FBI Hunts Chinese Hackers Behind Major Telecom Breaches, Seeks Public’s Help


# FBI Seeks Public Help to Track Chinese Salt Typhoon Hackers

The FBI has issued a public call for information regarding Chinese state-sponsored hackers known as Salt Typhoon, responsible for extensive breaches of telecommunications providers in the United States and globally.

## Widespread Telecom Breaches

In October, the FBI and CISA confirmed that Salt Typhoon hackers had infiltrated multiple major U.S. telecom companies including AT&T, Verizon, Lumen, Charter Communications, Consolidated Communications, and Windstream, along with dozens of telecom providers worldwide. During these intrusions, the attackers accessed the U.S. law enforcement’s wiretapping platform and obtained private communications of a limited number of U.S. government officials.

“Investigation into these actors revealed a broad and significant cyber campaign to leverage access into these networks to target victims on a global scale,” the FBI stated in its recent public service announcement. The breaches resulted in theft of call data logs, private communications, and copying of information subject to court-ordered law enforcement requests.

## Ongoing Threat and Recent Activity

The Salt Typhoon group (also known as Ghost Emperor, FamousSparrow, Earth Estries, and UNC2286) has been targeting government entities and telecom companies since at least 2019. Between December 2024 and January 2025, they breached additional telecommunications companies by exploiting vulnerabilities in unpatched Cisco IOS XE network devices. These recent victims include a U.S. internet service provider, a U.S.-based affiliate of a U.K. telecommunications provider, and telecom companies in Italy, South Africa, and Thailand.

Cisco has identified that the hackers use a custom tool called JumbledPath to stealthily monitor network traffic and capture sensitive data from compromised networks.

## Government Response

In January, the U.S. Treasury Department sanctioned Sichuan Juxinhe Network Technology, a Chinese cybersecurity firm believed to be directly involved in the Salt Typhoon telecom breaches.

The State Department is offering a reward of up to $10 million through its Rewards for Justice program for information about government-linked foreign hackers targeting U.S. critical infrastructure.

U.S. authorities are also considering banning TP-Link routers pending an investigation into national security risks and reportedly planning to ban China Telecom’s last active U.S. operations.

Share This Article