In short
The BBC Global Story episode explains the Salt Typhoon Chinese intelligence hack, uncovered in 2024, that compromised US telecom infrastructure and could have enabled espionage against policymakers and potentially “nearly every American,” even if communications were encrypted.
Guests and backgrounds
Anne Neuberger, former Deputy National Security Advisor under President Joe Biden, previously led cybersecurity in the White House. Joe Tidy, BBC cyber correspondent.
Key claims
Neuberger says telecom compromise could have gone undetected up to three years, turning telecom systems into an espionage platform. She describes three data types: sensitive phone calls, location/targeting via cell-tower data, and communications of people monitored by the US. She warns encrypted data could be decrypted later if quantum computers arrive, and says the US briefed the president, allies, and the press; she also discusses sanctions on Chinese firms tied to the hack. Tidy argues the attacks are ongoing in practice and compares the scale to “China doing a Snowden on America,” while noting all states run cyber espionage.
Notable examples
Potential interception of unencrypted calls (e.g., calls not using Signal/WhatsApp); tracking “persons of interest” across the US; references to US sanctions before Trump’s inauguration; comparisons to PRISM and mentions of cyber activity possibly supporting attacks on Venezuela and Iran.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOIntro to the Cyber-Attack
0:44 to 0:57
An introduction to the implications of a major Chinese cyber-attack.
“teens can gain hands-on investing experience and build positive money habits.”
Intro to the Cyber-Attack
1:00 to 2:39
An introduction to the implications of a major Chinese cyber-attack.
“Imagine you're an up-and-coming politician in the United States.”
Interview with Anne Neuberger
2:39 to 5:04
Anne Neuberger discusses the scale and impact of the hack.
“To understand the scale of the Salt Typhoon hack, we turn to someone who was right in the thick of it.”
Understanding Espionage and Detection
5:04 to 7:48
Insights into how the hack was detected and the difference between state actors and criminals.
“And hence the conversations that they carry could be of interest to a foreign government as well.”
Sensitive Data Stolen
7:48 to 9:50
Discussion on the types of sensitive information potentially compromised.
“The dream of intelligence operations is to collect intelligence for as long as absolutely possible.”
Responses and Reactions
9:50 to 11:45
Exploring the reactions of the U.S. government and allies to the hack.
“It was a broad swath of Americans and by that matter, other citizens around the world, communications that was available to them to collect.”
Long-Term Consequences of the Hack
11:45 to 14:00
Examining the potential long-term implications of the data breach.
“And I know at some point later, you all also briefed the press.”
Understanding Encryption and Quantum Threats
14:00 to 15:47
Learn how encryption works and the potential threat of quantum computers.
“You know, people often ask, if data is encrypted, will that always be secure?”
Salt Typhoon: A Major Cyber Espionage Operation
15:47 to 17:32
Explore the details and implications of the Salt Typhoon cyber attacks.
“So that's how Salt Typhoon looked from inside the U.S.”
Comparing Global Cyber Operations
17:32 to 19:35
Examine the cyber operations of different countries, including the U.S. and North Korea.
“I think what you get when you discover this type of intrusion is that this is what is happening right now.”
Show all 13 chapters
The Nature of Cyber Espionage
19:35 to 20:52
Discuss the methodologies and goals of cyber espionage across nations.
“I went to a briefing with a major cybersecurity CEO, massive company, one of the biggest players.”
The U.S. and China's Cyber Capabilities
20:52 to 24:08
Analyze the cyber capabilities of the U.S. and China and their implications.
“So that is kind of we expect it to be happening.”
Evaluating Cyber Superpowers
24:08 to 26:52
Learn about assessments of global cyber superpowers and recent insights.
“Well, our show is about where the world and America meet.”
Transcript
Automatic transcript. May contain errors.0:00This BBC podcast is supported by ads outside the UK.
0:30No bouncing between tabs. And best of all, no spreadsheets. Stop managing software and start managing your business with one unified system. Try for free today at odoo.com. That's O-D-O-O dot com. With the new Schwab Teen Investor Account, teens can gain hands-on investing experience and build positive money habits. It's an account co-owned by you and your teen, so you can monitor and engage with the account while your teen learns how to invest and manage money. Learn more at schwab.com. Imagine you're an up-and-coming politician in the United States. Your career is just getting underway. You don't know it yet, but in 2036, you'll be nominated to run for president.
1:16Except sitting on the servers of a foreign power right now are some compromising messages you sent in 2022. and they're just waiting to come back to bite you when you make it big. This is a scenario that some intelligence agencies fear may be coming our way. After a giant Chinese intelligence hack of data carried out by a group known as Salt Typhoon was uncovered. The Chinese government has denied responsibility for Salt Typhoon, but it's believed to have targeted Donald Trump, the Vice President J.D. Vance, but also potentially every living American citizen and people from around the world too.
2:03Today on the show, we speak with a former high-ranking official from the Biden administration who tells us that years from now, even encrypted data could become available to anyone, provided they have a powerful enough computer. From the BBC, I'm Tristan Redmond in London. And today on The Global Story, how did a huge hack go unnoticed for so long? And what does it say about who's winning the global cyber war?
2:39To understand the scale of the Salt Typhoon hack, we turn to someone who was right in the thick of it. Asma has been speaking with Anne Neuberger, a former deputy national security advisor under Joe Biden. Neuberger was in charge of cybersecurity in the previous White House. Asma started by asking her how she found out about this massive data breach. This would have been in the spring of 2024. So I was serving in the White House. So I was working in the secure rooms in the White House where the National Security Council, where I serve, typically sits. It was a conversation with the chief operating officer of a large telecom where he said to me, you know, the Chinese compromised the system we use to track people who are maybe under investigation by the FBI.
3:31So most countries have a way to determine if there is a particular person of suspicion. There's a concern that they may be conducting a crime. there's a way for the telecom systems to actually determine their communications. The Chinese compromised that. So essentially, they turned our telecommunication systems into their espionage system. And that's when I realized the potential scale. Because everything rides on telecom. A private communication I may have with my mom, or a CEO may be having with another CEO as they negotiate a deal. or for that matter, when the president is talking to key senators on the Hill.
4:11Those all ride on our telecommunications. And that is why telecommunications was such a target of interest to the Chinese government from an espionage perspective. What exactly was this operation? The Chinese compromised telecommunications. As I mentioned, telecommunications are the foundation of our digital infrastructure. Private conversations, corporate conversations, national security secrets, all travel across a country's telecommunication infrastructure. Encrypted and unencrypted. Both. Okay. And so this was across various telecom companies. Can you tell us a little bit about what those companies were and which companies you know were targeted?
4:51I don't want to speak to individual companies, but it ranged from large global telecommunications firms to really small regional ones near military bases who provided services to those bases. And hence the conversations that they carry could be of interest to a foreign government as well. And how did you figure out who did this? You mentioned that in that initial call you had with a major telecoms company that it was clear that this was the Chinese. How did you all detect that it was the Chinese? So first, China has one of the most, if not the most, sophisticated and large cyber hacking program in the world.
5:30So some of it comes from the intelligence community and their insights. But often what we'll see is by pulling the thread from compromised systems to the systems those compromised systems talk with, when you pull that thread all the way back, you can often identify the set of techniques and the actors, which often match a particular country. Once you have figured out who did this, and it sounds like the telecom company had a sense of who it was, you all were able to confirm that additional information. It's like, okay, yes, these are Chinese actors. Was it clear to you that it went up to the Chinese government?
6:09There are typically two types of actors in cyberspace. There's countries and criminals. The technique we see criminals using is ransomware. They do it to make money. They essentially lock a system and ask the company to pay a ransom, typically in cryptocurrency, to unlock it. So that's the MO of criminals. Make money out of it. The MO of compromise a system, carefully hide your tracks, stay in there for a long time. We believe the compromise of the telecoms could have gone on undetected for up to three years. Wow. That's typically a country conducting espionage. Three years prior to when it was detected, eh?
6:47Yes, for some of the telecoms. And that's a key point, because that meant that those telecoms had such spotty cybersecurity or such gaps in their cybersecurity that there could be an attacker in their network for that long. Now, the Chinese do a good job of compromising systems, hiding their tracks. But still, there could be an attacker in their networks for that long without being detected. Got it. So just to be clear on what you're saying, it seems like part of what made it clear to you all that this is a state actor, a country actor, is that this went so undetected. It went undetected for so long.
7:24And that a criminal would make themselves known because they want to get something out of it. Exactly. Countries and criminals have different goals. Interesting. Countries want espionage. Yeah, yeah. Or to preposition to cause trouble at a period of geopolitical crisis. Criminals want to make a buck. And the country, you're saying, went undetected for quite some time. And in some ways, you could argue, maybe would have preferred to remain undetected for many years to come. Absolutely. The dream of intelligence operations is to collect intelligence for as long as absolutely possible. So let's talk about what was actually obtained here.
7:58What is the most sensitive information that they got? There were really three kinds of information. One, phone calls, sensitive phone calls between, as you would expect, high-level policymakers, which could be of espionage interest to them. Second, you know, cell carriers or cell phone towers identify where the cell phones are. And if somebody's holding a cell phone, that helps identify where a person is. So we believe they were able to potentially track persons of interest across the U.S. government. Maybe people the U.S. government was tracking as potential Chinese spies. Maybe people working at sensitive sites in the United States.
8:42And then the third thing is individuals who the U.S. government may be monitoring via telecommunication systems. I see. There were reports that this hack allowed the Chinese government to spy on, as you say, government officials. also high-level politicians, Donald Trump's phone calls, for example. Is that accurate? I won't identify any specific individuals, but people making a phone call on an open phone system without using an encryption application like WhatsApp, like Signal, those phone calls, by the kind of access the Chinese had, could have been intercepted and collected. Got it. So it's certainly plausible, even if you're not going to go there, that that could be that type of phone call.
9:29Based on the kind of access the Chinese government had, Any phone call of interest, they could have made a copy of to take offline for broader intelligence. Okay. And I know that officials told the New York Times that this hack may have stolen information from nearly every American. Is that true? Everyone uses our phones, right? We use phones to communicate. We use phones to check in on our kids. It was a broad swath of Americans and by that matter, other citizens around the world, communications that was available to them to collect. And we know the Chinese do broad scale surveillance operations.
10:06So not just Americans, you're saying, were affected here. We know that the Chinese compromised telecoms around the world. Did you alert the president about this? Yes, the president would have been briefed as he routinely was whenever there were major cyber incidents. What was his reaction to this? Do you recall? You know, as you would expect, the first reaction is how could this happen? The second one is how do we make sure it never happens again? And the third is typically how do we convey to the foreign government that these kinds of activities aren't acceptable? You mentioned that you also, as part of the process of trying to let people know about the significance of this, you sort of quietly start alerting allies.
10:54How did you all do that? You know, typically, the more sensitive things are shared by the intelligence community with intelligence agencies, the technical details. The bigger picture significance of this will be shared by myself or other colleagues in the National Security Council. I pick up the phone and have a secure call with colleagues in key ally countries around the world. As you would expect, it would be Europe, the Indo-Pacific, key ally in the Middle East. And typically the fastest way that we notify key partners is we'll get on a secure call or a secure video. In a couple of cases, I did fly over to a particular country in order to walk them through in detail the seriousness of this and also to answer any questions.
11:45And I know at some point later, you all also briefed the press. For listeners who may not know, I used to cover the White House and I recall you talking to White House reporters. I remember that moment, but I will also say to you candidly, I don't know that many of my colleagues understood this to be a very significant moment. I don't know that a whole lot of stories actually came out in the press after that. When you briefed the press and you held a couple of calls with reporters, what was the motivation there? What were you all trying to accomplish? There's a major national security threat playing out, and we wanted to be transparent with the press and have them talk about this threat and help us in getting companies and citizens to understand the threat and act.
12:30Do you think citizens understood?
12:35Probably a mix. Those that are more technologically astute understood when we said, please use an encrypted app if you're having a sensitive conversation. Use WhatsApp. Use Signal. Because then your communication is encrypted end to end and cannot be intercepted. So some of this is happening, Anne, against the backdrop, just to remind listeners, of a pretty competitive presidential election that's also happening. This is the fall of 2024. Joe Biden, former president, decides not to run, but his vice president, Kamala Harris, does. And we see all this happening. We then see Trump win the election.
13:11And just days before Trump's inauguration, I recall that you all sanctioned a couple of Chinese companies that you all believe were part of this hack. And can you explain to me why you did that? In some cases in China, China's cybersecurity companies also play a role in China's offensive program. And we want to make that clear, that companies that call themselves cybersecurity companies should not be conducting offensive activity on behalf of their government. I want to talk about what the consequences long term of this hack could be. I think some folks might hear this and think, OK, there was this hack.
13:50It's been patched. It's been fixed. So now what? We move on. What, in your view, are the consequences? What's the sort of worst case scenario of the information that was obtained? You know, people often ask, if data is encrypted, will that always be secure? And the answer is yes, unless a country creates a quantum computer that can break encryption. Essentially, think about encryption as the virtual equivalent of a locked box. If I mail you a locked box, Asma, if you have the private key, if you have the key, you can just unlock it when you get it. Well, if I'm sending you a message and I want to do so securely in cyberspace, encryption is the set of math, the key that allows you to unlock that private message.
14:38And the math underpinning that tells us that those encryption keys are secure. Quantum technology is a different kind of technology that could potentially unlock those keys far more quickly than traditional classical computers could. We believe that no government has a quantum computer today and that they're probably a decade out, as the science is rather complex. But one concern the U.S. intelligence community has had is that China has been collecting encrypted information that could be of value even 10 years from now. Think about the encrypted details of a weapons program. So that if indeed they were able to develop a quantum computer and could decrypt that even 10 years from now, they could learn specific national security secrets.
15:29That is wild, Anne. Well, on that note, thank you so much for being very generous with your time. I appreciate it. Such a pleasure to be here with you.
15:47So that's how Salt Typhoon looked from inside the U.S. government. But how unusual is all of this anyway these days? Aren't all countries engaged in some form of cyber espionage? To put Salt Typhoon in context, Asma turned to the BBC's cyber correspondent, Joe Tidy. Joe, welcome to The Global Story. It's wonderful to have you with us. Thank you. Joe, what is the simplest way that you would explain what the Salt Typhoon attacks were? Yeah, so the Salt Typhoon attacks, they're kind of like, it's weird to talk about them in the past tense because arguably they're ongoing. It's more like the US discovered that the Chinese were carrying out this absolutely enormous surveillance operation attacking all sorts of different industries, including telecommunications, which is where they got most of the data from.
16:34And it really shocked the West because I think what we hadn't realised, what wasn't appreciated was the scale and the bravado of the Chinese state when it came to state surveillance and hacking. And Salt Typhoon was discovered, 2024, I think it was. And what they realised was that actually in some cases, these sort of like hackers that have been inside the networks have been there for many years. And the whole point of this type of cyber activity, this sort of espionage, is that you get into a network, you burrow in deeply and you extract information that could be useful to the Chinese state or, you know, whatever state it is that you're hacking for.
17:11And you're not meant to get discovered. You're not meant to get caught. And, of course, they did. And that's what led to an absolutely enormous upheaval of our kind of thinking around what China's capable of and what they're doing. Well, I should say, you mentioned it's ongoing. So just to be clear, these attacks remain. They are persistent. No doubt. I think what you get when you discover this type of intrusion is that this is what is happening right now. Obviously, you know, they were kicked out and the kind of immediate danger is over. But that information is gone. And what we assume is happening is that this is the kind of playbook that China is running its cyber operations by now.
17:51Because, of course, if they're capable of it on this scale once, they're doing it again. In the scope of cyber hacks, Joe, where does Salt Typhoon rank? Certainly it's up there with the most widespread and deep intrusions that we've seen. I just think about the amount of data that was stolen in these breaches. How on earth would an organization process all of that information, all that telemetry coming in, all the telco data, all the emails? There's a huge amount of data coming in to the Chinese hacking team there. And I bet they're still picking through it, trying to find intelligence. But in terms of like whether we've seen anything similar, I was reading a report on this the other day, which was quite funny because someone described it as China doing a Snowden on America.
18:37because, of course, Edward Snowden, very famously the contractor for the NSA, he revealed that there was a massive system of surveillance that America was using on its citizens and the rest of the world called PRISM, which was bringing in an absolute, you know, dragnet of information to the security services. And that's what it's reminded people of. There's a sort of irony here where everyone's going crazy about Salt Typhoon and the information they've got when, in fact, you know, This is years after America was revealed to be doing that already. So you're saying that the U.S. government could be doing something very similar to other countries.
19:14Yeah, and often it's put to me that if they're not, then I want my tax dollars back. Because this is what it's all about. Protecting a country is about stealing secrets, trying to get ahead of information that's coming out of your adversaries, and then preparing for what we don't want. We absolutely do not want this, of course, but preparing for some sort of conflict. And cyber is now, we know, a big part of that. I went to a briefing with a major cybersecurity CEO, massive company, one of the biggest players. And we talked about all the things like Salt Typhoon, all the things that Russia's doing.
19:48And I put it to him, you know, are we doing this? Is the West doing this? And he said, probably. And that's the interesting thing about this sort of conversation is that although we need to take them seriously, And if you are a vendor or if you're a company that's meant to be protecting people's data and protecting our critical networks, then obviously, absolutely, you should sit up and pay attention and be concerned about this. But at the same time, we have to have that zoom out approach where we realize that just because the West is saying one thing doesn't mean to say that they're not actually doing it themselves.
20:19We don't really hear about the attacks that the West does on China. We don't hear about the attacks that the West does on Russia. But they are probably happening. And I imagine that as the U.S. is the biggest cyber superpower out there, they're probably doing all these things too. So you're saying, Joe, that China isn't the only country running some sort of cyber espionage operations. Do you have a sense of what other countries might be doing in the United States? And do we know if what China is doing is any different than that? Well, if you look at, for example, let's say North Korea, for example.
20:51North Korea, every country has a cyber-based operation center where they do espionage, they do power projection, they do pre-positioning for conflict. So that is kind of we expect it to be happening. But North Korea is very different. And they kind of stand alone in a sense because North Korean cyber actors, state-sponsored, we know that they are hacking for money and they are making a huge amount of money. They stole$1.5 billion from a cryptocurrency exchange last year. Oh, wow. So, you know, they're bringing in, they're really affecting the GDP. Then you've got the kind of Russian approach, which is very much based around espionage and disruption and destruction, prepositioning for conflict, that kind of thing, very much based around what the kind of the Kremlin's goals are.
21:36But you also have this kind of massive cybercrime ecosystem, which is inside Russia, not being tackled at all by the Russian authorities. and in some cases they are having tacit approval by the Russian state to carry out attacks as long as you don't attack Russian targets. That seems to be the status quo there. When it comes to China, everything is, we think, very controlled. Everything comes from the CCP and it's a case of, right, what do we need to do to achieve our next aims? And the way that China works, we know, is they have these ginormous five-year, ten-year plans where they want to become, for example, the leaders in AI, the leaders in quantum, whatever it is.
22:18And we used to see many cases of the Chinese being complicit in hacking and stealing intellectual property. Now it seems, of course, if things have moved on and they're carrying out many, many different types of attacks to carry out espionage and also to preposition. When it comes to the US, we get very, very little data on this. Interestingly - In terms of what the US is doing. And the UK, you know, any NATO, So there's this alliance called the Five Eyes Alliance, which is UK, US, Australia, Canada and New Zealand. And the kind of things they are doing together or individually, unfortunately, we just don't really hear about because of that Western cybersecurity industrial base.
22:59If they see an attack they think is carried out by the West, they'll just ignore it and we won't hear about it. And also, we don't really hear much from the Chinese or the Russians about what the West is doing. Yeah, and I think that's a cultural thing. It's changing slightly because I've noticed the last few years, and I wrote about this recently, that China is now starting to call out the West a little bit. There was one recently where they discovered a hacking team, which they say is US-based, that had got into the central timekeepers of the Chinese industry. like there's some sort of clock that the Chinese industry relies on and the banking sector, and it's kind of like atomic time.
23:40And they'd found some sort of cyber intrusion there, which they said, and they said, you know, we think it's the Americans and they were going to plan to fiddle with this or mess with it or in some way cause disruption. Again, it's a prepositioning is the implication there. China has always called the US the hacking capital of the world. Russia's always accusing the US of doing it. But those kind of little insights are very, very rare. I would love to know what the West is up to. But sadly, I often just don't know. Well, our show is about where the world and America meet. And so, Joe, it's really so fascinating to hear you describe a climate in which we are hearing of cyber warfare, not just happening, you're saying, from the Chinese, but clearly the Americans as well.
24:26And it sounds like you're saying we don't have a clear sense then of which country is on top, because that's what I wanted to ask you is as we move into an era where U.S. dominance is increasingly being challenged, the United States is not the sole superpower of the world. Did you have a sense of which country has the upper hand in cyber surveillance, cyber warfare at this moment? Well, handily, there's a couple of universities that carry out quite regular assessments of this. So there's the Belfer Institute and there's the International Institute for Strategic Studies as well. And they have different metrics and different parameters for how they assess the cyber superpowers.
25:05So, for example, they'll go on what is the defense like in that country? What is the surveillance state like? What are the attack capabilities? Both of them put U.S. at the top, both those different researchers independently of each other. In fact, I think it's the International Institute for Strategic Studies. They put America at the top as the only tier one capable actor out there. Everyone else is tier two, tier three or not even on the list. So they say America is way ahead in terms of as a cyber superpower, whereas the other university puts them as as a sort of ahead of, but not that far away from what China is capable of.
25:43They would put the Belfer Center at Harvard University. That's the one. Yeah. Yeah. So these researchers will both agree that America is the world's cyber superpower in all respects because of the little hints that we have had and things that we think they can do. And I think what's interesting is the last sort of six months or so, we have seen some more little insights into what America's capable of with the attack on Venezuela and the attack on Iran. Only now we are starting to hear a little bit more because there's a lot of fog of war and all that stuff. But we're starting to wonder whether or not, and perhaps even confirm, that cyber was used in both those attacks as a way to soften targets or kind of lay the groundwork for a conventional physical attack.
Read the full transcript
26:31So I think those little insights that we have may further help our understanding of who is kind of on top or not. But certainly, America seems to be ahead.
26:48Well, Joe, it's been a pleasure speaking with you. Thanks so much. Thank you.
27:02That was the BBC's cyber correspondent, Joe Tidy. And before that, you heard from former Deputy National Security Advisor, Anne Neuberger. If you liked our episode today, then I have a favor to ask. Please rate us wherever you listen because it really helps other people to find us. And we love hearing from you all. So if you have any questions or ideas for future episodes, then you can drop us a line by emailing us at theglobalstory at bbc.com. And a quick record before we go, here at The Global Story, we bring you one story every day where the world and America meet. For the very latest news headlines, listen to our sister show, The Global News Podcast, and you can find it wherever you listen.
27:44And that's it from us for today. The episode was produced by Aaron Keller. It was edited by James Shield and mixed by Travis Evans. Our digital producer is Tom Bage. Our senior news editor is China Collins. Our studio manager is Phil Bull. And I'm Tristan Redman. Thanks as always for joining us. We'll talk to you again tomorrow. Cheerio. Thank you.
From the publisher
In 2024, reports emerged of a highly sophisticated cyber espionage campaign against US telecoms companies, which some analysts believe went all the way up to the Chinese government.
The group behind this campaign would later be codenamed Salt Typhoon, and it is believed to have quietly infiltrated critical US telecoms infrastructure in order to collect private information on influential Americans – including presidential candidates. In the process, it may have also swept up data from millions of ordinary Americans. The Chinese government has denied responsibility for Salt Typhoon.
We speak to former Deputy National Security Adviser Anne Neuberger, who was working inside the White House when the attacks were first uncovered. We also speak to BBC cyber correspondent Joe Tidy about how this hack unfolded – and what it reveals about who may be winning the cyber war.
Producer: Aron Keller
Sound engineer: Travis Evans
Executive producer: James Shield
Senior news editor: China Collins
(Photo: Analysts in the Security Operations Center at the Dell Secure Works office in South Carolina, US. Credit: Stephen Morton/Getty Images)




