The FBI just revealed the staggering scope of China's Salt Typhoon hacking campaign: at least 200 American companies and businesses across 80 countries have been compromised in what's now confirmed as one of the most extensive state-sponsored cyber operations in history. The campaign remains active and ongoing, according to FBI cyber chief Brett Leatherman.
The numbers are staggering, and they're only getting worse. What started as a suspected breach of a handful of US telecom providers has exploded into a global espionage operation affecting at least 200 American companies and spreading across 80 countries worldwide, according to FBI assistant director Brett Leatherman's latest briefing to The Washington Post.
The revelation marks the first time US officials have quantified the true scope of the Salt Typhoon campaign, and the scale is breathtaking. Previously confirmed victims include telecommunications giants AT&T, Verizon, and Lumen, along with Charter Communications and Windstream. But Leatherman's disclosure suggests hundreds more companies have been silently compromised.
[Embedded image: Global map showing the 80 countries affected by Salt Typhoon intrusions]
The hackers didn't just break in for bragging rights. According to the FBI's analysis, Salt Typhoon operatives systematically targeted call records and metadata belonging to senior American politicians and government officials. This intelligence goldmine allowed Chinese operatives to reverse-engineer US surveillance operations, mapping out who American intelligence agencies were monitoring and through what legal channels.
"The threat was so severe that we had to take the unprecedented step of recommending Americans switch to encrypted messaging apps," a senior FBI official told reporters during a background briefing. The agency's December advisory marked the first time the Bureau actively encouraged citizens to adopt encryption tools to protect against foreign surveillance.
The technical details reveal sophisticated tradecraft. Salt Typhoon operators primarily compromise company routers and network infrastructure, allowing them to siphon sensitive traffic without detection for months. The FBI's new technical advisory published Wednesday offers the first comprehensive guidance for identifying these intrusions, developed in collaboration with nearly two dozen international intelligence agencies.
[Video iframe: FBI cybersecurity briefing footage showing technical indicators of Salt Typhoon intrusions]
What's particularly alarming is the campaign's persistence. "This is ongoing," Leatherman emphasized in his Post interview, dispelling any notion that the threat has been contained. Intelligence sources familiar with the investigation tell The Tech Buzz that new victims are being identified weekly as forensic teams expand their search parameters.
The telecommunications sector remains ground zero for the campaign. Salt Typhoon's focus on telecom infrastructure makes strategic sense from an intelligence perspective, as these networks carry the communications of government officials, military personnel, and private sector leaders. By compromising the pipes rather than individual devices, Chinese operatives gained unprecedented visibility into American communications patterns.
The global expansion adds a new dimension to what was initially viewed as a US-focused operation. Intelligence analysts believe the 80-country footprint represents a coordinated effort to map Western alliance communications networks, potentially in preparation for future geopolitical tensions. Countries affected span North America, Europe, and the Asia-Pacific region, according to sources briefed on the investigation.
For enterprise security teams, the disclosure creates immediate pressure to audit router configurations and network monitoring systems. The FBI's advisory specifically calls out indicators of compromise related to router firmware modifications and unusual network traffic patterns. Security vendors report a surge in requests for network forensics services as companies scramble to determine if they've been affected.
The timing of this disclosure isn't accidental. With tensions escalating between Washington and Beijing over technology transfer restrictions and military posturing in the South China Sea, the Biden administration appears to be using hard intelligence disclosures to build international consensus around Chinese cyber threats.
The Salt Typhoon revelation transforms our understanding of Chinese cyber capabilities from targeted telecommunications breaches to a global intelligence operation of unprecedented scope. With 200+ American companies compromised and the campaign actively ongoing, this represents one of the most significant state-sponsored hacking disclosures in recent history. For businesses and government agencies alike, the message is clear: assume breach, verify continuously, and prepare for long-term remediation efforts as the full extent of Chinese infiltration continues to unfold.