Skip to content
EternaEdge

National security

Salt Typhoon's aftermath: the footholds were the story all along

20 August 2026 · 2m read · By EternaEdge

Two windows into the state of U.S. telecommunications security opened this month. A House Select Committee on China report found that U.S. carriers connected systems to data centers and infrastructure with routine pathways to equipment tied to China Mobile, China Telecom, and China Unicom — carriers otherwise barred from operating in the U.S. — exposure the committee says may have facilitated the Salt Typhoon espionage campaign, per Bloomberg and The Record. Reviewing four days of 2024 routing data, the committee counted 58 groups of internet addresses CISA had linked to Salt Typhoon servers, with China Mobile International's network appearing in routes to them at least 192 times.

Then Bloomberg reported the inside of the response: T-Mobile security staff, hunting intruders after the Salt Typhoon disclosures, at one point physically cut a cable to sever the access they had found. It is a vivid detail with a sobering implication — expelling a patient, well-resourced actor from carrier infrastructure is hand-to-hand work, and completeness is hard to prove.

Operate as if the carrier layer is contested

For enterprises, the practical conclusion has not changed since the first Salt Typhoon disclosures named AT&T and Verizon among the victims — it has only hardened: the confidentiality of calls, texts, and metadata cannot be assumed at the carrier layer.

  • Sensitive coordination belongs on end-to-end encrypted channels as policy, not preference — including for executives, legal, and security teams themselves.
  • Metadata is the prize. Who called whom, when, from where — that is targeting data for everything from espionage to executive protection, and it leaks even where content is protected.
  • Telecom exposure is a counterintelligence input: organizations supporting defense or critical infrastructure should assume communications patterns are collected and factor that into how they move sensitive programs.

The deeper lesson is about time horizons. The committee's finding is that the exposure persisted through years of crackdowns — access maintained not through malware but through the ordinary plumbing of interconnection. Adversaries think in infrastructure decades. Defense that thinks in patch cycles will keep being surprised by what was underneath it all along.

Next step

See it run on your domains of protection.

A demo walks the full arc — signal to case to defensible record — with the domains you protect in the room.