The Canadian Centre for Cyber Security and FBI have confirmed that the Chinese state-sponsored hacking group “Salt Typhoon” has successfully breached Canadian telecommunications infrastructure, marking a significant escalation in cyber espionage activities targeting North American critical infrastructure.
## February 2025 Breach Details
In February 2025, Salt Typhoon compromised three network devices belonging to a major Canadian telecommunications provider. The attackers exploited CVE-2023-20198, a critical vulnerability in Cisco IOS XE systems that allows remote, unauthenticated access and administrative privileges.
The hackers retrieved configuration files from all three compromised devices and modified at least one to establish a GRE tunnel, enabling them to collect network traffic and sensitive data.
## Unpatched Vulnerability Exploited
CVE-2023-20198 was first disclosed in October 2023 after threat actors used it as a zero-day attack to compromise over 10,000 devices worldwide. Despite having more than a year to implement security patches, the affected Canadian telecom provider had failed to update their systems, providing an easy entry point for the attackers.
## Expanding Threat Landscape
Following Salt Typhoon’s attacks on multiple American broadband providers in October 2024, Canadian authorities detected reconnaissance activities targeting dozens of key organizations across the country. While no breaches were initially confirmed, the recent February incident demonstrates that some critical service providers ignored security warnings.
Intelligence indicates Salt Typhoon’s activities extend beyond telecommunications, targeting multiple industries through reconnaissance operations that could enable future lateral movement and supply chain attacks.
## High-Value Targets
Telecommunications providers represent prime targets for state-sponsored espionage due to their access to:
– Call metadata and subscriber location data
– SMS message contents
– Government and political communications
– Critical infrastructure communications
The attacks typically focus on edge devices including routers, firewalls, and VPN appliances at network perimeters.
## Global Impact
Salt Typhoon has compromised telecommunications companies across dozens of countries, including major U.S. providers such as AT&T, Verizon, Lumen, Charter Communications, and Consolidated Communications. Most recently, satellite communications company Viasat confirmed a breach, though customer data remained unaffected.
## Ongoing Threat Assessment
The Canadian Cyber Centre warns that attacks against Canadian organizations “will almost certainly continue” over the next two years. Critical infrastructure operators are urged to implement immediate security measures, including edge device hardening and comprehensive patch management protocols.
The persistent exploitation of known vulnerabilities highlights the urgent need for organizations to prioritize cybersecurity investments and maintain current security patches across all network infrastructure.
