Desk live·
ForensicPost
Nation-state/Statecraft/File 24-1004

Inside the Carriers, and Nobody Could Say for How Long

A PRC state-linked operation was found in the networks of AT&T, Verizon, Lumen, T-Mobile and other US carriers. The finding was the discovery date, not the start date.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUS telecommunications carriers
ActorSalt Typhoon
D. Kennedy13 min readConfidence: high4 sources reviewed

In October 2024 the United States government confirmed that an operation attributed to People’s Republic of China state-sponsored actors, tracked as Salt Typhoon, had penetrated American telecommunications carriers. Reporting has placed AT&T, Verizon, Lumen and T-Mobile among them, with at least six other carriers named subsequently.

The attribution is official rather than a research assessment, which is why this file is graded high. Under the corpus standard that still ranks below a court finding, and no court has tested it.

The Date In The Headline Is When Somebody Looked

October 2024 is a discovery. Espionage operations are found when a defender goes looking or a partner tips them off, and the interval before that is unmeasured by construction.

Reporting has since indicated the agency had encountered the same actor in federal networks before the telecom intrusions surfaced. This corpus records dwell as not established here rather than adopting any of the durations that have circulated.

Espionage Is A Different Failure From Extortion

Nothing was encrypted, nothing was posted to a leak site, and no ransom was demanded. There is no moment at which the attacker chooses to be seen, which is the moment most of this database is built around.

The consequence is that the whole apparatus this corpus uses to measure incidents — notification counts, leak-site postings, ransom figures — produces nothing at all. What is known here is known because agencies said so.

What A Carrier Holds

Not message content in the main, but who contacted whom, from where, and when — for everybody. The corpus argued at 24-0712 that metadata is not a lesser category, and there the holder was one carrier and the taker was financially motivated.

Here the holder is most of a national telecom sector and the taker is a state. The instruments this desk uses to grade severity read both as high, which is a limitation of the scale rather than a judgement about the two being equivalent.

How we reported this

Compiled from official statements, congressional research material and contemporaneous reporting, listed below. Graded high on the strength of official attribution; under the corpus standard that ranks below a court finding and none exists. The list of affected carriers is as reported and this desk has not seen a complete official list. Dwell is recorded as not established: the October 2024 date is a discovery, not a start. Corrections: corrections@forensicpost.com.

Sources
  1. Salt Typhoon hacks of telecommunications companies and federal response implicationsCongressional Research Service
  2. CISA clocked Salt Typhoon in federal networks before telecom intrusionsCybersecurity Dive
  3. 2024: when China’s Salt Typhoon made cyberspace tidal wavesNew Lines Institute
  4. CISA issues guidance to telecom sector on Salt TyphoonDark Reading
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary