Offcanvas Logo

Menu

  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us

Contact us

  • 1 Executive Dr Suite 100 #123 Marlton NJ 08053
  • 856-282-4100
  • info@xitx.com

Menu

  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us

Contact Us

  • 1 Executive Dr Suite 100 #123 Marlton NJ 08053
  • 856-282-4100
  • info@xitx.com

info@xitx.com
856-282-4100
1 Executive Drive Suite 100 Marlton, NJ 08053
+1 856-282-4100
Facebook-f X-twitter Instagram Linkedin-in Youtube
Xact IT Solutions
Let’s Talk
  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us
Xact IT Solutions
  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us
Let’s Talk

Salt Typhoon and the Carrier Illusion: Why ‘We Use AT&T’ Is Not a Security Posture

Salt Typhoon and the Carrier Illusion: Why ‘We Use AT&T’ Is Not a Security Posture

Salt Typhoon is the name U.S. intelligence agencies assigned to a Chinese state-sponsored threat group that spent months – possibly years – operating inside the infrastructure of major American telecommunications carriers. The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) confirmed the campaign in late 2024 and continued issuing guidance into 2025. What it revealed is something most small and mid-sized business owners have never had to confront: when you use a major carrier’s network, you are a tenant in a building you do not control, and someone else may already have a key.

  1. What Actually Happened With Salt Typhoon
  2. Why the Carriers Were the Target
  3. How Small Businesses Inherit Risk They Never Signed Up For
  4. The False Security of Brand-Name Infrastructure
  5. What a Well-Run Business Actually Controls
  6. What This Means in Practice
  7. Zero Trust: A Brief Primer for Small Business Owners

What Actually Happened With Salt Typhoon

This was not a smash-and-grab. Salt Typhoon was a long-duration, patient operation targeting the lawful intercept systems that carriers are legally required to maintain – the same systems built to allow court-ordered wiretapping. Attackers compromised those systems and used them as a vantage point to monitor communications and harvest metadata at scale.

CISA’s joint advisory with the FBI, the NSA, and international partners described the scope as broad and the dwell time as significant. The carriers affected included some of the largest names in American telecommunications. The full list has not been publicly confirmed, but reporting from the Wall Street Journal and subsequent congressional testimony indicated that AT&T, Verizon, and Lumen Technologies were among those compromised.

You can review the official CISA advisory directly: Enhanced Visibility and Hardening Guidance for Communications Infrastructure. It is worth reading even if you are not a technical person. The plain-language summary makes clear that the problem is systemic, not isolated.

Salt Typhoon exploited shared carrier infrastructure to surveil traffic at scale without targeting individual businesses directly.

Why the Carriers Were the Target

Salt Typhoon - Close-up of a computer screen displaying network traffic logs, packet captures, or system monitoring dashboards with flowing data streams, representing the surveillance and metadata harvesting that occurs within compromised infrastructure.

Nation-state actors do not think the way a ransomware crew thinks. A ransomware group wants your data or your money, and they want it now. A state-sponsored group wants persistent access, intelligence collection, and the ability to act at a time of their choosing. Carriers are attractive for exactly that reason.

Compromise a carrier and you do not have to attack each individual business. You sit upstream. You watch traffic flow. You can identify targets of interest, monitor communications, and build a picture of an organization’s operations without ever touching that organization’s systems. The attack surface is one massive, shared, trusted network – rather than thousands of individual hardened endpoints.

This is the structural vulnerability Salt Typhoon exploited. The carriers were not negligent the way a small business leaving a firewall unconfigured is negligent. They were targeted specifically because of their scale and their position in shared infrastructure. That does not make the outcome any less real for the businesses and individuals whose communications traveled through those networks.

How Small Businesses Inherit Carrier Security Risk They Never Signed Up For

Your service contract with a carrier gives you connectivity. It does not give you any visibility into what happens to your traffic once it leaves your building or your cloud environment. You are one of millions of tenants on shared infrastructure, and the security posture of that infrastructure is entirely outside your control.

This is not hypothetical. Salt Typhoon demonstrated that adversaries with sufficient resources and patience can establish footholds in shared infrastructure and operate there quietly for extended periods. A small accounting firm in Burlington County using a major carrier for voice and data is not the target of a nation-state – but their communications may pass through infrastructure a nation-state has already accessed.

The exposure for most small businesses is not that someone is actively hunting them. The exposure is structural:

  • Communications metadata collected in bulk can reveal business relationships, deal timelines, and organizational structure – without the attacker ever reading a single email.
  • Voice calls and SMS messages traveling over carrier infrastructure that lacks end-to-end encryption are readable by anyone with access to that infrastructure.
  • The lawful intercept systems Salt Typhoon exploited were built to be tapped. The only question is who holds the keys.
  • Businesses that believe their security posture ends at their own perimeter have a gap that no amount of endpoint protection closes.

The inherited risk is baked into the way shared telecommunications infrastructure is designed and regulated. It does not go away by choosing a different carrier.

The False Security of Brand-Name Infrastructure

There is a version of this conversation that happens in a lot of small businesses. Someone raises communications security. Someone else says, “We use Verizon” or “We’re on Microsoft 365” or “We have a business account with AT&T.” The implication: because the vendor is large and reputable, the risk is low.

Salt Typhoon is a direct refutation of that logic. The carriers involved are not obscure vendors. They are among the largest and most technically sophisticated organizations in the world – with compliance programs, dedicated security teams, and decades of regulatory oversight. None of that prevented a sustained nation-state intrusion that went undetected for an extended period.

Brand recognition is not a security control. Vendor size is not a security control. Wide adoption does not make a service more secure – in many cases, it makes it a more attractive target, because the return on investment for an attacker scales with the number of organizations sharing the same infrastructure.

This is not an argument against using major carriers. It is an argument against treating carrier selection as a security decision at all. The carrier moves your traffic from point A to point B. What happens to that traffic in transit – and what you can observe and control on your end – is a separate question entirely.

What a Well-Run Business Actually Controls

You cannot fix the carriers. You cannot audit their intercept systems or remove a nation-state actor from their infrastructure. What you can control is the surface area you present and the protections you layer on top of infrastructure you do not own.

A well-run IT environment addresses this through deliberate design decisions and ongoing vigilance:

  • Encrypted communications channels for sensitive conversations – so that even if traffic is captured in transit, it is unreadable without keys the carrier does not hold.
  • Zero-trust network architecture, which assumes no traffic – regardless of where it originates – should be trusted by default. Every access request is verified. This limits what an attacker positioned inside shared infrastructure can actually reach.
  • Endpoint detection tools that watch for unusual behavior on devices, regardless of whether the compromise originated at the network or device level.
  • Separation of sensitive communications from routine business traffic, so the most critical conversations are not riding the same pipes as everything else.
  • Sufficient visibility into your own environment to detect lateral movement if it occurs – meaning you are not relying on your carrier or cloud vendor to tell you something is wrong.

None of these controls are exotic. They are standard components of a mature security program. The problem for most small businesses is not that the controls are unavailable – it is that no one has sat down with them and mapped their actual exposure to a coherent set of protections. That gap is where the real risk lives.

Our cybersecurity services are built around exactly this kind of structured approach – identifying what you actually face, then putting the right layers in place, not the most impressive-sounding ones. You can also explore our managed IT services to understand how ongoing oversight closes the gaps that one-time reviews miss.

What This Means in Practice

Salt Typhoon is useful not because it is likely to directly affect a 15-person professional services firm in South Jersey, but because it makes the underlying architecture visible in a way that a routine breach does not. Most breaches happen because someone clicked a link or reused a password. Salt Typhoon happened because the infrastructure itself was the target.

That distinction matters for how business owners think about security. You cannot patch your way out of a carrier-level compromise. You cannot train your employees to stop using the phone network. What you can do is stop treating the network as a trusted boundary and start building your security posture around a clear assumption: the pipe is not safe.

This is not alarmism. It is the direction the entire security industry has been moving for years under the label of “zero trust.” Salt Typhoon is the most vivid recent illustration of why that direction is correct.

For small and mid-sized businesses, the practical takeaway is direct: ask your IT firm whether your security posture assumes the network is trusted. If the answer is yes – or if they cannot answer the question clearly – that is worth a longer conversation. The businesses that get through the next decade without a significant incident will not be the ones with the biggest carriers or the most recognizable software vendors. They will be the ones that built security postures that do not depend on someone else’s infrastructure being clean.

We have maintained zero client breaches across every client we have served since 2004. That record is not a coincidence. It reflects a deliberate approach to building environments that do not collapse when the infrastructure around them does. Calm outcomes do not happen by accident.

If you want to know whether your current posture makes the same assumption Salt Typhoon exploited, Book a Free Cybersecurity Strategy Call. It is a 20-minute conversation with our team – no pressure, no obligation.

Zero Trust: A Brief Primer for Small Business Owners

Because Salt Typhoon pushes this conversation toward zero-trust principles, it is worth grounding that term for business owners who encounter it mostly as marketing language. Zero trust is not a product you buy. It is an architectural assumption: no user, device, or network segment is trusted by default, regardless of where the request originates.

In practice, that means four concrete things for a small or mid-sized business:

  • Multi-factor authentication everywhere. Credentials alone are not sufficient proof of identity. A second factor – an app-generated code, a hardware key, a biometric – is required before access is granted, even on your internal network.
  • Least-privilege access controls. Users and systems have access only to the resources they need for their specific role. A compromised account in accounting cannot reach your operations systems because accounting was never granted that access.
  • Continuous session verification. Access is not granted once at login and then assumed for the rest of the workday. Unusual login times, unexpected data transfers, or new device signatures trigger re-authentication or alerts.
  • Network segmentation. The network is divided into smaller zones so that a compromise in one area cannot propagate freely. An attacker who gains access to one segment hits a wall before reaching the next.

The NIST framework for zero-trust architecture is publicly available and provides a rigorous foundation for organizations building or evaluating these controls: NIST Special Publication 800-207: Zero Trust Architecture. It is technical, but the executive summary is accessible and worth the time for any business owner seriously evaluating their posture.

Salt Typhoon did not create the need for zero-trust principles. It demonstrated, at carrier scale, what happens when trusted-network assumptions meet a patient, well-resourced adversary. Small businesses do not face the same adversary. The lesson about infrastructure assumptions applies at every scale regardless.

Let’s Talk About Your IT Strategy

If anything in this post raised a question about your own environment, the fastest path to an answer is a 20-minute strategy call. We’ll look at your specific situation and tell you what we’d actually do about it.

Schedule a 20-Minute Strategy Call

Recent Posts

  • IT Vendor Evaluation: Why Client Roster Size Misleads CEOs – and the 4 Operational Indicators That Actually Predict Performance
  • MFA Bypass Attacks Are Rising: What 2025 Breach Data Reveals About SMB Authentication Gaps
  • IT Services Contract Clauses That Actually Protect You (Not the SLA)
  • Your IT Vendor’s Breach Is Your Breach: What CISA Advisories Reveal About Supply-Chain Attacks on Small Business
  • Integration Sprawl: The Ransomware Entry Point Most IT Vendors Stopped Auditing After Day One

Categories

  • AI for Business
  • Backup & Recovery
  • Blog
  • Business
  • Buyer Guides
  • CMMC
  • Compliance
  • Cybersecurity
  • Healthcare
  • Managed IT
  • News & Analysis
  • Threat Intelligence

Share

FRUSTRATED WITH YOUR CURRENT IT PROVIDER? LET’S TALK.

Get a Free IT Consultation
Xact IT Solutions
  • info@xitx.com
  • +1 856-282-4100
  • 1 Executive Drive Suite 100 Marlton NJ 08053

Follow Us

Quick Links
  • Home
  • Partner Program
  • Why Choose Xact IT Solutions | Xact IT Solutions
  • Contact
Services
  • IT Support
  • Cybersecurity Services for SMBs | Xact IT Solutions
  • IT Compliance
Recent Blogs
  • Supply-Chain Ransomware Attack Impacts 60 Credit Unions
  • Comcast Xfinity Data Breach Exposes 36 Million Customers’ Data
  • Crown Equipment’s Cyberattack: Recovery and Lessons Learned
Copyright © 2026. Website Design by Xact IT Solutions
  • Privacy Policy and Terms & Conditions
  • Home
  • Partner Program
  • Why Choose Xact IT Solutions | Xact IT Solutions
  • Contact