Security

Cyber-crime

China has utterly pwned 'thousands and thousands' of devices at US telcos

Senate Intelligence Committee chair says his 'hair is on fire' as execs front the White House


The Biden administration on Friday hosted telco execs to chat about China's recent attacks on the sector, amid revelations that US networks may need mass rebuilds to recover.

Details of the extent of China's attacks came from senator Mark R Warner, who on Thursday gave both The Washington Post and The New York Times insights into info he's learned in his role as chair of the Senate Intelligence Committee.

Warner told the Post, "my hair is on fire," given the severity of China's attacks on US telcos. The attacks, which started well before the US election, have seen Middle Kingdom operatives establish a persistent presence – and may require the replacement of "literally thousands and thousands and thousands" of switches and routers.

The senator added that China's activities make Russia-linked incidents like the SolarWinds supply chain incident and the ransomware attack on Colonial Pipeline look like "child’s play."

Warner told The Times the extent of China's activity remains unknown, and that "The barn door is still wide open, or mostly open."

The senator, a Democrat who represents Virginia, also confirmed previously known details, claming it was likely Chinese state employees could listen to phone calls – including some involving president-elect Donald Trump – perhaps by using carriers' wiretapping capabilities. He also said attackers were able to steal substantial quantities of data about calls made on networks.

Most of the senator's remarks confirm prior guidance from the FBI and the US Cybersecurity and Infrastructure Security Agency about the activities of a Beijing-backed crew dubbed Salt Typhoon that's accused of compromising, and rummaging around inside, US telco networks for many months.

For what it's worth, China claims the US makes this stuff up – but hasn't offered an alternative explanation.

The day after Warner chatted to the newspapers, the Biden administration’s national security advisor Jake Sullivan and deputy national security advisor for cyber and emerging technology Anne Neuberger met with telecom execs. According to a White House readout of the chat, they used the opportunity to "share intelligence and discuss the People's Republic of China's significant cyber espionage campaign targeting the sector."

Which rather suggests there's more info about this situation that's not available to the public. ®

Send us news
51 Comments

Trump administration wants to go on cyber offensive against China

The US has never attacked Chinese critical infrastructure before, right?

US reportedly mulls TP-Link router ban over national security risk

It could end up like Huawei -Trump's gonna get ya, get ya, get ya

Blocking Chinese spies from intercepting calls? There ought to be a law

Sen. Wyden blasts FCC's 'failure' amid Salt Typhoon hacks

China's Salt Typhoon recorded top American officials' calls, says White House

No word yet on who was snooped on. Any bets?

How Chinese insiders are stealing data scooped up by President Xi's national surveillance system

'It's a double-edged sword,' security researchers tell The Reg

How Androxgh0st rose from Mozi's ashes to become 'most prevalent malware'

Botnet's operators 'driven by similar interests as that of the Chinese state'

Deloitte says cyberattack on Rhode Island benefits portal carries 'major security threat'

Personal and financial data probably stolen

US names Chinese national it alleges was behind 2020 attack on Sophos firewalls

Also sanctions his employer – an outfit called Sichuan Silence linked to Ragnarok ransomware

Are your Prometheus servers and exporters secure? Probably not

Plus: Netscaler brute force barrage; BeyondTrust API key stolen; and more

Ransomware scum blow holes in Cleo software patches, Cl0p (sort of) claims responsibility

But can you really take crims at their word?

Blue Yonder ransomware termites claim credit

Also: Mystery US firm compromised by Chinese hackers for months; Safe links that aren't; Polish spy boss arrested, and more

Infosec experts divided on AI's potential to assist red teams

Yes, LLMs can do the heavy lifting. But good luck getting one to give evidence