A Chinese state-backed hacking group, known as Salt Typhoon, has infiltrated at least 200 U.S. companies, according to the FBI’s top cyber official. The campaign, which had previously been linked to breaches at nine major U.S. telecommunications and internet providers, is now confirmed to have operated on a much larger scale.
In an interview with The Washington Post, FBI Assistant Director Brett Leatherman revealed that Salt Typhoon also compromised organizations in 80 countries, underscoring the global reach of the espionage operation.
While the FBI did not disclose the full list of affected companies, earlier reports confirmed that AT&T, Verizon, and Lumen were among the initial victims. Later, Charter Communications and Windstream were also identified as targets.
The hackers’ primary objective was to obtain call records of senior U.S. politicians and officials, allowing them to map communication networks and track surveillance activities authorized under legal orders. At one point, the FBI considered the threat so severe that it urged Americans to use encrypted messaging apps to protect their calls and messages from interception.
In a joint advisory published Wednesday, the FBI and nearly two dozen international agencies warned that Salt Typhoon focuses on exploiting company routers to siphon sensitive network traffic. The advisory also included technical recommendations to help organizations detect and mitigate intrusions.
Leatherman emphasized that the cyber threat from China remains “ongoing” and continues to pose a significant risk to U.S. national security.



