Skip to content
Salt Typhoon Isn't a US Problem, It's a Global One

Salt Typhoon Isn't a US Problem, It's a Global One

3 min readSilentel editorial

Through 2025, Salt Typhoon's reach turned out to extend across roughly 80 countries, not just the US carriers where the story began.

A year ago, we wrote about Salt Typhoon as a story about American telecom carriers and the wiretap systems the US government mandated them to build. That framing hasn't aged well, not because it was wrong, but because it was incomplete. Through 2025, it became clear that Salt Typhoon was never a US-specific campaign. It was a global one, and the US disclosures were simply the first to surface.

The scope kept growing

By August 2025, the FBI confirmed that Salt Typhoon had compromised more than 200 organizations across roughly 80 countries, a figure that dwarfed the original story about nine US carriers. That same month, a joint cybersecurity advisory backed by authorities from thirteen countries formally linked the campaign to three China-based technology firms, describing an espionage apparatus that extended well beyond telecommunications into government agencies, transportation providers, and even hospitality and lodging businesses.

Some of the additional victims had already surfaced earlier in the year. A February 2025 report from threat intelligence firm Recorded Future identified telecommunications providers in Italy, South Africa, and Thailand among the newly compromised, alongside reconnaissance activity against a telecom operator in Myanmar. None of these were incidental targets. They were part of the same sustained campaign that had spent years inside US carrier networks, simply pointed at a wider set of countries once researchers started actively looking.

By September 2025, the US Treasury had sanctioned a Chinese technology firm tied directly to the group, an unusual step that formally acknowledged the campaign as state directed rather than the work of an independent criminal actor.

The uncomfortable pattern

What ties all of this together isn't just the scale, it's the target. Salt Typhoon consistently went after the same category of infrastructure everywhere it operated: the lawful intercept and core routing systems that telecom providers build because their national regulators require them to. Every country with a legal mandate for built-in surveillance access has, by definition, built the same kind of access point Salt Typhoon exploited in the US. The campaign's global reach isn't really a story about one group's persistence. It's a story about how consistent the underlying vulnerability is, wherever a similar regulatory requirement exists.

Why this matters beyond the headlines

For governments and organizations outside the US, it would be easy to have read the original Salt Typhoon coverage as someone else's problem. The 2025 disclosures make that read increasingly hard to sustain.

  • Scale changes the calculus: a campaign confirmed across roughly 80 countries isn't an isolated national security failure, it's evidence of a structural weakness present anywhere similar lawful intercept infrastructure exists.
  • Detection lags reality by a wide margin: several of the international victims identified in 2025 had reportedly been compromised well before their breach was confirmed publicly, meaning the actual footprint of this campaign is almost certainly still being discovered.
  • National carrier infrastructure isn't a safe default anywhere: the assumption that this is specifically an American vulnerability, tied to American regulatory choices, doesn't hold up once the same pattern shows up in countries with entirely different regulatory regimes.

The lesson from a year of expanding disclosures isn't that any single country got unlucky. It's that any organization depending on national carrier infrastructure for sensitive communication is depending on a system that has now been shown, repeatedly and across continents, to be reachable by a sufficiently determined state actor. That's not a reason to panic. It's a reason to look seriously at what alternatives exist that don't share the same exposure.