Source PacketCollectionsSource PacketsOfficial Source

Salt Typhoon And Telecommunications Defensive Source Note

Salt Typhoon now has a dedicated telecommunications defensive source lane in the corpus. The accessible official record in this pass supports three safe conclusions:

Full Index

UNCLASSIFIED//OPEN SOURCE

Source Packet ID: WI-SOURCEPACKET-SALT-TYPHOON-TELECOM-2026-0001

Prepared UTC: 2026-06-17T21:06:51Z

Information cutoff UTC: 2026-06-17T21:06:51Z

Source base: U.S. Department of the Treasury January 17, 2025 Salt Typhoon sanctions press release; Department of State Rewards for Justice foreign malicious cyber activity against U.S. critical infrastructure reward page; U.S. Senate Committee on Commerce, Science, and Transportation February 3, 2026 Salt Typhoon telecommunications oversight page; CISA, NSA, FBI, and FCC public source-family routes with access notes from the 2026-06-17 direct verification pass; ODNI 2026 Annual Threat Assessment; existing WARLOCK-INDEX PRC cyber and critical-infrastructure defensive source packet, China/PLA source tracker, official U.S. register, U.S. intelligence and law-enforcement register, official U.S. threat-source matrix, global actor-domain matrix, coverage map, and China actor profile.

Analytic confidence: High for the Treasury sanctions release identity, the Rewards for Justice critical-infrastructure cyber reward route, and the Senate Commerce oversight page identity. Moderate for Salt Typhoon telecommunications scope and remediation status because the most current official advisory, FBI, CISA, NSA, and FCC source-family pages either returned access barriers, generic search results, or timeouts in this environment, and some current claims are carried by congressional oversight language until primary advisory pages are directly refreshed. Low for any technical, provider-specific, victim-specific, network-architecture, or current-intrusion status claim not directly supported by an accessible official page.

Purpose: Convert the queued Salt Typhoon telecommunications lane into a safe source note that separates sanctions, reward, congressional oversight, cyber-advisory, telecom-regulatory, and intelligence-assessment source families without reproducing exploit paths, indicators, router guidance, lawful-intercept detail, provider-specific vulnerabilities, or incident- response procedures.

Boundary: Defensive strategic source organization only. This note does not provide cyber operations guidance, exploit steps, commands, indicators, vulnerability lists, malware behavior, router configuration guidance, lawful- intercept system detail, victim identification, provider-specific security findings, network diagrams, incident-response playbooks, telecommunications engineering advice, sanctions-evasion guidance, investigative direction, or operational guidance.

Bottom Line

Salt Typhoon now has a dedicated telecommunications defensive source lane in WARLOCK-INDEX. The accessible official record in this pass supports three safe conclusions:

  1. Treasury publicly associated Salt Typhoon with compromises of multiple major U.S. telecommunication and internet-service-provider networks and sanctioned a named company it described as directly involved in those compromises.
  2. Rewards for Justice maintains a broader State Department source route for information about foreign malicious cyber activity against U.S. critical infrastructure.
  3. Senate Commerce oversight material dated February 3, 2026 keeps Salt Typhoon remediation, network-security verification, provider transparency, FCC action, and joint-advisory source routing in the live public oversight record.

This note does not adjudicate current provider security, active access, victim counts, technical exploitation, or remediation sufficiency. It records where those claims should be sourced and what must remain out of the corpus.

Source Ledger

Source familyPublisherDate or access statePrimary valueLimits
Treasury Salt Typhoon sanctions releaseU.S. Department of the Treasury / OFACPublished 2025-01-17; accessed 2026-06-17Official U.S. sanctions source for Yin Kecheng, Sichuan Juxinhe Network Technology Co., Ltd., Treasury network compromise framing, and Salt Typhoon telecommunications-infrastructure compromise framingSanctions source; not a complete cyber-incident report, technical advisory, victim inventory, or remediation assessment
OFAC recent-action routeOFACLinked by Treasury release; direct route not verified in this passFollow-on route for designation detail tied to the Treasury releaseDo not summarize direct OFAC entry until page-level access succeeds
Rewards for Justice critical-infrastructure cyber reward pageDepartment of State / Rewards for JusticeAccessible 2026-06-17; dynamic pageOfficial reward-source route for foreign malicious cyber activity against U.S. critical infrastructureBroad reward page; not Salt Typhoon-specific by itself in this pass and not a technical source
Senate Commerce Salt Typhoon oversight pageU.S. Senate Committee on Commerce, Science, and TransportationPublished 2026-02-03; modified 2026-04-07; accessed 2026-06-17Official congressional oversight source for AT&T/Verizon transparency requests, Mandiant assessment requests, FCC rule references, and references to FBI/joint-advisory statementsOversight source and congressional interpretation; primary FBI, FCC, and joint-advisory pages still need direct refresh
CISA cybersecurity advisories source familyCybersecurity and Infrastructure Security AgencySearch/advisory routes returned Akamai access denied on 2026-06-17Primary intended source family for defensive joint advisories and telecommunications hardening guidancePage-level advisory extraction incomplete; no technical details copied
NSA cybersecurity advisories and guidance source familyNational Security AgencySource route returned Akamai access denied on 2026-06-17Joint advisory mirror and cyber-defense source familyPage-level extraction incomplete; no technical details copied
FBI cyber source familyFederal Bureau of InvestigationSearch route returned Cloudflare challenge on 2026-06-17FBI cyber, investigative, actor-warning, and public reporting routeSearch access incomplete; use only as source-family route until direct page succeeds
FCC Salt Typhoon / telecommunications cybersecurity routeFederal Communications CommissionSearch route produced HTTP/2 error and HTTP/1.1 timeout on 2026-06-17Telecom-regulatory and CALEA/network-protection policy source familyNot verified in this pass; use Senate page only for current congressional oversight references
ODNI 2026 Annual Threat AssessmentOffice of the Director of National IntelligenceRepository source family already activeStrategic IC framing for PRC cyber threat and critical-infrastructure riskSummary public IC assessment; no technical or provider-specific extraction
PRC cyber defensive source packetWARLOCK-INDEXExisting dated packetParent source-treatment lane for PRC cyber, critical infrastructure, CISA/NSA/FBI source routing, DOJ events, and PRC issuer-source separationInternal derived source organization; later direct official pages supersede it

Source Separation Matrix

Claim familyFirst source laneCross-check before stronger claimWARLOCK-INDEX treatment
Salt Typhoon as a named telecom-compromise source laneTreasury sanctions releaseCISA/NSA/FBI joint advisory pages; ODNI; Senate oversight; allied advisory pagesOfficial U.S. source lane, not a complete actor dossier
Sanctioned persons or entitiesTreasury release; OFAC recent-action routeOFAC SDN/current sanctions list if exact status is neededLegal-public source status; no sanctions-evasion discussion
Telecommunications provider remediation statusSenate Commerce oversight pageProvider disclosures, FCC docket/release pages, CISA/FBI/NSA advisories, independent audit or congressional records where publicMark as contested/oversight source until primary evidence is direct
Scope across U.S. organizations and countriesSenate Commerce page attribution to FBI and advisory materialPrimary FBI and joint-advisory pagesUse only as congressional-source reporting until primary official pages are accessible
Critical-infrastructure reward routeRewards for Justice page; Treasury cross-linkState/RFJ updates and DOJ/FBI source eventsBroad reporting-source route; do not include tip-channel mechanics
Telecom regulatory actionSenate Commerce page references to FCC actionFCC orders, declaratory rulings, NPRM, rescission pages, Federal RegisterRegulatory-source queue; do not infer cybersecurity sufficiency from policy action alone
Defensive advisory contentCISA/NSA/FBI source familiesAllied advisory mirrors and sector agenciesHigh-level source metadata only; no IOCs, CVEs, commands, or device guidance
Intelligence threat framingODNI 2026DoD, CISA/NSA/FBI, Treasury, allied agenciesStrategic threat frame; no classified inference

Safe Extraction Rules

  1. Extract only publisher, publication date, access date, title, source family, actor label, sector lane, and high-level warning or oversight theme.
  2. Do not copy indicators, vulnerability IDs, commands, device models, router guidance, lawful-intercept system details, provider-specific architecture, victim names, or technical remediation procedures.
  3. Treat Senate oversight language as congressional-source evidence until the referenced FBI, FCC, CISA, NSA, and joint-advisory pages are directly refreshed.
  4. Treat Treasury sanctions material as official legal-public status and attribution language, not as a complete technical incident timeline.
  5. Treat Rewards for Justice as a reporting/reward source family and do not reproduce tip-channel mechanics.
  6. Keep telecommunications as an infrastructure-sector lane; do not create provider vulnerability maps, network diagrams, or readiness rankings.

Telecom Defensive Routing

Routing laneUseFollow-on evidence neededBoundary
Sanctions and attributionTreasury / OFACOFAC current sanctions entry; DOJ/FBI where publicNo sanctions-evasion guidance or private-person dossiering
Critical-infrastructure rewardRewards for JusticeState/RFJ update log if availableNo operational reporting-channel mechanics
Congressional oversightSenate CommerceHearing record, witness testimony, provider responses, committee lettersOversight record is not a technical audit
Advisory source refreshCISA, NSA, FBI, allied cyber agenciesDirect advisory pages, dates, titles, agency listNo technical extraction
Telecom regulationFCCOrders, declaratory ruling, NPRM, rescission, Federal RegisterNo legal advice or network-engineering advice
Intelligence frameODNI 2026Later ATA, agency testimony, public advisoriesNo classified inference
Sector riskCISA sector and telecom sourcesSector risk-management pages and public telecom cyber guidanceNo provider-specific vulnerability mapping

Follow-On Queue

ProductPurposePrimary source families
Salt Typhoon Advisory Page-Level RefreshCapture exact CISA, NSA, FBI, and allied advisory titles, dates, co-seal agency lists, and access notes without technical detailCISA, NSA, FBI, allied cyber agencies
FCC Telecommunications Cybersecurity Source RefreshCapture FCC orders, declaratory rulings, NPRM, rescission, and Federal Register routes tied to Salt Typhoon and CALEA/network-security policyFCC, Federal Register, Senate Commerce
OFAC Salt Typhoon Designation RefreshCapture current OFAC recent-action and SDN status for designated individuals/entitiesTreasury, OFAC
Senate / Congressional Oversight PacketCapture letters, hearings, testimony, and provider-response source routingSenate Commerce, House Homeland Security, provider public filings where source-classed
Allied Telecom Cyber Cross-CheckCapture allied cyber-agency mirror advisories and telecom-sector warningsUK, Canada, Australia, New Zealand, Japan, EU/NATO cyber agencies

Information Gaps

  • CISA and NSA direct pages returned access denied in this environment; exact advisory routes, titles, dates, and co-seal agency lists still require a later page-level refresh.
  • FBI direct search returned a Cloudflare challenge, so FBI statements cited by Senate Commerce should not be treated as directly captured FBI text.
  • FCC source routes timed out or errored in this environment; FCC orders and dockets need a separate verification pass.
  • Treasury's OFAC recent-action link remains a follow-on direct-route capture even though the Treasury press release itself was accessible.
  • Public sources cannot prove active access, complete victim lists, current remediation status, provider-specific security posture, or classified intelligence judgments.

Cross References

Source Base

  • U.S. Department of the Treasury, Treasury Sanctions Company Associated with Salt Typhoon and Hacker Associated with Treasury Compromise: https://home.treasury.gov/news/press-releases/jy2792
  • Rewards for Justice, Foreign Malicious Cyber Activity Against U.S. Critical Infrastructure: https://rewardsforjustice.net/rewards/foreign-malicious-cyber-activity-against-u-s-critical-infrastructure/
  • U.S. Senate Committee on Commerce, Science, and Transportation, Cantwell Demands AT&T, Verizon CEOs Come Clean on Salt Typhoon Hacks, Ongoing Network Security Risks: https://www.commerce.senate.gov/press/dem/release/cantwell-demands-att-verizon-ceos-come-clean-on-salt-typhoon-hacks-ongoing-network-security-risks/
  • Cybersecurity and Infrastructure Security Agency, cybersecurity advisories source family: https://www.cisa.gov/news-events/cybersecurity-advisories
  • National Security Agency, cybersecurity advisories and guidance source family: https://www.nsa.gov/Press-Room/Cybersecurity-Advisories-Guidance/
  • Federal Bureau of Investigation, cyber source family: https://www.fbi.gov/investigate/cyber
  • Federal Communications Commission, public source family: https://www.fcc.gov/
  • Office of the Director of National Intelligence, Annual Threat Assessment of the U.S. Intelligence Community 2026: https://www.dni.gov/files/ODNI/documents/assessments/ATA-2026-Unclassified-Report.pdf