pwshub.com

Chinese cyberspies reportedly breached Verizon, AT&T

Verizon, AT&T, and Lumen Technologies were among the US broadband providers whose networks were reportedly hacked by Chinese cyberspies, possibly compromising the wiretapping systems used for court-ordered surveillance.

Salt Typhoon, the Beijing-linked crew that the American public first learned about last month after the espionage gang was spotted on US internet service providers' networks, gained a foothold in at least these three telecommunications giants' infrastructure, according to a Wall Street Journal report

After breaking into the carriers' networks, the Chinese government-backed snoops may have had access to systems the communications providers use to share domestic data with law enforcement requests, along with more "generic internet traffic" from individuals and businesses across the US, the newspaper reported, citing "people familiar with the matter."

The FBI and other law enforcement agencies are allowed to intercept electronic communications, provided that they have obtained a court order and that the data is being used to solve crimes or investigate national security matters. 

Of course, sometimes network providers and other companies provide this level of snooping access without a warrant, too.

As it relates to the Salt Typhoon breaches, it's unclear if the spies also compromised the systems used for foreign intelligence surveillance.

The US Cybersecurity and Infrastructure Security Agency (CISA) referred questions about the alleged Salt Typhoon network intrusions to the providers.

AT&T, Verizon, and Lumen Technologies declined to answer The Register's inquiries.

A Verizon spokesperson did, however, note that the September 30 outage "was the result of a misconfiguration in our network," and not related to Salt Typhoon or any type of cybersecurity incident.

The Feds and private security analysts are currently investigating the Salt Typhoon breach, including how much and what data the Chinese spies stole, according to the Wall Street Journal.

How the crew gained initial access also remains unclear, although investigators are looking into Cisco routers as a possible entry point, the WSJ said. 

Outdated Cisco and Netgear routers have been previously abused by Chinese espionage gangs to break into US critical infrastructure facilities, prepare for future attacks, and steal sensitive corporate and government data.

Cisco did not immediately respond to The Register's inquiries.

This latest update on the PRC's snooping efforts follows a series of attacks that both government and private investigators have tied to the Chinese government. 

Last month, FBI Director Christopher Wray revealed that law enforcement disrupted a 260,000-device botnet controlled by China's Flax Typhoon. And as recent as August, a different cyberspy gang Volt Typhoon was spotted snooping on American networks.

Wray has repeatedly warned about the national security risk posed by Chinese state-sponsored hacking crews, telling lawmakers that China has "a bigger hacking program than that of every major nation combined, and it has stolen more of our personal and corporate data than every nation big or small, combined," and that there are 50 Chinese cyber-spies for every one FBI analyst. ®

Source: go.theregister.com

Related stories
1 week ago - Expecting a longer storm season this year? Another Beijing-linked cyberspy crew, this one dubbed Salt Typhoon, has reportedly been spotted on networks belonging to US internet service providers in stealthy data-stealing missions and...
2 weeks ago - FBI Director hails successful action but calls it “just one round in a much longer fight.”
12 hours ago - Plus: Google, Oracle, spend $9.5 billion on Asia datacenters; Philippines to tax clouds; Vietnam infosec praised; and more In Brief Chinese authorities have reportedly let local orgs know they should satisfy their need for AI accelerators...
1 month ago - Plus: Trump family X accounts hijacked to promote crypto scam; Fog ransomware spreads; Hijacked PyPI packages; and more Infosec in brief After activating its chameleon field and going to ground following press attention earlier this year,...
1 month ago - No, no, go ahead, don't let us stop you, Xi Cyber-spies suspected of connections with China have infected "dozens" of computers belonging to Russian government agencies and IT providers with backdoors and trojans since late July,...
Other stories
40 minutes ago - This scam uses Google search results to redirect you to scammers instead of Microsoft support. Here's what tech expert Kurt “CyberGuy" Knutsson has to say.
40 minutes ago - Apple's second generation earbuds are significantly discounted during Amazon' October Prime Day event.
40 minutes ago - The Department of Homeland Security says people may not have their Real IDs ready by the current deadline.
40 minutes ago - Content credentials should make it easier to understand where an image came from. They'll also help artists protect their work from AI.
40 minutes ago - Article updated on Oct 8, 2024 You can save for months to come with this shopping strategy. Why You Can Trust CNET Money Our Experts ...