Cybersecurity Policy Report, U.S., Allies Offer Salt Typhoon Update Amid Lingering ‘Information Gap’, (Aug 27, 2025)
Organizations Mentioned:Federal Bureau of Investigation

Cyber defense agencies from the U.S. and 12 allied nations today provided a significant update about the cyber espionage campaign known as Salt Typhoon and offered new security recommendations informed by government and private-sector investigations, but they admitted that their knowledge of the effort remained incomplete.
Attributed to the government of the People’s Republic of China (PRC), Salt Typhoon is one of several “typhoon” cyber threat groups that seek to penetrate critical infrastructure, and the joint cybersecurity advisory published today suggests that the groups have overlapping goals.
Salt Typhoon, for example, targeted telecommunications networks, but data gleaned from those networks can be used in other cyber espionage campaigns targeting transportation or lodging, giving the Chinese government “the capability to identify and track their targets’ communications and movements around the world,” the advisory says.
Previous Salt Typhoon advisories offered scant details on the hackers’ tactics, and the latest one acknowledges that investigators remain uncertain about how the attackers gain their initial foothold in a system. “Initial access vectors remain a critical information gap for parties working to understand the scope, scale, and impact of the actors’ malicious activity,” it says.
It notes, however, that the hackers appear to be having “considerable success” exploiting known vulnerabilities rather than relying on unknown “zero-day” vulnerabilities. It advises organizations to prioritize the patching of known vulnerabilities that are being actively exploited.
The advisory also cautions that evicting the “advanced persistent threat” (APT) known as Salt Typhoon should be done carefully.
“The malicious activity described in this advisory often involves persistent, long-term access to networks where the APT actors maintain several methods of access. Network defenders should exercise caution when sequencing defensive measures to maximize the chance of achieving full eviction,” it says.
“Where possible, gaining a full understanding of the APT actors’ extent of access into networks followed by simultaneous measures to remove them may be necessary to achieve a complete and lasting eviction. Partial response actions may alert the actors to an ongoing investigation and jeopardize the ability to conduct full eviction,” it warns.
“The APT actors often take steps to protect their established access, such as compromising mail servers or administrator devices/accounts to monitor for signs that their activity has been detected. Organizations should take steps to protect the details of their threat hunting and incident response from APT actor monitoring activities,” the advisory adds.
The advisory names three Chinese companies that it says are linked to the APT, including Sichuan Juxinhe Network Technology Co. Ltd., Huanyu Tianqiong Information Technology Co. Ltd., and Sichuan Zhixin Ruijie Network Technology Co. Ltd. “These companies provide cyber-related products and services to China’s intelligence services, including multiple units in the People’s Liberation Army and Ministry of State Security,” it says.
“The recommended mitigations in this joint advisory include patching known exploited vulnerabilities (KEVs), enabling centralized logging, and securing edge infrastructure. These steps are critical to reducing the risk of compromise and ensuring the resilience of systems that underpin national and economic security,” according to a news release from the Cybersecurity and Infrastructure Security Agency, one of the advisory’s authors.
“CISA and our partners are committed to equipping critical infrastructure owners and operators with the intelligence and tools they need to defend against sophisticated cyber threats,” said Madhu Gottumukkala, CISA’s acting director. “By exposing the tactics used by PRC state-sponsored actors and providing actionable guidance, we are helping organizations strengthen their defenses and protect the systems that underpin our national and economic security.”
“PRC threat actors thrive in the shadows,” said Brett Leatherman, head of the Federal Bureau of Investigation’s cyber division. “Together with our government and private sector partners we defend the homeland by shining a light on their activity and undermining the tactics and infrastructure they rely on.”
In a video posted on the FBI’s website, Mr. Leatherman suggested that global cyber investigators had more work to do to unravel the Salt Typhoon campaign and evict the hackers. “Today’s release is a milestone in the Salt Typhoon story,” he said. “But the story isn’t finished. We will keep pressing forward until those responsible are brought to justice.”
MainStory: TopStory FederalLegislation InternationalLegislation DataSecurity