The Register Home Page

back to article FBI cyber cop: Salt Typhoon pwned 'nearly every American'

China's Salt Typhoon cyberspies hoovered up information belonging to millions of people in the United States over the course of the years-long intrusion into telecommunications networks, according to a top FBI cyber official. "There's a good chance this espionage campaign has stolen information from nearly every American," …

  1. beast666 Silver badge

    "There's a good chance this espionage campaign Google has stolen information from nearly every American,"

    1. Anonymous Coward
      Anonymous Coward

      This. Halfway through the article I stopped and went "wait a minute, how much of this information was collected by a domestic megacorp which then Salt Typhoon collected due to their sheer negligence?" We've had so many data breaches from data hoarding companies in the last decade that virtually everything on everyone from their medical records to credit card statements are public information now. I know Salt Typhoon is actively penetrating infrastructure, but I bet the bulk of the information they have on people is simply stuff corporations hoarded in insecure databases. This is like leaving a ton of rotting food out and then blaming the cockroaches infesting your house for your poor living conditions.

      1. Anonymous Coward
        Anonymous Coward

        Don't forget that other article -- Chinese spies are *still* in 'Murrican systems.

        - https://www.theregister.com/2025/08/28/china_salt_typhoon_alert/

        The Chinese attacked US-mandated backdoors. That's how they got in - through the door - that's how they spread, and it was very effective. This should *not* be considered individual corporations' lack of security -- this is a government-mandated failure, one that everyone who uses a computer has spoken vehemently against since the gov. started clamoring for Encryption backdoors.

      2. Anonymous Coward
        Anonymous Coward

        More importantly, the Chinese authorities have no jurisdiction to bang you up for an edgy tweet. So who cares?

  2. VoiceOfTruth Silver badge

    Boo Hoo, America

    How does it feel?

    >> Salt Typhoon collected "bulk information from millions of Americans."

    And the USA collects bulk information from the whole world.

    It would be nice if Jessica Lyons asked Machtinger a few questions, rather than acting as his mouthpiece. You see, if you want to be treated as a serious journalist you should ask difficult questions. Instead what we have here is FBI propaganda.

    The USA is the threat to the world. It is not our friend. Those tariffs are not friendly. We won't forget.

    1. mirachu

      Re: Boo Hoo, America

      "The" threat? "A" threat, I'll give you that.

    2. Anonymous Coward
      Anonymous Coward

      Re: Boo Hoo, America

      What taffifs were collected on American goods by your country in 2024? I presume it wasn't 0%...

    3. Christoph

      Re: Boo Hoo, America

      Quite - how come it took so long to notice the attack, didn't their own spying inside Chinese networks spot anything about it?

      1. trindflo
        Joke

        Re: Boo Hoo, America

        Well yeah, but it was sort of like coventry. We didn't want them to know that we knew, so we just kept the information to ourselves and let them carry on while we occasionally monitored.

  3. DS999 Silver badge

    If everybody is compromised

    Then the horse is out of the barn door. We need to collectively adopt measures that assume my name, address, SSN, mother's maiden name and so forth is out there, and set up methods where I can identify myself that isn't limited to "what I know".

    For instance, I ought to be able to "lock" my credit using 2FA linked to my phone (by that I don't mean SMS) so even if someone gets their hands on my info that they can't open credit cards in my name and I would need to unlock my credit using my phone before I'm able to do that, or take out a mortgage or whatever.

    Maybe this is just the sort of kick in the pants we'll need to eventually move on from this shitty system where if someone knows your SSN they can ruin your life.

    1. Doctor Syntax Silver badge

      Re: If everybody is compromised

      For instance, I ought to be able to "lock" my credit using 2FA linked to my phone (by that I don't mean SMS) so even if someone gets their hands on my info that they can't open credit cards in my name and I would need to unlock my credit using my phone before I'm able to do that, or take out a mortgage or whatever.

      Then your phone gets stolen...

      When your phone becomes your avatar whoever has your phone becomes you.

      1. DS999 Silver badge
        Facepalm

        Re: If everybody is compromised

        If my phone is stolen a crook is not going to be able to use it as the second factor, because he can't unlock it. Or are you assuming it has been stolen by a master criminal specifically because he wants to impersonate me, and has access to Cellebrite level technology so he can unlock an iPhone? Any criminal that capable won't bother with small time credit fraud criming.

        1. druck Silver badge

          Re: If everybody is compromised

          If the criminal asks you nicely to unlock the phone before taking it, with a gun to your head, are you going to refuse?

          That gun toting criminal possibly wont be versed in cybercrime, but he will sell the unlocked phone on to someone who is.

          1. Yougottalaugh

            Re: If everybody is compromised

            They would have to shoot me, or act very quickly since I would put the device in Lost Mode to lock it as quickly as possible. I talked my daughter through this 2 mins after her iPhone was stolen, then through the remote wipe, and then "go to the Apple store and buy a new one and switch Stolen Device Protection on just in case the next their knows your passcode and tell me how much to send you". Sad day - it's not nice having something you value stolen - and expensive Dad day, but I appreciate the data protection feature. To access anything available the phone thief would also need to find and steal my ObiKey. Yes I am that paranoid, its a little inconvenient but better too be safe...

          2. DS999 Silver badge

            Re: If everybody is compromised

            So now I'm supposed to think using a phone as a second factor is a bad idea because I might meet a criminal willing to commit murder to give him access to my phone? All to "impersonate" me and take out credit in my name? To say you're REALLY reaching here is quite the understatement!

            1. druck Silver badge

              Re: If everybody is compromised

              You really think people aren't killed in thefts that net them a few dollars to spend on drugs?

      2. ChrisMarshallNY
        Facepalm

        Re: If everybody is compromised

        It's older than that.

        Many years ago, the film "Taking Care of Business" riffed on the power of the personal datebook:

        https://en.wikipedia.org/wiki/Taking_Care_of_Business_(film)

      3. daysgoby

        Re: If everybody is compromised

        Did they steal my finger prints and head too? If so then I don't think I'm gonna care much about them hacking accounts

    2. PCScreenOnly Silver badge

      Re: If everybody is compromised

      I really hate phones. Only a few people can ring me and even then it is really just 1 person.

      If my phone gets stolen or dies, that is the end - not wanting to replace, but no, these days I to have apps for this that and the other and then MFA - so stop making phones the be all and end all

      *May look at just a data only SIM, but they cost more than a standard SIM, and android really does not like working on a phone device if the phone and SMS apps are removed

      1. Prst. V.Jeltz Silver badge
        Windows

        Re: I really hate phones.

        Your handle reflects that , and its something I can get behind , mainly from a UI pov . Tasks that I could do blindfold on a pc seem impossible on a phone .

        A simple example ( of hundreds) is how do I hover the mouse over an XKCD cartoon to see the bonus punchline?

        I made the URL a link so phone users wont have to fuck about selecting cutting pasting etc etc , another task that I would nt even have attempted on a phone

        It'd be nice to have some sort of luddite icon for those that refuse to leave the command line. Some say even coming down from the trees was a bad idea.

        1. Blazde Silver badge

          Re: I really hate phones.

          It's the clearest example of mass technological regression since Dark Ages Europe forgot how to do clean running water. It's not just that a desktop or even a lightweight laptop/palmtop is so much better than a pokey touchscreen phone, even a very small device with a proper keyboard like a Blackberry makes infinitely more sense. How do you browse the web on a touchscreen phone when basic manipulation of the URI is impossible, there's no real concept of having multiple pages open at once, and nearly every website you try to use wants to run it's own bespoke app?

          It's as if we were happily driving cars then suddenly Segways became a thing and overnight everyone forgot how good cars were.. (Unintentionally ironic analogy seeing as how this appified b.s. *is* now ruining cars as well)

          1. beatboxchad

            Re: I really hate phones.

            The hover for the XKCD image is a long press, and most browsers have tabs too. But to your point, I dislike phone typing, especially in recent years as the predictive autocorrects on most virtual keyboards have gotten so opinionated that they'll substitute entire words for more common ones, five or six times in a row for the same word! It impedes technical conversation, and my healthy blood pressure levels lol.

            On the original topic, I am really sick of [in]security culture and childish war games. America is a class and culture war zone filled with refugees of its practice of burning cultures and ecologies for fuel, and all of the smartest most sensitive people take the brunt of the natural consequences. It's hard to be creative and truly innovate in constant grief, when most everyone left (and anyone with any actual power) is stupid, selfish, shortsighted, petty, and extremely cruel. We are bankrupt. Drugs, bullying, and sexual harassment run every single workplace, nobody trusts each other, nobody can get healthcare or basic living security. The whole thing is a trash fire and a farce. The imperial boomerang is landing hard in America's face right now. Most everyone I like or respect is horrified and scared. Hard to do good creative engineering work in these conditions.

            /rant

            Don't get me wrong, we are living creatures born to thrive and I still have hope for the contingent of our species with a functioning neocortex. The LLM's are pretty cool, and SOME cultures on this planet are still doing good scientific research without committing heinous crimes against humanity and nature. And the phones, though inconvenient, are pretty cool tools for global communication. I'll need to escape the US Southeast (an international cultural treasure, as sick as we are) to rejoin that whole jam session, and my outlook will improve. The insecure war pigs will always set me off tho. They always have.

            1. druck Silver badge
              Unhappy

              Re: I really hate phones.

              I'm glad I'm not the only one noticing how enshittified touch keyboards have become.

              It's happened to me twice; first with Swype which started off with almost telepathic abilities to recognise which word I was after, but slowly descended in to just randomly picking words from the dictionary. I moved to the Samsung keyboard which was never as good in the first place, but again degraded to the level that it can't even get the simplest words in under 6 tries.

              Typing rather than swiping on on screen keyboards is magnitudes slower than the old T9 predictive text on physical number keys - that's today's idea of progress for you.

        2. an it guy

          Re: I really hate phones.

          Um for the xkcd thing, see https://m.xkcd.com

          Then tap the image and the alt text is there. Doesn't always work for the grand fancy xkcds where you really need keys, but otherwise it's good

        3. Anonymous Coward
          Anonymous Coward

          Re: I really hate phones.

          You just long press on the image if you're on Firefox. It wasn't that difficult to figure out.

      2. theDeathOfRats

        About that data only SIM...

        I have one for 1€ a month as a backup. It has (or had, don't know, they keep adding MBs) about a 200MB per month (though the unused allowance goes to the next month's, up to 6 or so). Of course, you can contract for XXGB a month, and the price goes up.

        If you are in Europe I'm pretty sure you can find something similar.

        As for android misbehaving... I didn't have a problem with it, but haven't tried it in one of the recent versions.

    3. Bryan W

      Re: If everybody is compromised

      This why I keep my credit locked. Super lame that I have to go out of MY way to make sure American financial institutions don't commit fraud in MY name on someone else's behalf, and THEY aren't held accountable, but it's better than nothing I guess.

      1. retiredFool Silver badge

        Re: If everybody is compromised

        I locked mine down years ago. All 3 credit agencies. If you are older, you likely aren't opening new accounts all the time so not that inconvenient. If younger, it would be a pain. I also put a pin on my IRS filings. That was another easy scam. File in someone else's name and get a refund leaving them to sort it out with the IRS. I've also a PIN on my cell # so no one can re-assign the number. It is crazy one needs to do all this and probably more not to be scammed in the most trivial attacks.

    4. JoeCool Silver badge

      No worries,

      I'm certain that many western governments have a solution in the waiting - say, a biometrics id platform repurposed from some nefarious intelligence supplier.

      But it will only be used to protect the citizens.

  4. Joe W Silver badge

    Remind me of two things

    1 why did they dismantle the cyber security agency?

    2 Why do they allow companies to collect tons of data? For the telecoms carrier name, address, phone number, email, bank account number should be enough, right? They don't need my sex/gender/kinks/persons in the household/date of birth etc. to be stored indefinitely (dob is important when signing the contract, to check if you are a minor, not needed after that.

    1. Headley_Grange Silver badge

      Re: Remind me of two things

      One of the first things that Trump did in his first term was to refuse to give up his phone for a secure one because, obvs, social media access is more important than national security. When the people running the country have got such attitudes about inconvenience vs security then it's little wonder that the the rest of the country leaks like a sieve.

      1. Taliesinawen Bronze badge

        Re: Remind me of two things

        > One of the first things that Trump did in his first term was to refuse to give up his phone for a secure one

        Not much of a choice being bugged by the NSA or the Chinese MSS (Ministry of State Security).

      2. Gary Stewart Silver badge

        Re: Remind me of two things

        Another thing he did in his first term was to magically declassify over a hundred top secret documents so he could take them home to Mar Lardo and have somebody read them to him, slowly. Luckily for the

        US they were safely and securely stored in bathrooms and on stages. Oh, and gave classifies Israeli information to Vlad. One has to wonder if that was why Kim loved him so much

        At least in his second term he found several people that were more incompetent with secret information than he was(?). Deflection is the name of his game.

    2. Anonymous Coward
      Anonymous Coward

      Re: Remind me of two things

      Also:

      - Allow DOGE to access and copy all those data

      - Menace EU because it has rules to protect citizens' data far better than US

      And of course, the best way to front China is to enrage all your allies with various menaces, insults, tariffs...

    3. daysgoby

      Re: Remind me of two things

      1. Because Putin told Trump that's what he had to do

      2. Because the USA is run by broligarchs

  5. TReko
    Big Brother

    Backdoors bite back

    Salt Typhoon exploited backdoors the US government had forced companies to put in their systems.

    This is the key reason that crypto backdoors are unsafe for everyone. If your own government can spy on you, hackers will hack your government to get that information.

    It will be the EU, UK and Australian citizens' turn next.

    1. Anonymous Coward
      Anonymous Coward

      Re: Backdoors bite back

      Maybe. Or since most, if not all, of those equipment is built in China, the backdoor were planted there. Who knows?

      1. Anonymous Coward
        Anonymous Coward

        Re: Backdoors bite back

        Search for "CALEA"

        1. Taliesinawen Bronze badge
    2. Gary Stewart Silver badge

      Re: Backdoors bite back

      Np, no, no. You don't understand how American politics work. It was the Dems that planted the back doors so they could secretly download very very naughty pictures and buy canned baby, mostly girl babies for some reason, from their basement bunkers under Pizza parlors. I know this to be true because the all seeing eye on my dollar bill told me so. I call him (has to be a him, because) by his initials QA so as to not give the cabal any clues they can use to find him.

      1. Benegesserict Cumbersomberbatch Silver badge

        Re: Backdoors bite back

        Woke! Wowoke! Wowowowowoke!!

    3. trindflo

      Re: Backdoors bite back

      Not what I've seen. I worked at a place that used a service to keep all the on-premise machines running. The service would install some important Microsoft patches, but not most of them. The service would never update firmware. When I took over managing them and reviewed the state of things, I was horrified. The service felt it was in our best interest to make sure they didn't do anything that might impede us...like updating firmware...at least that was their story.

      So rather than backdoors, I propose it is mostly horrible IT practices.

      Based only on the above observations.

  6. Claude Yeller Silver badge

    Record every human

    Nothing new. Intelligence agencies are simply collecting info about every human on earth.

    A database containing the information of all humans and all their contacts and connections is not only valuable for Meta and Google ad networks. It's also valuable for other entities that want to exploit as many humans as possible.

    Intelligence organisations are obvious customers and users of such databases.

    It is very rare when such information is used to the benefit of the subjects.

  7. weladenwow

    "The scale of indiscriminate targeting is unlike what we've seen in the past." saith venerable spokesperson.

    Que?

    Never heard of Prism, eh? or GCHQ? Icould go on ...

    1. Anonymous Coward
      Anonymous Coward

      They just buy already exfiltrated information on the dark web these days. Far more reliable and cheap, let the IABs front the initial effort.

  8. Wang Cores Silver badge

    Oh my frightful goodness, someone should DO SOMETHING

    One question though. Was this before or after;

    - Google

    - Amazon

    - Experian

    - ECHELON (NSA)

    - Paypal

    - Cash App

    - Palantir

    - DOGE

    Got this info?

    1. Gary Stewart Silver badge

      Re: Oh my frightful goodness, someone should DO SOMETHING

      And this is just a partial list. Big Brother(s) is truly with us, for too many people he just hasn't come out of the shadows yet.

    2. Ididntbringacoat

      Re: Oh my frightful goodness, someone should DO SOMETHING

      During.

      And Enduring.

  9. heyrick Silver badge

    The scale of indiscriminate targeting is unlike what we've seen in the past.

    Pot.

    Kettle.

    Black.

  10. Bryan W

    Opt out

    Consumer products are a joke now. Might as well say "Home DDoS Node with some gateway routing features, maybe."

    If you can, get yourself a mini PC with 8GB RAM and low end but workhorse CPU (and at least 2 eth ports of course, more if you want to avoid needing a switch). These are like $150-$200 on Amazon.

    Install opnSense and turn on IPS. Use your old router as a WiFi access point. Maybe think about replacing it one day because I doubt it's WiFi impl isn't full of flaws too.

    Profit. You will have to keep it updated, but at least you have the keys to your own home's network now and aren't just some schmuck left to whims to every botnet campaign targeting the latest flaws.

    1. Anonymous Coward
      Anonymous Coward

      Re: Opt out

      Consumer products have always been crap. That's nothing new. Consumer network gear is a trade off between features and usability...it's not a scam, people buy shit because it's easy to setup and get going.

      I use OPNSense myself, but I'd never recommend it to someone without the knowledge to set it up or maintain it...unless they're paying someone to do it for them or I am doing it for them.

      The main problem with consumer kit isn't the kit itself, it's often fairly good hardware for the price, the problem is the proprietary firmware and shitty operating systems. Consumer routers really ought to be standardised and regulated...we also need legislation that permits the consumers choice of hardware rather than what is foisted upon them by the ISP. Whether an ISP wants to support the router or not is irrelevant, their responsibility should stop at the socket unless they provided the router upon request of the customer.

      I dearly wish I could get rid of my fucking crap Virgin Hub.

      1. Yet Another Anonymous coward Silver badge

        Re: Opt out

        >Consumer products have always been crap

        May I introduce sir to the crap that is a lot of "enterprise" networking gear ?

        1. Anonymous Coward
          Anonymous Coward

          Re: Opt out

          Yeah, but the difference is if you end up with crap enterprise gear, it's because you cut corners and hired a frickin' chump to suggest it and install it. That is simply karma.

          Back in the day, the hallmark of all crappy network engineers was those crappy "stackable" switches by 3COM I think it was, they were called "superstack" I think...they had these massive proprietary connectors on the back with ludicrously thick cable and always needed to be booted in the right order to work. Usually the order the switches were installed in the rack was not the order you needed to power them on because at some point you know the engineer dicked around with it until somehow it worked.

          It was also guaranteed there would be at least one switching loop somewhere with those switches because at some point someone would arrive and not know how those switches work and installed an uplink from each switch to the "primary" switch to try and resolve a network issue, which would work until someone came along and booted everything in the right order...a switching loop just hiding there, like a secret land mine.

  11. Anonymous Coward
    Anonymous Coward

    I'm way more concerned...

    ...about 5 eyes than China.

    My own country spies on me more than any other nation.

    1. Brl4n Bronze badge

      Re: I'm way more concerned...

      look up communism and get back to us

      1. Anonymous Coward
        Anonymous Coward

        Re: I'm way more concerned...

        Yeah but I'm not in China. So if they spy on me, who cares? That's the point.

      2. Anonymous Coward
        Anonymous Coward

        Re: I'm way more concerned...

        Thing is it's difficult for a government to get people to give a shit about foreign nations spying on them when they are also spying on their citizens.

        It's like the school bully beating you to steal your homework and justifying it by saying the Chinese kid sat behind you was looking over your shoulder copying you as well. Both folks are stealing off you, but only one of them is an immediate threat...Chinese kid might be a communist, but it's the kid nearer to you, beating the shit out of you that you need to worry about.

        If your government is also a bully stealing your homework, you have nobody to turn to if the Chinese kid is looking over your shoulder. That's the problem.

        Your government should have no interest in you as long as you're a law abiding citizen and you pay your taxes. They should not be engaging in the same practices as a foreign nation in order to try and stop the foreign nation doing what they're doing...because as far as their citizens will be concerned, if they're going to be spied on no matter what, why should they even care?

        We used to call the practice of providing protection then shaking you down for money and information "racketeering" and it was a criminal offense...these days, it's perfectly acceptable government behaviour it seems.

  12. daysgoby

    return the favor...

    It's about time that the USA returns the favor 10X. I'm not sure why we're so passive about this nonsense

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like