Arthur T Knackerbracket has processed the following story:
US Senator Maria Cantwell (D-WA) has demanded that Google-owned incident response firm Mandiant hand over the Salt Typhoon-related security assessments of AT&T and Verizon that, according to the lawmaker, both operators have thus far refused to give Congress.
AT&T and Verizon's networks were among those breached by China's Salt Typhoon, potentially giving Beijing long-term, persistent access to critical US networks.
"In December 2024, AT&T and Verizon both claimed that their networks were secure, but only weeks before the companies made those announcements, the U.S. government warned the breach was so significant it made it 'impossible' for agencies 'to predict a time frame on when we'll have a full eviction,'" the Democratic senator from Washington state wrote in a July 23 letter [PDF] to Mandiant Executive VP Sandra Joyce.
To get a better idea of whether the telecoms firms' claims are true, Cantwell last month sent a letter to both AT&T and Verizon requesting information about steps they took to secure their networks. Both companies told her that Mandiant had conducted security assessments following the Salt Typhoon intrusions, but the telcos refused to hand them over, according to the senator.
"This response only heightens my concerns about AT&T's and Verizon's current security posture, as they are either unwilling or unable to provide specific documentation that would corroborate their claims that their networks are secure," Cantwell wrote.
So instead, Cantwell has asked Mandiant to provide these documents by August 6. Specifically, the senator wants the incident response firm to share with Congress:
- A copy of all reports, assessments, and analyses Mandiant conducted for AT&T and Verizon, respectively, in response to the Salt Typhoon attacks.
- A list of any recommendations by Mandiant that have not been fully addressed by AT&T or Verizon in response to the Salt Typhoon attacks.
- All records related to the costs and expenses of Mandiant's work for AT&T and Verizon, respectively, in response to the Salt Typhoon attacks.
It's highly unlikely, however, that American networks have fully eradicated the Chinese spies and locked all of their backdoors into US-based IT systems.
In February, two months after AT&T and Verizon confirmed that Chinese government-backed snoops accessed portions of their systems earlier in 2024, Recorded Future's Insikt Group documented Salt Typhoon compromises in at least seven devices linked to global telecom providers and other orgs.
Plus, the PRC snoops "possibly targeted" more than a dozen universities, including the University of California, Los Angeles, to access research related to telecommunications, engineering, and technology, according to the infosec shop.
Then, in June, SecurityScorecard's strike threat analysts told The Register that the team uncovered an ongoing campaign, designed to gain long-term access to networks that bears all the markings of one of China's "Typhoon" crews.
The Cyber Safety Review Board (CSRB), under the Department of Homeland Security umbrella, had been investigating Salt Typhoon, and how the Chinese cyber spies penetrated US government and telecommunications networks, prior to the board's dissolution on President Trump's first day in office.
Also last month, a group of Democratic senators urged Homeland Security Secretary Kristi Noem to reestablish the CSRB, in large part so the board could finish its Salt Typhoon probe.
(Score: -1, Offtopic) by Anonymous Coward on Friday August 01 2025, @05:51PM (5 children)
The security is only an issue because of our vote. We made it an issue by our own negligence and apathy. It is very much on topic. The truth is just too ugly for you to bear. Your downmodding is unjustified, but don't let that stop you
(Score: 2) by janrinok on Saturday August 02 2025, @07:25AM (4 children)
We have covered the Salt series (Salt Typhoon, etc) and the Volt series (Volt Typhoon, etc) in previous discussions. That they originate in China, have links to specific Chinese military units, and their activities are facts that are well documented.
This was not just an attack on the US infrastructure. It also affected other countries around the world (UK, Germany, Australia and many others). Now, unless Americans are responsible for electing those in power in all of those countries too it is entirely unconnected with who has been in the US Government either now or in the last decade or so. It has nothing to do with how the US population has voted. It will not be changed by modifying how people elect future representatives at all levels. The common link is that they all used the same communications hardware. Those other countries are already replacing it and in some cases have completed the task - the US hasn't.
I have not denied the situation that you now find yourself in. In fact, I have clearly stated that YOU are all responsible for your Government. and it is up to you to sort it out. Expecting another election to provide a different outcome is a dream on your part. There are already major changes taking place in your Judiciary, the respect for the Constitution, the removal of basic freedoms from all Americans, voting redistricting etc. These changes are designed to ensure that the outcome of future elections is already decided. But that is NOT the topic under discussion. It has been discussed at length elsewhere.
Trump has disbanded the team responsible for investigating this breach of the US' security, probably because it was a legacy of the previous President. There will be no final report. The senator is trying to obtain whatever information is available so that the public can be informed of the level of the intrusion, and its implications. That is exactly what I would expect a senator to do. They are there to serve the people - not a specific President.
People on this site are complaining that many discussions have become political rather than sticking to the story topic. YOU are one of the people who is intentionally doing this in various stories and journals. Please stop. Stop hiding behind your imagined anonymity (others have already identified you) - post your thoughts in your journal. You are being an ass.
So I will moderate you as I see fit. You are off-topic.
(Score: 0, Disagree) by Anonymous Coward on Saturday August 02 2025, @05:48PM (3 children)
By whom? Has any of it been cross examined, or is it taken at face value? Again, the sources of your info have been proven to be untrustworthy. And there is little to no demand to verify anything, or for any real transparency. Hence the problem will continue indefinitely, until WE choose to act.
Merely repeating what I have said from the very beginning. So what are you arguing about?
:-) of course you will, very amusing.
(Score: 2) by janrinok on Saturday August 02 2025, @06:52PM (2 children)
Because you keep repeating it in different discussions and it is off-topic. Discuss the story, not your personal and irrelevant political views.
(Score: -1, Offtopic) by Anonymous Coward on Saturday August 02 2025, @09:45PM (1 child)
Not at all. I just go to the root of the problem being discussed, without all the superficial emotional clickbait that so enthralls people. You are perfectly free to ignore the comments like the others do
(Score: 4, Funny) by janrinok on Sunday August 03 2025, @03:03AM
Like everyone else with an account, I am also free to moderate your comments.