Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Salt Typhoon topic
No spam. Unsubscribe anytime.
Congressional panel hears on 'SALT Typhoon' breach as telecom security priority
Summary
Witnesses and members described last fall's SALT Typhoon cyber campaign as an extensive, government‑backed espionage operation that infiltrated multiple U.S. telecommunications networks and spurred calls for greater public‑private collaboration, sustained funding and improved information sharing.
Get email alerts on the Cybersecurity Salt Typhoon topic
No spam. Unsubscribe anytime.
House Energy and Commerce subcommittee members and witnesses on May 14 focused the hearing on SALT Typhoon, a Chinese‑linked cyber espionage operation that federal officials have said compromised multiple U.S. telecommunications providers. The panel’s witnesses described the operation as broad in scope and said it exposed persistent gaps in detection, response and government‑industry coordination.
The subcommittee’s chair, Representative (Chair) and ranking member Doris Matsui opened the hearing describing SALT Typhoon as “one of the worst hacks in U.S. history” and urged stronger protections for communications infrastructure. Laura Galante, former intelligence community cyber executive and director of the Cyber Threat Intelligence Integration Center at the Office of the Director of National Intelligence, told the panel SALT Typhoon “was first publicly detailed last fall in 2024” and that the FBI had confirmed at least nine U.S. telecom companies were affected.
Why it matters: telecommunications networks carry voice, metadata and other signals that underpin government, commercial, and emergency communications. Witnesses warned that the combination of broad access to multiple carriers, advances in artificial intelligence for data analysis and delays in detection raise the risk that adversaries can both harvest intelligence and position capabilities for future disruptive activity.
Jamil Jaffer, founder and executive director of the National Security Institute, told members the incident was “not just the communications of specific high target individuals” but a broad, persistent capability that enabled long‑term intelligence collection. He warned that stolen records may include content and law‑enforcement request data and said those holdings could be shared among adversaries.
Industry witnesses emphasized the limits of private companies acting alone. David Stalen, chief executive officer of the Telecommunications Industry Association, said defense‑in‑depth and supply‑chain verification are needed and noted his organization’s SCS 9,001 supply chain security standard as an industry response. Witnesses and members repeatedly called for speedy, routine information sharing between federal agencies and the private sector to improve detection and response times.
Several members and witnesses expressed concern about federal reorganizations and funding decisions that they said have reduced collaborative incident‑response capacity. Galante, who led the unified coordination group for the government response to SALT Typhoon, said boards and joint bodies — such as the Cyber Safety Review Board and enduring security frameworks that paired government and industry practitioners — had been useful in prior investigations and their reduction or dissolution hampers cross‑sector learning.
Members also raised the question of accountability and deterrence. Witnesses urged clearer national positions on penalties and coordinated consequences for state actors that conduct destructive or persistent espionage against U.S. infrastructure.
The hearing produced no formal actions or votes. Members asked witnesses to provide additional evidence and to respond to written questions for the record.

