Skip to content
Flash Briefing critical Communications

Salt Typhoon Access Persists in European Telecoms More Than a Year After Initial Disclosure

Fourteen months after US carriers confirmed the intrusions, Salt Typhoon still has active access inside at least two major European telecoms networks. Intelligence assessments shared with European regulators in April 2026 make that clear. The access has not been remediated. The operators are working on it, with national intelligence agencies and ENISA, but they are not done.

What made the original US campaign notable wasn’t the scale, though the scale was significant. It was the target. Salt Typhoon went after the lawful intercept infrastructure. Not billing data. Not subscriber records. The actual surveillance apparatus: the technical systems that allow law enforcement and intelligence agencies to access call content, SMS, and metadata on specific targets under legal authorisation.

What That Access Actually Means

Every major carrier in a regulated jurisdiction runs a lawful intercept capability. CALEA in the US. The Investigatory Powers Act framework in the UK. Equivalent regimes across Europe. These systems exist because regulators require them, and they are by design accessible to law enforcement with the appropriate legal process.

Salt Typhoon gained access to those systems. For a period, Chinese intelligence had visibility into which individuals Western agencies were actively monitoring. Not the content of every call. The surveillance targeting list. Who law enforcement and intelligence services considered important enough to watch.

The long-term damage here isn’t primarily technical. It’s intelligence damage. Even after the access is fully closed, the knowledge of who was under surveillance (and therefore what Western agencies knew and didn’t know at specific points in time) cannot be un-shared. Sources and methods exposure of this kind takes years to fully assess and potentially longer to mitigate.

European Carriers Are Not Spectators

The two European carriers affected have not been publicly named. Both are notified and in active remediation. The entry point, consistent with the US campaign pattern, appears to be internet-facing network edge equipment with known but unpatched vulnerabilities: management interfaces that had available patches and didn’t have them applied.

The same vulnerability class. The same technique. Across a different continent, more than a year after the US disclosures gave every carrier in the world an explicit reason to audit these systems.

That’s the operational picture telecoms security teams are dealing with: an adversary patient enough to maintain long-term access, targeting infrastructure that operators have structural reasons to leave connected and partially exposed, in an environment where remediation requires coordination between the carrier, national intelligence agencies, and equipment vendors.

Three Questions for Telecoms Leadership

Senior leadership at any telecoms operator should be in front of their CISO this week with three specific questions:

First: have all network edge devices, specifically those adjacent to or involved in lawful intercept infrastructure, been audited against the Salt Typhoon IOCs published in CISA advisory AA24-338A? Not “scheduled for audit.” Done.

Second: is access to lawful intercept systems logged, and are those logs stored in an environment that would survive compromise of the main carrier network?

Third: have the confidential sector briefings available through NCSC and NCA been received and acted on? Not just received.

Patch management on network edge equipment is the primary available defensive action. That sounds like a basic point. The European intrusions described above suggest it still isn’t being treated as one.