Chinese hackers were able to breach US National Guard and stay undetected for months
- The Department of Homeland Security says Salt Typhoon accessed National Guard systems
- Hackers were present between March and December 2024
- The group stole vital intelligence and personally identifiable information
A Chinese state-sponsored threat actor known as Salt Typhoon was lurking in the network of the US Army National Guard for nine months, the US Government has confirmed.
TheDepartment of Homeland Security (DHS) said the attackers were present in the networks between March and December 2024.
During this time, the group stole sensitive data from its victims, including administrator credentials, network traffic diagrams, geographical maps, and personally identifiable information (PII) of service members. Furthermore, the attackers accessed data traffic between the state’s network and every other US state, and at least four additional territories. This means that they could have pivoted to other networks as well, compromising even more government and military targets.
Typhoon over America
It was not discussed how the breach happened, but DHS did say the group was known for exploiting existing vulnerabilities (CVEs) in Cisco’s routers and similar hardware.
Salt Typhoon is a known Chinese state-sponsored threat actor, part of the wider “typhoon” organization that includes groups such as Brass Typhoon, Volt Typhoon, and others.
These organizations were tasked with infiltrating different core organizations within the US, such as critical infrastructure organizations, communications firms, government, military, and defense organizations, and similar.
The goal of the campaign was to be present inside the networks should tensions between the US and China over Taiwan escalate into a full-blown war, giving it the ability to disrupt networks, and steal key intelligence.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Salt Typhoon is often in the media – with recent attacks against the likes of AT&T, Verizon, Lumen, Charter, Windstream, and Viasat, to name a few, often abusing unpatched Cisco routers to gain access, before deploying custom malware such as JumblePath and GhostSpider.
Via BleepingComputer
You might also like
The Department of Homeland Security says Salt Typhoon accessed National Guard systems Hackers were present between March and December 2024 The group stole vital intelligence and personally identifiable information A Chinese state-sponsored threat actor known as Salt Typhoon was lurking in the network of the US Army National Guard for…
Recent Posts
- This HP Omen 16 deal with RTX 5050 graphics is a steal for video editing — and I can’t find it cheaper anywhere else
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
- How to watch France vs Ivory Coast: FREE streams, TV channels for World Cup 2026 warm-up
- Cash App made a magic wand for contactless payments
- Wave Cash App’s Magic Wand to Pay for Stuff
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023