Noah MitchellVIEW PROFILE →
The Spies in the Wires: How China's Salt Typhoon Quietly Breached Canada's Telecom Networks
Some of the most dangerous cyberattacks are the ones you never notice. That is the nature of Salt Typhoon, a Chinese state-sponsored operation that has wormed into telecom networks worldwide, including in Canada. The Cyber Centre and the FBI have warned that intruders compromised a Canadian telecom
When people picture a devastating cyberattack, they often imagine locked screens, ransom demands and chaos. But some of the most dangerous intrusions are the ones you never notice at all. That is precisely the nature of Salt Typhoon, a Chinese state-sponsored hacking operation that has quietly wormed its way into telecom networks around the world, including here in Canada.
A warning from the top
The alarm has been raised at the very highest levels. Canada's Cyber Centre, the country's national authority on cybersecurity, has joined forces with the United States' FBI to warn about the threat posed by a group tracked in the industry as Salt Typhoon, which is directly linked to the People's Republic of China.
What sets this campaign apart from ordinary cybercrime is its fundamental purpose. This is not about quick financial gain, but about long-term espionage. The goal is to sit silently inside critical communication systems, listening, watching and gathering intelligence, sometimes for many months on end without ever being detected.
How they got in

The Canadian angle became disturbingly concrete in early 2025. According to the Cyber Centre, three network devices registered to a Canadian telecommunications company were compromised by actors likely tied to Salt Typhoon in the middle of February that year, marking a clear escalation of the threat on home soil.
The break-in relied on a known weakness in networking equipment rather than some exotic new technique. The attackers exploited a critical vulnerability in Cisco software, a flaw that allowed remote, unauthenticated intruders to create their own accounts and grant themselves administrator-level privileges, effectively handing them the keys to the system.
This particular detail carries an uncomfortable lesson for defenders. The vulnerability they used was already publicly documented, underlining how unpatched or overlooked equipment can quietly become an open door, even inside the sophisticated networks that carry a nation's most sensitive communications every single day.
What the spies were after
Once inside, the hackers did not always behave in the same way. In some cases, they appeared content simply to map out the architecture of the networks they had entered, quietly cataloguing the weaknesses and layouts that could be exploited in some future operation further down the line.
In other cases, however, the intent was far more aggressive and immediate. The intruders managed to steal actual call records and private communications belonging to high-value targets, a group that reportedly included government employees and political figures whose conversations would be of obvious interest to a foreign intelligence service.
That distinction matters enormously in practice. A stolen credit card can be cancelled, but intercepted phone records and private messages of officials can reveal sources, strategies and relationships, offering a foreign power a detailed map of a country's inner workings that simply cannot be reset or undone afterwards.
A threat that is not going away
Perhaps the most sobering part of the whole warning is its outlook for the future. Security professionals at the Cyber Centre believe these incursions will not stop any time soon, and they expect them to continue for at least the next two years, with telecom providers and their many clients firmly in the crosshairs.
The threat also appears to reach well beyond phone companies alone. The Cyber Centre has found overlaps with malicious indicators associated with Salt Typhoon that strongly suggest the targeting is broader than just the telecommunications sector, hinting at a much wider web of potential victims across other industries.
For ordinary Canadians, the real takeaway here is not panic but awareness. Most people will never be a direct target of a state espionage campaign, yet everyone relies on the same telecom backbone, which means the security of these networks is ultimately a matter of national, and deeply personal, concern for all.
Salt Typhoon is a stark reminder that the most serious cyber threats are not always loud or dramatic. Sometimes they are patient, invisible and coldly strategic, hiding in the very wires that connect us to one another. Defending against them will require not a single quick fix, but a sustained and vigilant effort for many years to come.






