Article Details
Scrape Timestamp (UTC): 2025-01-17 16:10:04.981
Original Article Text
Click to Toggle View
FCC orders telecoms to secure their networks after Salt Tyhpoon hacks. The Federal Communications Commission (FCC) has ordered U.S. telecommunications carriers to secure their networks following last year's Salt Typhoon security breaches. Today's action comes after FCC Chairwoman Jessica Rosenworcel said in early December that the FCC would act "urgently" to require U.S. carriers to secure their systems from cyberattacks. "We now have a choice to make. We can turn the other way and hope this threat goes away. But hope is not a plan," Rosenworcel said on Friday. "In light of the vulnerabilities exposed by Salt Typhoon, we need to take action to secure our networks. The time to take this action is now. We do not have the luxury of waiting." The Commission adopted a declaratory ruling that "takes effect immediately," finding that section 105 of the Communications Assistance for Law Enforcement Act (CALEA) requires telecom companies to secure their networks from communications interception and unlawful access. The FCC also wants to strengthen communications against future cyberattacks by requiring telecoms to submit annual certifications confirming that they have an up-to-date cybersecurity risk management plan. Additionally, it seeks comment on other ways to strengthen the cybersecurity of communications systems and services. "The FCC's Declaratory Ruling and Notice of Proposed Rulemaking is a critical step to require U.S. telecoms to improve cybersecurity to meet today's nation state threats, including those from China's well-resourced and sophisticated offensive cyber program," National Security Advisor Jake Sullivan added. The Salt Typhoon telecom breaches CISA and the FBI confirmed the hacks in late October following reports that the Salt Typhoon Chinese hacking group had breached the networks of multiple telcos, including Verizon, AT&T, and Lumen Technologies. Throughout this campaign, the threat actors accessed the U.S. law enforcement's wiretapping platform and compromised the "private communications" of a "limited number" of U.S. government officials. Anne Neuberger, the White House's deputy national security adviser for cyber and emerging technologies, told reporters that the hackers breached nine U.S. carriers (including Windstream, Charter, and Consolidated Communications) and telecom companies in dozens of other countries. AT&T, Verizon, and Lumen announced on December 30 that they had evicted the Salt Typhoon hackers from their networks. However, this happened after the Chinese hackers accessed targeted individuals' text messages, voicemails, and phone calls. T-Mobile also disclosed in November that unknown attackers breached some of its routers in a network reconnaissance attempt after connecting from a linked wireline provider's network. However, Jeff Simon, the company's Chief Security Officer, didn't link the incident to Salt Typhoon and said T-Mobile's cyber defenses stopped the attack. In response to these breaches, U.S. authorities reportedly plan to ban China Telecom's last active operations in the United States. They're also considering banning TP-Link routers if an ongoing investigation shows their use in cyberattacks poses a national security risk.
Daily Brief Summary
The FCC has mandated U.S. telecom carriers to enhance network security following severe breaches by the Salt Typhoon hacking group.
Chairwoman Jessica Rosenworcel emphasized the urgency of implementing robust cybersecurity measures in light of recent vulnerabilities exposed by state-sponsored cyberattacks.
A new FCC ruling effective immediately under CALEA requires telecoms to secure their networks against unauthorized access and interceptions.
Telecom companies are now required to submit annual cybersecurity risk management plans to demonstrate compliance with new security standards.
The ruling also includes a call for public comment on additional methods to fortify the security of U.S. communications infrastructure.
National Security Advisor Jake Sullivan highlighted the necessity of these measures to counter sophisticated threats from nation state actors like China.
Salt Typhoon breaches impacted several major U.S. telecommunications providers, leading to unauthorized access to sensitive government communications and personal data from officials.
While some incidents linked to network vulnerabilities were managed effectively, such as the attempted breach at T-Mobile, the overall situation highlighted significant national security risks.