Desk live·
ForensicPost
Nation-state/Telecom/File 25-0213

Salt Typhoon Compromised Five Telecoms Firms During the Sanctions Period

Threat researchers observed the Salt Typhoon set compromising five telecommunications firms between December 2024 and January 2025 — during and after the imposition of US sanctions intended to deter it.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTelecommunications firms
ActorSalt Typhoon
D. Kennedy11 min readConfidence: high2 sources reviewed

Threat intelligence researchers reported observing the intrusion set tracked as Salt Typhoon — which they track under a separate designation — compromising five telecommunications firms between December 2024 and January 2025, a period spanning the imposition of US sanctions related to the campaign.

Sanctions Are Not A Control

Financial sanctions work by making an activity expensive: freezing assets, cutting access to banking, deterring counterparties. That mechanism has purchase on criminal enterprises, which need to convert access into money through systems others control.

It has very little purchase on a state intelligence operation. There is no revenue to interdict, no counterparty to frighten, and no commercial calculation in which the sanction registers as a cost. The operation continued during the month it was announced.

This desk’s enforcement files at 26-0624 and 26-0522 record real disruption of criminal infrastructure. The distinction matters: takedowns and sanctions work against organisations that need the financial system, and do not work against organisations that do not.

What The Observation Actually Demonstrates

The finding is not that sanctions were ineffective in some general sense — they carry diplomatic and signalling functions this desk is not positioned to assess.

It is narrower and firmer: sanctions did not interrupt operational tempo. Five carriers were compromised in the window. If the policy objective was to stop the intrusions, the intrusions did not stop.

How we reported this

Compiled from public reporting of vendor threat research, listed below. The observation is a research assessment, not an official finding, and the affected carriers were not all named. Corrections: corrections@forensicpost.com.

Sources
  1. China’s Salt Typhoon hackers continue to breach telecom firms despite US sanctionsTechCrunch
  2. Salt Typhoon exposes US cyber vulnerabilitiesITIF
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary