Salt Typhoon has compromised networks in more than 80 countries during 2026, with victims spanning telecommunications, transportation and government. By breadth of victim count and by the strategic value of what was accessed, it stands as one of the most consequential espionage campaigns publicly documented.
The group is assessed as Chinese state-aligned and is part of a broader landscape in which each major bloc has a distinct emphasis: North Korea pursues revenue, China pursues espionage and infrastructure access, Russia pursues disruption, and Iran pursues regional influence.
Why telecommunications is the crown jewel
Compromising a telecommunications provider is categorically different from compromising a normal enterprise. The provider is not the objective — it is the vantage point.
Access to carrier infrastructure can yield:
- Call detail records revealing who contacted whom, when and for how long, at national scale. Metadata alone maps organisations, relationships and hierarchies with remarkable precision.
- Location data derived from cell tower associations, providing movement patterns for any subscriber of interest.
- SMS content, including the one-time codes that still guard a great many accounts.
- Lawful intercept systems — the interfaces built for authorised surveillance, which become an extraordinarily powerful capability in unauthorised hands.
- Routing infrastructure, enabling selective traffic interception or redirection.
An attacker inside a carrier does not need to breach the organisations they want to watch. They watch the pipe those organisations already use.
The expansion into transportation and government
The move beyond telecoms into transportation and government networks suggests either a broadening mandate or the opportunistic exploitation of the same weaknesses across sectors that share infrastructure characteristics: large legacy estates, edge devices with long patch cycles, and operational technology alongside IT.
Transportation carries dual value. It offers intelligence on the movement of goods and people, and it represents pre-positioning — access maintained quietly against the possibility of future disruption. That pre-positioning model has been documented across critical infrastructure sectors, where access is established and held without any immediate destructive action.
The wider nation-state picture in 2026
Several trends define state-sponsored activity this year:
Breakout time has collapsed
The 2026 benchmark for adversary breakout time — from initial foothold to active exfiltration — is 72 minutes, a fourfold reduction from prior-year averages. Any response model that assumes a human analyst will triage an alert, escalate it and coordinate containment within a working day is now structurally too slow.
Volume is rising sharply
APT41 recorded a 113% surge in operations in a single quarter, described as the largest documented single-quarter increase for any nation-state actor. Capacity is being scaled deliberately.
AI is now operational, not experimental
All four major nation-state blocs operationalised large language models during 2025, and threat actors are now testing fully autonomous AI-driven attack pipelines. The near-term effect is less about novel attack techniques and more about throughput: faster reconnaissance, more convincing and better-localised social engineering, and quicker triage of stolen data.
Critical infrastructure is in scope
Iranian APT actors have targeted US critical infrastructure including water treatment facilities and energy systems, interacting directly with SCADA and HMI control systems. Direct interaction with control systems is a meaningful escalation from data theft.
Detecting an adversary that does not use malware
Groups operating at this level generally avoid custom malware where they can. They prefer:
- Valid credentials, obtained through phishing, infostealer logs or a prior compromise.
- Living-off-the-land binaries — PowerShell, WMI, native admin tooling that no allowlist blocks.
- Edge network devices as persistence points, where no EDR agent exists and firmware is rarely inspected.
- Legitimate remote access tools that blend into normal administrative traffic.
Signature-based detection contributes almost nothing against this. What does help:
- Baseline network device behaviour. Configuration changes, new administrative sessions, unusual outbound connections from routers and firewalls. These devices should be boring; deviation is signal.
- Identity analytics over endpoint analytics. When the attacker uses valid credentials, the anomaly is in the authentication pattern, not the process tree.
- Egress monitoring on infrastructure segments. Management networks should talk to a small, well-defined set of destinations. Anything else warrants investigation.
- Firmware integrity verification on network appliances, as far as your vendors support it.
- Assumed-breach hunting. Given 72-minute breakout times and multi-year dwell in some documented cases, waiting for an alert is not a strategy.
What this means for ordinary organisations
Most readers will not be a direct Salt Typhoon target. That does not make the campaign irrelevant.
If your telecommunications provider is compromised, your SMS-based authentication codes are potentially exposed and your call metadata is potentially collected — without any failure on your part. The defensive implications are concrete:
- Move off SMS-based MFA. It was already the weakest option; carrier compromise makes it worse.
- Use end-to-end encrypted messaging for sensitive internal communication, so that carrier-level access yields metadata rather than content.
- Assume communications metadata is collectable and factor that into how you handle genuinely sensitive matters.
- Include third-party infrastructure compromise in your threat model rather than only your own perimeter.



