Friday, January 17, 2025
HomeCyber Security NewsChinese Hackers Breached Deep Into US Telecom to Spy on Calls and...

Chinese Hackers Breached Deep Into US Telecom to Spy on Calls and Texts

Published on

SIEM as a Service

Follow Us on Google News

In a breach that lawmakers are calling the most serious in U.S. history, Chinese hackers infiltrated the nation’s telecommunications systems, gaining the ability to listen to phone conversations and read text messages by exploiting outdated equipment and vulnerabilities in network connections.

The revelations come as investigators scramble to understand the full scope of the intrusion.

“The barn door is still wide open, or mostly open,” said Senator Mark Warner, chairman of the Senate Intelligence Committee and a former telecommunications executive.

Speaking in an interview on Thursday, Warner expressed shock over the depth of the breach, which was linked to a Chinese intelligence group known as “Salt Typhoon.”

The hack was initially discovered by Microsoft during the summer of 2024 and is the “worst telecom hack in our nation’s history by far,” a senior U.S. senator told.

Chinese government-linked actors have hacked multiple telecom networks, stealing customer call records, targeting private communications of government and political figures, and copying data from U.S. law enforcement court orders, according to the FBI and CISA.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

Hack Targeted Conversations of Key Officials

Investigators revealed that the breach allowed hackers to monitor phone calls and text messages involving prominent Americans, including President-elect Donald J. Trump and Vice President-elect JD Vance.

While encrypted communication services like WhatsApp, Signal, or iMessage remained secure, hackers intercepted unencrypted texts and calls made over traditional phone networks.

The intrusion targeted national security officials, politicians, and their staff, enabling the hackers to listen to specific conversations during limited periods.

However, investigators believe the hackers lacked the ability to access past call recordings. Instead, they collected metadata including phone numbers, call durations, and location data which can yield valuable intelligence.

A Nationwide Network Breach

Hackers exploited vulnerabilities in aging telecommunications equipment and the seams between networks operated by major carriers such as Verizon, AT&T, and T-Mobile.

Initially, investigators believed the breach was confined to systems used for court-ordered surveillance. However, new findings show the intrusion extended far deeper, affecting every major U.S. telecommunications provider.

China’s hacking efforts have evolved over two decades, transitioning from stealing intellectual property and military blueprints to targeting sensitive government data.

Past examples include the theft of security clearance files for over 22 million Americans during the Obama administration.

Unlike Russia’s high-profile disruptions such as the 2020 SolarWinds software hack or the Colonial Pipeline attack China’s approach has been more covert, focusing on long-term intelligence gains. U.S. officials now believe the recent activity reflects a shift toward deeper, systemic infiltration.

Since the breach was exposed, Chinese hackers have seemingly withdrawn, making it harder for investigators to map their full activities.

Warner cautioned that the hackers may not have been fully expelled from U.S. networks. “We’ve not found everywhere they are,” he said, emphasizing the need for continued investigation.

Warner also urged transparency to alert the public to the severity of the breach. “We have to let the American people know this,” he stated.

Lessons from Allies

Australia and Britain have already implemented minimum cybersecurity standards for their telecommunications systems following similar breaches.

Warner expressed hope that the U.S. would follow suit, using this incident as a wake-up call to strengthen its defenses.

With U.S. officials still uncovering the extent of the intrusion, the breach underscores critical vulnerabilities in the nation’s telecommunications infrastructure and raises alarms about the potential long-term consequences of such widespread access by hostile actors.

Are you from SOC/DFIR Teams? – Analyse Malware & Phishing with ANY.RUN -> Try for Free

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

AWS Warns of Multiple Vulnerabilities in Amazon WorkSpaces, Amazon AppStream 2.0, & Amazon DCV

Amazon Web Services (AWS) has issued a critical security advisory highlighting vulnerabilities in specific...

FlowerStorm PaaS Platform Attacking Microsoft Users With Fake Login Pages

Rockstar2FA is a PaaS kit that mimics the legitimate credential-request behavior of cloud/SaaS platforms....

New Tool Unveiled to Scan Hacking Content on Telegram

A Russian software developer, aided by the National Technology Initiative, has introduced a groundbreaking...

PoC Exploit Released for Ivanti Connect Secure RCE Vulnerability

A serious security flaw has been identified in Ivanti Connect Secure, designated as CVE-2025-0282, which...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

AWS Warns of Multiple Vulnerabilities in Amazon WorkSpaces, Amazon AppStream 2.0, & Amazon DCV

Amazon Web Services (AWS) has issued a critical security advisory highlighting vulnerabilities in specific...

FlowerStorm PaaS Platform Attacking Microsoft Users With Fake Login Pages

Rockstar2FA is a PaaS kit that mimics the legitimate credential-request behavior of cloud/SaaS platforms....

New Tool Unveiled to Scan Hacking Content on Telegram

A Russian software developer, aided by the National Technology Initiative, has introduced a groundbreaking...