
The Salt Typhoon Breach: When the Wiretap System Gets Wiretapped
3 min readSilentel editorial
Chinese state hackers spent 2024 inside the same lawful intercept systems US carriers built for government surveillance.
Every US telecom carrier is required by law to build wiretapping capability into its network. It's called CALEA, the Communications Assistance for Law Enforcement Act, and it exists so that law enforcement and intelligence agencies can conduct court-authorized surveillance. In 2024, it became clear that the same systems built to let the US government listen in had themselves been quietly compromised, not by the people they were built for, but by a Chinese state-sponsored hacking group known as Salt Typhoon.
What was actually breached
Salt Typhoon's campaign against US telecommunications infrastructure came into public view through the fall of 2024. Reporting from the Wall Street Journal in early October described how the hackers had gone after CALEA wiretap systems directly, the infrastructure carriers maintain specifically to support court-ordered surveillance. Major carriers, including AT&T and Verizon, were among those affected. Later reporting that month, from the New York Times, described phones belonging to senior campaign staff from both major US presidential campaigns as having been targeted during the same operation.
Beyond the wiretap systems themselves, the campaign reportedly gave the hackers access to call metadata, records of who called whom, when, for how long, and from which locations, alongside visibility into which numbers US law enforcement had targeted for surveillance in the first place. For a foreign intelligence service, that last piece is its own category of damage. It doesn't just expose the calls, it exposes who the calls belonged to and whether they were already under watch.
The irony is the whole story
This isn't simply a big breach. It's a breach with a specific, almost poetic structural failure at its center: the systems that were compromised exist because a government mandated them. CALEA doesn't just permit lawful intercept capability, it requires every carrier to build it in. That requirement created a standardized, deeply embedded access point across the entire US telecom industry, present in exactly the same form at carrier after carrier.
Security researchers have warned for decades that mandated backdoors, even ones built for legitimate law enforcement purposes, create a single class of vulnerability that becomes everyone's problem the moment it's found by the wrong party. Salt Typhoon is that warning playing out in practice. The infrastructure wasn't broken into through some exotic zero-day. It was accessed through the very access points that were required to exist.
The lesson for anyone relying on a national carrier
For governments and defence organizations, the uncomfortable takeaway isn't really about China specifically. It's about what happens when the security of your communications depends on infrastructure you don't control, built to specifications that mandate a built-in access point as a condition of operating.
- Mandated access points don't stay exclusive: a system built so that one authorized party can intercept communications is, by design, a system where interception is technically possible. Ensuring only the intended party can use it is a separate and much harder problem, one this breach shows wasn't solved.
- Carrier-level compromise affects everyone on that carrier, indiscriminately: unlike a targeted attack against a specific organization, a breach at the infrastructure layer sweeps up anyone using that network, regardless of how careful they've been.
- Sovereignty over the communication layer is the actual mitigation: a communications system that doesn't route through, or depend on, a national carrier's mandated intercept infrastructure isn't exposed to this specific failure mode at all, because there's no built-in access point sitting inside someone else's network for an adversary to find.
Salt Typhoon is likely to be studied for years as a case study in what happens when a government's own surveillance mandate becomes its adversary's easiest way in. For any organization that has to assume its communications might be a high-value target, the response isn't better monitoring of someone else's network. It's not depending on that network's built-in access points to begin with.