Security

Cyber-crime

China has utterly pwned 'thousands and thousands' of devices at US telcos

Senate Intelligence Committee chair says his 'hair is on fire' as execs front the White House


The Biden administration on Friday hosted telco execs to chat about China's recent attacks on the sector, amid revelations that US networks may need mass rebuilds to recover.

Details of the extent of China's attacks came from senator Mark R Warner, who on Thursday gave both The Washington Post and The New York Times insights into info he's learned in his role as chair of the Senate Intelligence Committee.

Warner told the Post, "my hair is on fire," given the severity of China's attacks on US telcos. The attacks, which started well before the US election, have seen Middle Kingdom operatives establish a persistent presence – and may require the replacement of "literally thousands and thousands and thousands" of switches and routers.

The senator added that China's activities make Russia-linked incidents like the SolarWinds supply chain incident and the ransomware attack on Colonial Pipeline look like "child’s play."

Warner told The Times the extent of China's activity remains unknown, and that "The barn door is still wide open, or mostly open."

The senator, a Democrat who represents Virginia, also confirmed previously known details, claming it was likely Chinese state employees could listen to phone calls – including some involving president-elect Donald Trump – perhaps by using carriers' wiretapping capabilities. He also said attackers were able to steal substantial quantities of data about calls made on networks.

Most of the senator's remarks confirm prior guidance from the FBI and the US Cybersecurity and Infrastructure Security Agency about the activities of a Beijing-backed crew dubbed Salt Typhoon that's accused of compromising, and rummaging around inside, US telco networks for many months.

For what it's worth, China claims the US makes this stuff up – but hasn't offered an alternative explanation.

The day after Warner chatted to the newspapers, the Biden administration’s national security advisor Jake Sullivan and deputy national security advisor for cyber and emerging technology Anne Neuberger met with telecom execs. According to a White House readout of the chat, they used the opportunity to "share intelligence and discuss the People's Republic of China's significant cyber espionage campaign targeting the sector."

Which rather suggests there's more info about this situation that's not available to the public. ®

Send us news
51 Comments

Biden signs sweeping cybersecurity order, just in time for Trump to gut it

Ransomware, AI, secure software, digital IDs – there's something for everyone in the presidential directive

FCC to telcos: By law you must secure your networks from foreign spies. Get on it

Plus: Uncle Sam is cross with this one Chinese biz over Salt Typhoon mega-snooping

After China's Salt Typhoon, the reconstruction starts now

If 40 years of faulty building gets blown down, don’t rebuild with the rubble

More telcos confirm China Salt Typhoon security breaches as White House weighs in

Intrusions allowed Beijing to 'geolocate millions of individuals, record phone calls at will'

China to probe US chip subsidies as export curbs rattle allies

Beijing investigating claims of unfair competition in mature semiconductors

Akamai to quit its CDN in China, seemingly not due to trouble from Beijing

Security and cloud compute have so much more upside than the boring business of shifting bits

FCC boss urges speedy spectrum auction to fund 'Rip'n'Replace' of Chinese kit

Telcos would effectively fund grants paid to protect national security

Charter, Consolidated, Windstream reportedly join China's Salt Typhoon victim list

Slow drip of compromised telecom networks continues

Encryption backdoor debate 'done and dusted,' former White House tech advisor says

When the FBI urges E2EE, you know it's serious business

Chinese cyber-spies peek over shoulder of officials probing real-estate deals near American military bases

Gee, wonder why Beijing is so keen on the – checks notes – Committee on Foreign Investment in the US

GoDaddy slapped with wet lettuce for years of lax security and 'several major breaches'

Watchdog alleged it had no SIEM or MFA, orders rapid adoption of basic infosec tools

The bell tolls for TikTok as lifelines to avoid January 19 US ban vanish

SCOTUS unlikely to save it, no time to find a buyer. So, hi, Xiaohongshu!