The US government has confirmed a “broad and significant cyber espionage campaign” by China-linked operatives targeting “multiple” American telecommunications providers’ networks.
In a joint statement released Wednesday, the FBI and the US Cybersecurity and Infrastructure Security Agency (CISA) detailed the impact of the digital attacks, which involved the theft of customer call records, the compromise of private communications of select individuals—primarily those involved in government or political activities—and the copying of sensitive information requested by US law enforcement through court orders.
This announcement marks a development from the agencies’ late October disclosure that they were assisting affected companies and potential victims. It follows earlier reports indicating that a Chinese government-backed cyber-espionage group had infiltrated US telecommunications networks, including Verizon, AT&T, and Lumen Technologies.
The statement stops just short of confirming all previous reporting but suggests a significant breach. After infiltrating telecom networks, the China-linked entities—sometimes referred to as “Salt Typhoon”—allegedly accessed wiretapping systems used for court-ordered surveillance and targeted phones belonging to key figures, including Democratic presidential candidate Kamala Harris, Republican president-elect Donald Trump, and VP-elect JD Vance.
In effect, the statement acknowledges China’s penetration into US communications networks. The federal agencies emphasized their ongoing efforts to provide technical assistance, share information to support other potential victims, and bolster cyber defenses across the commercial communications sector. They urged any organization that suspects it has been compromised to reach out to its local FBI field office or CISA.
Meanwhile, security researchers have warned of further threats from another Chinese state-backed cyber group, Volt Typhoon, which is reportedly using old Cisco routers to build a botnet aimed at infiltrating critical infrastructure networks and launching cyberattacks.
Read the joint statement here.












