Cyber-Attack Timeline: Salt Typhoon

Educational & easy-to consume visual guides to understanding attacks & enhancing resilience

Salt Typhoon Timeline Image (1) Salt Typhoon Summary Image (1)

Download Our Educational Cyber-Attack Timeline: Salt Typhoon

The Salt Typhoon cyber espionage campaign has been making shocking headlines around the world, but especially in the US. This sophisticated, allegedly state-backed operation has been targeting critical infrastructure, government agencies, and key industries worldwide. Security researchers have linked this campaign to advanced persistent threat (APT) actors leveraging stealthy techniques to infiltrate and persist within high-value networks.

The campaign focused on long-term cyber espionage has been using stealthy intrusion methods, and data exfiltration to support geopolitical and economic agendas. Hackers associated with the campaign managed to break into some of the biggest US internet providers and data of millions has apparently been compromised. According to news reports, Salt Typhoon threat actors also targeted the phones of Donald Trump and Kamala Harris during the recent US elections 

We've tried to make sense of everything that has gone down since the Nation-State actors have tried to establish their foothold in critical US infrastructure with our Salt Typhoon Cyber Attack Timeline.

From spear phishing campaigns to exploitation of zero-day vulnerabilities, the hackers have been using a variety of Tactics and Techniques in pursuit of sensitive information over the last few months.

Our Detailed Cyber Attack Timeline encapsulates, in depth, these series of incursions. The Salt Typhoon Cyber Attack Timeline summary is a visual representation of the key events, impact and actions taken in this massive cyber espionage campaign. 

Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.

  • ** GDPR ** We wholeheartedly believe your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data. 
  • Align with the GDPR requirements.
  • Increase your Breach Readiness.
  • Reduce your time to detect and respond.

Complete the form below to receive a copy of the detailed Salt Typhoon Attack timeline document and summary.

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

FAQs on the Salt Typhoon Cyber Attack

  • What is the Salt Typhoon cyber attack?

    Salt Typhoon is the name given by Microsoft to an alleged Chinese state-sponsored cyber espionage campaign that compromised the networks of multiple US telecommunications and internet providers. Rather than seeking ransom or destruction, the campaign was geared toward long-term intelligence collection, reportedly accessing call records, some private communications and systems used for court-authorised wiretap requests. A senior US senator described it as the worst telecom hack in the nation's history.

  • When did the Salt Typhoon attack happen?

    The campaign was first publicly disclosed by The Wall Street Journal on 25 September 2024, though US investigators reportedly began looking into it in the late spring of 2024 and the intruders had in some cases held access for a year or more. Disclosures, impact assessments and the US government response continued through late 2024 and into early 2025, with further technical findings published in February 2025.

  • Who is behind the Salt Typhoon attack?

    US officials and security researchers have attributed the campaign to alleged Chinese state-sponsored actors linked to China's Ministry of State Security. In January 2025, the US Treasury's OFAC sanctioned a China-based company, Sichuan Juxinhe Network Technology, which it said was directly linked to Salt Typhoon, along with a Shanghai-based cyber actor, Yin Kecheng. China has routinely denied such allegations. The 'Salt Typhoon' name was coined by Microsoft.

  • Which companies were affected by Salt Typhoon?

    Reporting indicated that at least nine US telecommunications companies were compromised, including AT&T, Verizon, Lumen Technologies, T-Mobile, Charter Communications, Consolidated Communications and Windstream. Several carriers later said they had contained the activity and detected no further nation-state access on their networks.

  • How did Salt Typhoon gain access to the telecom networks?

    According to Cisco Talos, the attackers gained access to Cisco devices largely through compromised login credentials. Researchers also found that older and known Cisco vulnerabilities were exploited in some cases (CVE-2018-0171, CVE-2023-20198 and CVE-2023-20273) to reach unpatched devices. US officials highlighted weak controls, noting that in one telecom a single compromised administrator account had access to more than 100,000 routers.

  • What data did Salt Typhoon access?

    Officials and reporting indicated the attackers accessed large volumes of call records and metadata, reportedly affecting the records of more than a million people, along with some private calls and texts of a smaller number of individuals primarily involved in government or political activity. The campaign also reportedly reached systems used for court-authorised US wiretap requests. End-to-end encrypted communications, such as those on Signal, were believed not to have been compromised.

  • Were US politicians targeted by Salt Typhoon?

    According to The Washington Post, the campaign reportedly targeted the phones of Donald Trump and his running mate JD Vance, people working on Vice President Kamala Harris's campaign, and State Department officials. Officials noted the effort was not directly election-related, as the intruders had reportedly been inside the telecom systems months earlier, in some cases more than a year before. These points reflect media reporting and official statements.

  • What malware and tools did Salt Typhoon use?

    Researchers attributed a range of custom tooling to the group. Trend Micro reported a backdoor called GhostSpider, alongside a Linux backdoor known as Masol RAT, a rootkit named Demodex, and a modular backdoor called SnappyBee. Cisco Talos separately documented custom malware it named JumbledPath, used to chain remote connections between targeted Cisco devices and attacker-controlled jump hosts.

  • Was a ransom demanded in the Salt Typhoon attack?

    No. Salt Typhoon was an intelligence-collection and espionage campaign rather than a ransomware or extortion operation, so no ransom was demanded. Its goal, according to officials and reporting, was long-term access to sensitive communications and records.

  • How did the US government respond to Salt Typhoon?

    The FBI and CISA investigated and issued guidance, including urging senior officials and politicians to use only end-to-end encrypted communications. US agencies held a classified briefing for all senators, the FCC moved to require carriers to secure their networks, and the Treasury's OFAC imposed sanctions on Sichuan Juxinhe Network Technology and the cyber actor Yin Kecheng. Officials cautioned that the affected companies had not fully removed the intruders at the time of reporting.

  • Why is Salt Typhoon considered so serious?
     Salt Typhoon struck the core infrastructure that underpins US communications, reportedly reached systems tied to lawful wiretap requests, and affected the records of more than a million people. Officials described it as potentially catastrophic and warned that evicting the intruders could require physically replacing large amounts of ageing, unpatchable network equipment. It underlined the systemic risk of nation-state actors prepositioning inside critical infrastructure. 
  • What can organisations learn from the Salt Typhoon attack?

    The campaign shows how stolen credentials and unpatched, internet-facing equipment can give a capable adversary deep, persistent access to critical networks. The key lessons are rigorous patching of network devices, least-privilege design so no single account controls vast infrastructure, strong credential and access management, end-to-end encryption for sensitive communications, and readiness for stealthy nation-state intrusions. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • The form above collects personal information so we may email you the requested information and pressing the "Get your free copy now"  button acts as informed consent for this processing purpose. Consequently we may be in touch to:

    • Update you when we host our ground-breaking Wisdom of Crowds events in your country or region.
    • Keep you posted on free resources and documents around Wisdom of Crowds events and its outputs. (For example, we tend to create insightful mind maps and we also are the creators of free to view Insights with Cyber Leaders Video Interviews. )
    • Ping you a note about upcoming FREE educational webinars on GDPR and Cybersecurity.
    • Inform you of any upcoming Data Breach Response or Cyber Incident Response training.  
  • Using the information from this page we will NOT sell or market to you any of our consultancy or trusted advisory services.  
  • In its purest interpretation, this act of us communicating with you is direct marketing and is processed on the basis of our legitimate interest and your engaging in our services. All marketing communication will include an unsubscribe button or other method of ending communication.