Threat intelligence researchers reported observing the intrusion set tracked as Salt Typhoon — which they track under a separate designation — compromising five telecommunications firms between December 2024 and January 2025, a period spanning the imposition of US sanctions related to the campaign.
Sanctions Are Not A Control
Financial sanctions work by making an activity expensive: freezing assets, cutting access to banking, deterring counterparties. That mechanism has purchase on criminal enterprises, which need to convert access into money through systems others control.
It has very little purchase on a state intelligence operation. There is no revenue to interdict, no counterparty to frighten, and no commercial calculation in which the sanction registers as a cost. The operation continued during the month it was announced.
This desk’s enforcement files at 26-0624 and 26-0522 record real disruption of criminal infrastructure. The distinction matters: takedowns and sanctions work against organisations that need the financial system, and do not work against organisations that do not.
What The Observation Actually Demonstrates
The finding is not that sanctions were ineffective in some general sense — they carry diplomatic and signalling functions this desk is not positioned to assess.
It is narrower and firmer: sanctions did not interrupt operational tempo. Five carriers were compromised in the window. If the policy objective was to stop the intrusions, the intrusions did not stop.
Compiled from public reporting of vendor threat research, listed below. The observation is a research assessment, not an official finding, and the affected carriers were not all named. Corrections: corrections@forensicpost.com.