
The Federal Bureau of Investigation (FBI) announced on Friday a $10 million reward for information leading to the identification or disruption of Salt Typhoon, a China-backed hacking group accused of targeting several major U.S. telecommunications companies and the U.S. Treasury Department. The agency emphasized that it is particularly seeking intelligence that could expose the individuals orchestrating these operations or shed light on the group’s activities within the telecommunications sector.
According to the FBI, Salt Typhoon has conducted a "broad and significant cyber campaign," leveraging its access to critical networks to carry out attacks on a global scale. Identified as an advanced persistent threat (APT) group with links to the Chinese government, Salt Typhoon has drawn significant concern from cybersecurity experts and government agencies alike.
The group’s operations first came to widespread attention in September of last year when U.S. authorities revealed that Salt Typhoon had infiltrated the networks of several major U.S. telecom providers, including Verizon, AT&T, T-Mobile, and Lumen Technologies. The FBI reported that the hackers accessed call data logs, a limited amount of private communications, and select information that was subject to court-ordered law enforcement requests.
Among the victims of these breaches were high-profile political figures. The FBI disclosed that the group targeted the phone records of then-President-elect Donald Trump, his vice-presidential running mate Senator JD Vance of Ohio, and staffers from Kamala Harris’s campaign team, in the lead-up to the 2024 presidential election.
The FBI expressed alarm over the duration and depth of the intrusions, noting that PRC-linked threat actors had been embedded within several telecom providers for an undetermined period and may still be present. Salt Typhoon’s use of sophisticated anti-forensic and anti-analysis techniques reportedly enabled the group to operate undetected for months. Intelligence assessments suggest that Salt Typhoon has been active since at least 2020.
Also tracked under the names GhostEmperor and FamousSparrow, Salt Typhoon’s activities are viewed as part of a broader Chinese strategy to penetrate and compromise U.S. critical infrastructure. Beijing has consistently denied involvement in any of these activities.
In addition to the telecom breaches, Salt Typhoon has been implicated in a cyberattack on the U.S. Treasury Department earlier this year, where hackers gained unauthorized access to the laptops of senior officials.
To encourage public cooperation, the FBI posted notices on social media platform X, in both English and Chinese, urging anyone with information about Salt Typhoon to come forward. Reports can be submitted to the FBI’s Internet Crime Complaint Center (IC3) or through local FBI field offices.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543