Salt Typhoon’s Strategic Pivot: Targeting IT Vendors and Supply Chain
Changing Tides: Salt Typhoon’s Strategic Redirection to IT Supply Chain Attack
A China-nexus espionage group spent years inside the phone carriers, ISPs, and network gear that connect Houston businesses to the world. For a small business, the Salt Typhoon supply chain risk is not the front door. It is the plumbing.
Salt Typhoon is a China-nexus cyber-espionage group that targets telecom carriers, internet providers, and IT vendors rather than end businesses, which means the Salt Typhoon supply chain risk to a Houston SMB runs through the trusted providers it depends on, not through its own firewall.
In September 2024, US officials confirmed that a group tracked as Salt Typhoon had been living inside the networks of major American telecom companies. Not one, not two. On the public record, the list includes Verizon, AT&T, T-Mobile, Lumen, Spectrum, Consolidated Communications, and Windstream. The group had been there, undetected, for what investigators later estimated was one to two years before anyone noticed. The prize was not ransomware or a quick payout. It was quiet, long-term access to the pipes that carry everyone's calls, texts, and data.
This is a different animal from the ransomware gangs most small businesses picture. Salt Typhoon is patient, funded, and interested in information, not extortion. It reportedly reached the systems that carriers use to answer court-ordered wiretap requests, and it pulled metadata tied to more than a million phone users. For a business owner in Katy or Sugar Land, the unsettling part is not that Salt Typhoon wants your invoices. It is that your carrier and your IT vendors are exactly the kind of high-value waypoint this group hunts for, and you inherit their exposure whether you know it or not.
Who Is Salt Typhoon, and How Is It Different From Volt Typhoon?
Salt Typhoon is a telecom-and-IT-vendor espionage group. Volt Typhoon pre-positions inside utilities. They are not the same threat.
Salt Typhoon is a China-nexus espionage actor focused on stealing communications and intelligence by compromising telecom and IT infrastructure, which makes it distinct from Volt Typhoon, a separate Chinese group that quietly pre-positions inside utility and critical-infrastructure systems to be ready for disruption later.
The naming gets confusing fast, so it is worth being precise. On August 27, 2025, CISA, the NSA, the FBI, and allied cybersecurity agencies across the Five Eyes and partner nations released a joint advisory (tracked as AA25-239A) on Salt Typhoon. It attributes the campaign to Chinese state-sponsored actors and estimates that roughly 600 organizations across more than 80 countries were flagged as being of interest. The same actor turns up under other names in vendor reporting: OPERATOR PANDA, RedMike, GhostEmperor, and Earth Estries among them.
Here is the distinction that matters for a Houston business. Salt Typhoon steals. It sits inside telecom networks to collect calls, texts, location metadata, and the sensitive material that flows through communications providers. Volt Typhoon waits. A separate Chinese group, Volt Typhoon uses living-off-the-land techniques to burrow into water, power, and other operational-technology systems, holding access it can use to disrupt if a conflict ever demands it. There is also a third cousin, Silk Typhoon, which is the group Microsoft tied to the March 2025 IT-supply-chain campaign that abused stolen API keys from cloud and managed-service providers. One name family, three very different jobs. If you only remember one thing: Salt Typhoon is about listening, and its road into your business runs through the vendors that carry your traffic.
Why Does Salt Typhoon Target IT Vendors Instead of Businesses Directly?
Because one compromised carrier or IT provider yields access to thousands of downstream customers at once.
Salt Typhoon targets telecom carriers and IT vendors because a single provider sits between thousands of businesses and the internet, so compromising one router at a carrier delivers reach that would take years of individual break-ins to match.
Attacking one small business at a time is slow work. Attacking the company that connects five thousand small businesses is efficient. That is the whole logic of a supply chain campaign, and Salt Typhoon executed it against the layer almost no one thinks about: the network gear itself. According to the August 2025 joint advisory, the group gained initial access largely by exploiting exposed edge devices, including known flaws in Cisco networking equipment tracked as CVE-2018-0171, CVE-2023-20198, and CVE-2023-20273. These are the routers and gateways that live at the boundary of a provider's network.
Once inside, the group did not smash and grab. It targeted the backbone routers of major providers, along with the provider-edge and customer-edge routers that hand traffic off between networks. From there it used trusted connections to pivot from one victim into the networks of others, quietly, for months. When your traffic crosses a router the attacker controls, they do not need to break your firewall. They already sit on the road your data travels. In 35 years around this work, the breaches that scared me most were never the loud ones. They were the ones where the attacker owned a piece of shared infrastructure and simply watched.
- Scale is the point. One backbone router touches the traffic of thousands of businesses; a carrier is a force multiplier no single company can be.
- Network gear is under-monitored. Most organizations watch laptops and servers closely and barely look at the routers and edge appliances Salt Typhoon lives in.
- Trusted connections carry the pivot. The links between provider networks are assumed safe, so lateral movement across them draws little attention.
- Espionage rewards patience. A ransomware crew wants speed; a nation-state actor wants to stay unseen for a year or two and collect.
How Does a Houston Small Business Actually Get Exposed?
Through the carrier that routes your calls, the ISP that carries your data, and the vendors that hold privileged access to your systems.
A Houston SMB gets exposed to Salt Typhoon indirectly, when its telecom carrier, internet provider, or an IT vendor with privileged access is compromised, because the traffic and trust the business hands to those providers becomes a channel the attacker can observe or abuse.
You will never get a Salt Typhoon phishing email. That is what makes this hard to explain to a business owner who is used to thinking about attacks as things that arrive in an inbox. The exposure is structural. Every call your Sugar Land office places, every file your Katy team syncs to the cloud, every remote-access session your outsourced help desk opens crosses infrastructure you do not own and cannot patch. If a nation-state actor is resident in that infrastructure, your sensitive communications are within reach even though your own systems were never touched.
The same logic applies to the IT vendors themselves. A managed provider, a VoIP company, or a remote-support tool holds standing, privileged access into a client's environment. That access is a convenience on a normal day and a liability on a bad one. This is why vendor risk is no longer a paperwork exercise. When Silk Typhoon abused stolen provider API keys to reach downstream customers, and when Salt Typhoon pivoted through carrier networks, both proved the same point: the security of your business now includes the security of everyone you have handed a key to.
What a small business can control is its own posture, built on the assumption that the network beneath it may already be compromised. Encryption makes intercepted traffic worthless. If your calls and data are encrypted end to end, sitting on the wire buys the attacker far less. Segmentation limits the blast radius. If a vendor account is abused, tight network boundaries keep the damage from spreading. Monitoring catches the pivot. Watching for unusual access from vendor accounts and unfamiliar locations is how the quiet lateral movement gets caught. None of this requires owning a telecom carrier. It requires treating your own environment as if the plumbing is hostile.
Do You Know Which Vendors Hold a Key to Your Network?
Most Houston SMBs cannot name every provider with privileged access to their systems. A CinchOps security assessment maps that exposure and shows you where the trust is riskiest.
Explore CinchOps cybersecurity →Compliance sharpens the stakes for regulated Houston firms. A CPA practice under the Gramm-Leach-Bliley Act, a law office guarding privileged client files, or a medical group bound by HIPAA all answer for the confidentiality of data that travels across these same provider networks. Documented vendor-risk management and strong encryption are not just defense against Salt Typhoon. They are the evidence of due diligence a regulator will ask for when communications data is involved.
The hard lesson of Salt Typhoon is that you can do everything right inside your own four walls and still be exposed, because a nation-state parked itself in your carrier. You cannot patch their router. What you can do is encrypt what leaves your building, segment what a vendor can reach, and watch the accounts you handed the keys to. Treat the network under you as if it is already owned, because for a lot of businesses, it quietly was.
Your Vendors Are Part of Your Attack Surface
CinchOps helps Houston-area SMBs manage third-party and supply chain risk: mapping who holds privileged access, hardening network boundaries, enforcing encryption, and monitoring for the quiet lateral movement that nation-state actors like Salt Typhoon rely on. It is part of our cybersecurity and managed IT services.
Explore CinchOps cybersecurity →How CinchOps Helps Your Business
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area.
CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. You cannot audit your carrier's backbone routers, but you can control how much a compromised provider can see or reach. That is where a supply-chain-aware defense pays off. For a Houston SMB worried about Salt Typhoon, that means:
- Vendor and third-party risk mapping. We inventory every provider with privileged access to your environment and rank where the trust is riskiest.
- Encryption everywhere it counts. End-to-end protection for calls, data, and remote sessions so intercepted traffic is worthless to an eavesdropper.
- Network segmentation and least privilege. Tight boundaries that keep an abused vendor account from turning into a full-environment compromise.
- Continuous monitoring for lateral movement. Alerting on unusual access from vendor accounts and unfamiliar locations, the signal Salt Typhoon works hard to hide.
CinchOps serves businesses across Houston, Katy, and Sugar Land, with industry experience in CPA firms, law firms, and oil and gas - the kind of Houston businesses whose communications are worth a nation-state's patience.
Salt Typhoon proved that the provider you trust can become the road an attacker travels. The businesses that come through this best are the ones that stopped assuming the network under them is clean. If you want a clear picture of which vendors can reach your systems and how exposed that leaves you, talk to CinchOps and start with an honest map of your third-party risk.
Frequently Asked Questions
What is Salt Typhoon and why does it matter to a Houston small business?
Salt Typhoon is a Chinese state-sponsored espionage group that compromised major US telecom carriers and internet providers to collect calls, texts, and metadata. It matters to a Houston SMB because the exposure is inherited: the business is reached through the carrier, ISP, or IT vendor it trusts, not through a direct attack on its own systems.
How is Salt Typhoon different from Volt Typhoon?
Salt Typhoon steals information by living inside telecom and IT infrastructure. Volt Typhoon is a separate Chinese group that pre-positions inside water, power, and other operational-technology systems to be ready to disrupt them later. One listens for intelligence; the other waits for a chance to cause damage. They share a naming style but pursue different goals.
Can a small business defend against a nation-state actor in its telecom provider?
Not by patching the provider, which it cannot control. It defends by hardening its own posture: encrypting calls and data so intercepted traffic is worthless, segmenting the network so an abused vendor account cannot spread, and monitoring for unusual access. The strategy is to assume the network beneath the business may already be compromised and limit what that costs.
Discover More
Sources
- CISA/NSA/FBI and allied agencies, Joint Advisory AA25-239A: Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide (August 27, 2025)
- Microsoft Threat Intelligence, Silk Typhoon Targeting IT Supply Chain (March 5, 2025)
- The Hacker News, Salt Typhoon Exploits Edge Device Flaws to Breach 600 Organizations Worldwide
- Congressional Research Service, Salt Typhoon Hacks of Telecommunications Companies and Federal Response Implications