In her remarks, Neuberger confirmed that nine telecommunications providers were impacted by the breaches, adding one more firm to the eight she acknowledged earlier this month. She noted that guidance was given to key U.S. telecommunications firms early on — a “hunting guide” and a “hardening guide” — that detailed Chinese hacking methods and allowed companies to “look for those techniques in their networks and call for help if they discover it.” This led to the determination that a ninth telco provider had been impacted by the same Salt Typhoon breach, alongside Lumen Technologies, AT&T, Verizon and others.
It’s unclear if the Chinese hackers have been fully evicted from all of the U.S. telecommunications networks. Earlier this month, Neuberger said that none of the providers have managed to oust the Chinese hackers from their networks, an assertion that some of the providers, including Lumen and AT&T, have refuted.
Neuberger explained that once Chinese hackers infiltrated telecommunication networks, they essentially had “broad and full access” to American data, which allowed them to “geolocate millions of individuals” and “record phone calls at will.”
It’s unclear how many Americans were impacted by the breach at large, though Neuberger said a large number of individuals were geolocated in the Washington, D.C., area. ”We believe it was the goal of identifying who those phones belong to and if they were government targets of interest for follow-on espionage and intelligence collection of communications, of texts and phone calls on those particular phones.” She added that “probably less than 100” individuals were targeted for collection of their phone calls and texts.
It’s also difficult to adequately track the widespread impact of the incident, Neuberger said, because Chinese hackers are “very careful about their techniques,” and some details of the scope and scale of the campaign may never come to light. She said officials are focusing their efforts on holding China accountable and working with telecommunications companies to refine the “hardening guidance” and make it more difficult for cybercriminals to engage in large-scale hacking campaigns in the future.
“The first step is creating a defensible infrastructure. We wouldn’t leave our homes, our offices unlocked, and yet our critical infrastructure, the private companies owning and operating our critical infrastructure, often do not have the basic cybersecurity practices in place that would make our infrastructure riskier, costlier and harder for countries and criminals to attack,” Neuberger said.
To that end, Neuberger called on the Federal Communications Commission to formalize the new security requirements it proposed for phone carriers earlier this month, and argued that voluntary cybersecurity practices are inadequate to protect against Chinese, Russian and Iranian hacking of U.S. critical infrastructure.