Other
Wikipedia / SecurityWeek / Congress.gov CRS
Primary Source βIncident Details
Chinese MSS-affiliated APT Salt Typhoon (FamousSparrow) breached at least 9 US telecoms including AT&T, Verizon, T-Mobile starting ~late 2022/early 2023. Accessed CALEA lawful intercept systems, obtaining near-complete list of wiretap targets. Harvested metadata (call/text timestamps, IPs, phone numbers) for 1M+ users primarily in DC area. Obtained audio recordings of Trump, JD Vance, Harris campaign staff. 200+ businesses in 80+ countries hit globally. Senator Warner called it ‘worst telecom hack in US history.’ Prompted CISA/FBI joint advisories Dec 2024.
Technical Details
- Initial Attack Vector
- CWE-287: Improper Authentication (exploitation of network edge devices and telecom infrastructure to access CALEA lawful intercept systems)
- Vendor / Product
- AT&T / Verizon / T-Mobile / Lumen / Spectrum / Consolidated Communications / Windstream telecom infrastructure
Timeline
- 2023-01-01 Breach occurred
- 2024-10-25 Publicly disclosed
- unknown Customers notified