Mandiant Salt Typhoon Probe Controversy – Senator Demands Action
China-Linked Salt typhoon Cyber-Espionage Campaign Continues to Target Telecoms and Academia
Table of Contents
Chinese government-backed hackers,operating under the moniker “Salt Typhoon,” have continued thier persistent cyber-espionage campaign,with recent revelations indicating ongoing targeting of global telecommunications providers and academic institutions. The group’s activities,first brought to light in late 2024,have been further detailed by cybersecurity researchers,highlighting a complex and far-reaching effort to infiltrate sensitive networks.
Escalating Operations and Broadened Scope
In February, Recorded Future’s Insikt Group documented Salt Typhoon’s compromises in at least seven devices linked to global telecom providers and other organizations. this followed earlier confirmations by AT&T and Verizon in December 2024 that Chinese government-backed snoops had accessed portions of their systems earlier that year. The Insikt Group’s findings further suggested that the PRC snoops “possibly targeted” more than a dozen universities, including the University of California, Los Angeles.The apparent objective was to gain access to research related to telecommunications, engineering, and technology, underscoring the group’s strategic focus on critical infrastructure and innovation.
Ongoing Campaign Bears Hallmarks of Chinese Cyber-Espionage
Adding to the growing body of evidence, in June, securityscorecard’s strike threat analysts revealed an ongoing campaign designed to gain long-term access to networks. This campaign exhibited all the characteristics associated with China’s “Typhoon” crews, suggesting a coordinated and sustained effort by state-sponsored actors.
The Fate of the Cyber Safety review Board and Calls for its Revival
The Cyber Safety Review Board (CSRB), an entity operating under the Department of Homeland Security, had been actively investigating Salt Typhoon and the methods by which these Chinese cyber spies penetrated US government and telecommunications networks. However, the board’s inquiry was abruptly halted following its dissolution on President Trump’s first day in office.
This dissolution has drawn criticism and calls for the board’s reinstatement. Just last month, a group of Democratic senators urged Homeland Security Secretary Kristi Noem to reestablish the CSRB. A primary motivation for this plea was the desire for the board to complete its crucial probe into the Salt Typhoon activities, highlighting the perceived importance of understanding and mitigating the threat posed by these sophisticated cyber operations.The senators’ appeal underscores a broader concern about the need for robust oversight and investigation into state-sponsored cyber threats.
