Telecom Subversion by Nation-States — Research Reference
Chinese state-sponsored hackers compromised at least nine US telecom companies: AT&T, Verizon, T-Mobile, Lumen, Spectrum, Consolidated Communications, Windstream. Specifically targeted the CALEA-mandated lawful-intercept systems — the wiretapping backdoors the US government required telecoms to build.
Contents
Salt Typhoon (2024-2025)
Chinese state-sponsored hackers compromised at least nine US telecom companies: AT&T, Verizon, T-Mobile, Lumen, Charter (Spectrum), Consolidated Communications, Windstream. Specifically targeted the CALEA-mandated lawful intercept systems — the wiretapping infrastructure the US government required telecoms to build.
Compromised: call metadata from over a million users (mostly Washington DC area), live phone calls of specific targets (Trump and Harris campaign staffers), access to the lawful intercept systems themselves. Hackers had access for over a year before Microsoft detected them. As of late 2024, telecoms had not proven full eradication.
Senator Mark Warner: “the worst telecom hack in our nation’s history,” making prior Russian cyberattacks look like “child’s play.”
December 3, 2024: FBI and CISA recommended all Americans use end-to-end encrypted messaging apps. The same FBI that spent years trying to break encryption was now telling people to use it.
Treasury sanctioned Sichuan Juxinhe Network Technology Co. for direct involvement (January 17, 2025).
- Source: Salt Typhoon (Wikipedia)
- Source: Dark Reading: Salt Typhoon APT Subverts Law Enforcement Wiretapping
- Source: TechCrunch: FBI Recommends Encrypted Messaging Apps
- Source: NPR: FBI Warns Americans to Keep Text Messages Secure
- Source: Treasury Sanctions (Press Release)
- Source: CRS Report: Salt Typhoon Hacks
CALEA — The Original Sin (1994)
Communications Assistance for Law Enforcement Act. Signed by Clinton. Required all telecoms to build wiretapping capability into network architecture. Expanded 2004-2005 to include broadband ISPs and VoIP.
EFF warned from the beginning. After Salt Typhoon: “The lesson will be repeated until it is learned: there is no backdoor that only lets in good guys and keeps out bad guys.”
During original Congressional hearings, cybersecurity experts warned backdoors would be prime targets for foreign intelligence. FBI Director Louis Freeh assured Congress they posed no security risks. Thirty years later, China exploited exactly those systems.
Senator Wyden post-Salt Typhoon: CALEA hack proves the dangers of government-mandated backdoors.
- Source: EFF: Salt Typhoon Hack Shows There’s No Security Backdoor That’s Only For The “Good Guys”
- Source: Lawfare: CALEA Was a National Security Disaster Waiting to Happen
- Source: CALEA (Wikipedia)
The Athens Affair (2004-2005) — CALEA Exploited a Decade Earlier
Unknown actors (later linked to US Embassy/NSA) used lawful intercept features in Ericsson switches on Vodafone Greece’s network to tap 100+ phones including the Greek Prime Minister, defense ministry, and foreign affairs officials. Vodafone’s Network Planning Manager, Kostas Tsalikidis, was found dead during the investigation.
- Source: IEEE Spectrum: The Athens Affair
- Source: The Intercept: Did a Rogue NSA Operation Cause the Death of a Greek Telecom Employee?
- Source: Greek Wiretapping Case (Wikipedia)
SS7 Vulnerabilities
Signaling System 7, developed 1975, still underpins global telecom routing. No authentication. Any entity with SS7 access can track any phone’s location, intercept calls/texts, redirect communications. Not a bug — the architecture.
60 Minutes demonstration (2016): Karsten Nohl tracked Congressman Ted Lieu’s location, read his texts, recorded his calls with Lieu’s consent. Lieu later introduced legislation.
O2/Telefonica bank fraud (2017): First confirmed criminal SS7 exploitation in Europe. Attackers purchased SS7 access from a foreign operator for <€1,000, intercepted 2FA codes, drained bank accounts.
Saudi Arabia used SS7 to track Saudi citizens in the United States (2019-2020). The FCC, despite years of warnings, did nothing.
Citizen Lab: Circles — SS7 exploitation company selling to government security services. Some clients suspected of organizing extraterritorial targeted killings of dissidents.
Commercial SS7 surveillance networks (2025): A joint Lighthouse Reports investigation (“Surveillance Secrets”) and Citizen Lab report (“Bad Connection”) documented covert surveillance vendors — including the Indonesia-based firm First Wap — exploiting SS7 access to track phones worldwide for government and private clients.
- Source: Contrast Security: 60 Minutes and SS7 Vulnerability
- Source: The Hacker News: Real-World SS7 Attack — Bank Account Hacking
- Source: TechCrunch: Saudi Spies Tracked Phones Using Flaws the FCC Failed to Fix
- Source: Citizen Lab: Bad Connection — Uncovering Global Telecom Exploitation by Covert Surveillance Actors (2025)
- Source: Lighthouse Reports: Surveillance Secrets (2025)
- Source: Citizen Lab: Running in Circles — Clients of Cyberespionage Firm Circles
NSA and the Telecoms
Room 641A: AT&T, 611 Folsom Street, San Francisco. Fiber-optic splitters duplicated all traffic to NSA equipment (Narus STA 6400). Similar rooms in Seattle, San Jose, LA, San Diego, Atlanta. Revealed 2006 by technician Mark Klein.
FAIRVIEW (AT&T): NSA’s most important corporate partnership. Began 1985. Budget $188.9M (2013) — twice the next-largest. Billions of emails. Wiretapped UN headquarters.
STORMBREW (Verizon): Budget $46M (2013). Upstream collection from fiber-optic cables at seven international choke points.
Retroactive immunity (2008): After warrantless wiretapping exposed, Congress granted retroactive immunity to all cooperating telecoms. 46 civil lawsuits dismissed. EFF’s Hepting v. AT&T killed.
- Source: ProPublica/NYT: NSA Spying Relies on AT&T’s ‘Extreme Willingness to Help’ (August 2015)
- Source: Room 641A (Wikipedia)
- Source: ACLU: Talking Points on FISA Amendments Act 2008
GCHQ and British Telecoms
Tempora (launched 2011): Probes on 200+ internet links. Two components: “Mastering the Internet” and “Global Telecoms Exploitation.” BT (codenamed “REMEDY”) and Vodafone Cable (codenamed “GERONTIC”) received secret payments running into tens of millions of pounds annually.
Undersea cable tapping: data from 18+ submarine cables processed at GCHQ Cheltenham and Bude, Cornwall. Seeb base in Oman was first global internet tapping location.
The Huawei Controversy
Vodafone Italy backdoor (2009-2011): Bloomberg: Vodafone found telnet backdoor in Huawei routers, internal presentation identified 26 vulnerabilities (6 critical, 9 major). Huawei allegedly refused to remove. Vodafone disputed “backdoor” characterization. Huawei called them “weaknesses.”
Australia banned first (August 2018). UK: strip by 2027. US “rip and replace”: $1.9B FCC program, 40%+ of carriers can’t afford to finish.
The counter-argument: No smoking gun of Huawei backdoors being actively exploited has been publicly documented.
- Source: Bloomberg: Vodafone Found Hidden Backdoors in Huawei Equipment
- Source: GOV.UK: Huawei Removed from UK 5G by 2027
- Source: Washington Post: FCC Rip and Replace Threatens Rural Service
The Pegasus Project
Coordinated by Forbidden Stories. 80+ journalists, 17 media organizations, 10 countries. Amnesty International forensics, Citizen Lab peer review.
50,000+ phone numbers selected for targeting by NSO clients. 14 heads of state (Macron, Imran Khan, Ramaphosa), 600+ government officials from 34 countries.
Khashoggi connection: Pegasus on iPhone of Khashoggi confidant Omar Abdulaziz months before the murder.
FORCEDENTRY: Zero-click exploit targeting Apple’s image rendering library. Also: WhatsApp zero-click (CVE-2019-3568), 1,400+ phones in two weeks.
US blacklisted NSO Group (November 4, 2021). Apple sued (November 23, 2021). December 2024: court ruled NSO liable for hacking 1,400 WhatsApp users.
- Source: Forbidden Stories: About the Pegasus Project
- Source: Citizen Lab: FORCEDENTRY
- Source: Commerce Dept: NSO Group Added to Entity List
- Source: Apple: Sues NSO Group
Stingray / IMSI Catchers
Cell-site simulators masquerading as cell towers. ACLU identified 75 agencies in 27 states using them. Harris Corporation required police NDAs. FBI intervened in state criminal trials to protect secrecy. Prosecutors dropped cases rather than reveal Stingray use.
- Source: ACLU: Stingray Tracking Devices
- Source: Cato: Stingray — A New Frontier in Police Surveillance
Undersea Cable Tapping
Operation Ivy Bells (1971-1980): USS Halibut installed listening device on Soviet undersea cable in Sea of Okhotsk. Soviets so confident they didn’t encrypt. Compromised 1980 by NSA analyst Ronald Pelton.
Concentration risk: 97-99% of intercontinental data through ~400 undersea cables.
Baltic Sea incidents (2023-2024): Balticconnector gas pipeline severed by Chinese vessel (October 2023). BCS/C-Lion1 cables disrupted, Chinese cargo ship Yi Peng 3 suspected (November 2024). Finland charged Eagle S tanker crew for Estlink 2 sabotage (December 2024).
- Source: Operation Ivy Bells (Wikipedia)
- Source: Atlantic Council: Baltic Sea Cable Cuts
- Source: NPR: Sabotage Suspected After Undersea Cables Damaged
The Comedy of Mutual Subversion
ANOM (Operation Trojan Shield, 2018-2021)
FBI designed, built, and secretly operated an entire encrypted phone network. Distributed 12,000+ devices to 300+ criminal syndicates in 100+ countries. Monitored 27 million messages. Result: 800+ arrests across 16 countries, 8 tons of cocaine, 22 tons of marijuana, 2 tons of meth, 250 firearms, $48M in currency seized.
- Source: DOJ: FBI’s Encrypted Phone Platform Infiltrated Criminal Syndicates
- Source: NPR: Trojan Shield
Crypto AG (Operation Rubicon, 1970-2018)
CIA and West German BND secretly purchased Swiss encryption company for $5.75M in 1970. Sold deliberately weakened encryption to 120+ governments for nearly 50 years. BND exited ~1993; CIA continued as sole owner until ~2018. Revealed February 11, 2020.
- Source: Washington Post: How the CIA Used Crypto AG to Spy on Countries for Decades
- Source: Operation Rubicon (Wikipedia)
The Circular Absurdity
The US mandates backdoors (CALEA) that China exploits (Salt Typhoon). The US bans Huawei for alleged backdoors while running its own backdoor programs through US telecoms (FAIRVIEW, STORMBREW). The US blacklists NSO Group while operating its own global surveillance phone network (ANOM). The CIA sold rigged encryption to 120 governments while complaining about other nations’ espionage. After Salt Typhoon, the FBI told Americans to use the encryption it had spent years trying to break — and on the same call, still pushed for “responsibly managed encryption.” No such technology exists.
SIM Swapping
96% of SIM swap cases involve social engineering or insider collusion. FBI IC3: 2,026 complaints in 2022, $72.6M in losses. T-Mobile: three major breaches in three years (2021-2023), $350M settlement + $15.75M FCC penalty. In March 2025, T-Mobile ordered to pay $33M after SIM swap enabled theft of ~$38M in cryptocurrency.
- Source: FBI IC3: SIM Swap PSA (February 2022)
- Source: Krebs on Security: New T-Mobile Breach Affects 37 Million Accounts
The “Going Dark” Debate
FBI Directors repeatedly claimed encryption lets criminals “go dark.” Christopher Wray pushed for “responsibly managed encryption.” No such technology exists.
Burr-Feinstein bill (2016): Would have required companies to break their own encryption on court order. So broadly written it would have effectively outlawed file compression. Senator Wyden threatened to filibuster. Died without a vote.
EARN IT Act (2020, reintroduced 2022): Would have amended Section 230 to force platforms to scan for CSAM, effectively breaking E2E encryption. Failed after fierce opposition.
The post-Salt Typhoon irony: An unnamed FBI official on the same call recommending encryption still pushed for “responsibly managed encryption” — and could not name a single app that met that description.
- Source: EFF: The EARN IT Act Violates the Constitution
- Source: The Intercept: How to Protect Yourself From Salt Typhoon, No Matter What the FBI Says
- Source: Gizmodo: FBI Warns Americans to Start Using Encrypted Messaging Apps
Related research
- NSA / Snowden — the SIGINT foundation this sits on (Room 641A, FAIRVIEW, Five Eyes)
- Digital ID · The Twitter Files
- The revolving door — the tap/backdoor personnel cluster