese state-backed group has been conducting widespread attacks across numerous sectors, with a primary focus on high-capacity backbone routers used by major telecom providers. The threat actors are also targeting provider edge (PE) and customer edge (CE) routers to gain strategic access points within networks.

Beyond direct breaches, the hackers are exploiting compromised devices and trusted network relationships to move laterally into other systems. By reconfiguring router settings, they establish persistent backdoors that allow long-term surveillance and data collection.

The group has ties to several China-based firms—Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology, and Sichuan Zhixin Ruijie Network Technology—all of which supply cybersecurity tools and services to China’s Ministry of State Security and the People’s Liberation Army.

"Back in the fall, the FBI and CISA traced intrusions at multiple U.S. telecommunications companies to PRC-linked operatives identified as Salt Typhoon. Active since at least 2019, these actors have carried out an extensive cyber-espionage operation, undermining global standards for telecommunications privacy and security," stated Brett Leatherman, assistant director of the FBI’s Cyber Division.

"Today’s Joint Cybersecurity Advisory aims to equip defenders with actionable intelligence to prevent, detect, and respond to these threats. Combined with guidance issued in late 2024, it provides concrete steps to enhance network visibility and identify malicious behavior early."

Salt Typhoon's reach more extensive than prior estimates

Alarmingly, the FBI revealed that the scale of Salt Typhoon’s campaign far exceeds earlier assessments, affecting no fewer than 60 organizations across 80 countries.

“Beijing’s broad targeting of private communications underscores the need for stronger coordination with international partners to detect and disrupt such activities at the earliest possible stage,” Leatherman emphasized.

“If your organization suspects it may have been compromised by Salt Typhoon—or any malicious cyber actor—I urge you to reach out to your nearest FBI field office immediately.”

This latest advisory follows a recent Department of Defense (DoD) report exposing a prolonged cyber intrusion by Salt Typhoon into U.S. National Guard networks.

In July, the DoD disclosed that the group had infiltrated the network of an unnamed state National Guard unit and remained undetected for nearly 12 months.

During that time, the attackers are believed to have accessed and stolen sensitive military and law enforcement information.

Defensive measures against Salt Typhoon

The advisory outlines the group’s typical attack methodology: initial entry through unpatched vulnerabilities in networking infrastructure.

Once inside a system, the hackers modify access control lists, create elevated-privilege user accounts, and activate remote administration features to solidify their foothold before expanding movement across the network.

Unlike financially motivated cybercriminals, Salt Typhoon’s objectives center on intelligence gathering, specifically targeting telecom operators, government agencies, and defense systems.

That said, healthcare institutions have also emerged as potential targets.

“This alert exposes one of the most expansive state-sponsored cyber espionage campaigns ever linked to the Chinese government,” warned John Riggi, national cybersecurity advisor for the American Hospital Association (AHA).

“U.S. healthcare organizations could face direct or indirect consequences from this espionage, including disruptive attacks on critical infrastructure. They must take immediate action to detect, isolate, remediate, and report instances of these malware variants—whether found on internal systems or third-party service providers—to the FBI.”

Don’t forget to follow php.cn on Google News for continuous updates on our latest tech news, in-depth analysis, and reviews.

The above is the detailed content of FBI warns 'indiscriminate' Salt Typhoon hacking campaign has hit organizations in more than 80 countries. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undress AI Tool

Undress AI Tool

Undress images for free

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

ArtGPT

ArtGPT

AI image generator for creative art from text prompts.

Stock Market GPT

Stock Market GPT

AI powered investment research for smarter decisions

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

OpenAI’s new parental controls and mental health safeguards for ChatGPT aim to make the AI safer for teens. OpenAI’s new parental controls and mental health safeguards for ChatGPT aim to make the AI safer for teens. Sep 15, 2025 am 12:06 AM

OpenAI rolls out parental controls for ChatGPTParents can now connect with their teen’s accounts, limit features, and get alerts if emotional distress is detectedHigh-risk conversations will be handled by specially tuned models trained to support use

Google NotebookLM's AI podcast hosts can now get into an argument over your notes Google NotebookLM's AI podcast hosts can now get into an argument over your notes Sep 16, 2025 am 07:12 AM

NotebookLM by Google now features new Audio Overview formats: Brief, Critique, and DebateThese additions bring livelier interactions and structured discussions to uploaded contentThe enhancement pushes the tool closer to interactive, podcast-style AI

Microsoft warns of slow Azure traffic Microsoft warns of slow Azure traffic Sep 17, 2025 am 05:33 AM

Microsoft has issued a warning about heightened network latency affecting Azure services due to disruptions in undersea cables located in the Red Sea, forcing the company to redirect traffic through alternative routes."While network connectivity

GPT 5 vs GPT 4o: Which is Better? GPT 5 vs GPT 4o: Which is Better? Sep 18, 2025 am 03:21 AM

The latest release of GPT-5 has taken the world by storm. OpenAI’s newest flagship model has received mixed reviews – while some praise its capabilities, others highlight its shortcomings. This made me wonder: Is GPT-

Codex CLI vs Gemini CLI vs Claude Code: Which is the Best? Codex CLI vs Gemini CLI vs Claude Code: Which is the Best? Sep 18, 2025 am 04:06 AM

In 2025, a number of AI programming assistants that can be accessed directly from the terminal will be released one after another. Codex CLI, Gemini CLI, and Claude Code are some of these popular tools that embed large language models into command line workflows. These programming tools are capable of generating and repairing code through natural language instructions, and are very powerful. We reviewed the performance of these three tools in different tasks to determine which one is more practical. Each assistant is based on advanced AI models such as o4-mini, Gemini 2.5 Pro or Claude Sonnet 4, designed to improve development efficiency. We put the three in the same environment and use specific metrics

FBI warns 'indiscriminate' Salt Typhoon hacking campaign has hit organizations in more than 80 countries FBI warns 'indiscriminate' Salt Typhoon hacking campaign has hit organizations in more than 80 countries Sep 14, 2025 am 12:42 AM

The FBI has released a critical security alert, warning that the infamous hacking collective known as Salt Typhoon is intensifying its cyber operations worldwide.According to the agency, this Chinese state-backed group has been conducting widespread

AI means data breaches now cost much less - but they're still a huge threat to businesses AI means data breaches now cost much less - but they're still a huge threat to businesses Sep 21, 2025 am 12:24 AM

AI is cutting the time it takes to detect and respond to data breachesIBM reports AI adopters save up to £600,000 per breach compared to non-usersJust 33% of UK organizations have implemented AI in their security strategiesRecent findings from IBM in

The AI trust paradox: how regulated industries can stay credible in an AI-driven world The AI trust paradox: how regulated industries can stay credible in an AI-driven world Sep 21, 2025 am 12:36 AM

If you’d told a room full of risk-averse insurance executives five years ago that nearly half of UK consumers would soon welcome health advice from AI, you’d have been met with serious skepticism, if not outright laughter.Our latest report s

See all articles