Salt Typhoon: Securing America’s Telecommunications from State-Sponsored Cyber Attacks

Defense Posture and Global ThreatsHouse Oversight and Government Reform Subcommittee on Military and Foreign Affairs · 2025-04-02 · 119th Congress
The House Oversight Subcommittee on Military and Foreign Affairs held this hearing to examine the Salt Typhoon breach, a Chinese state-sponsored hack that compromised US telecom networks and intercepted communications of high-value government and political targets, and to hear expert recommendations on securing critical infrastructure from foreign cyber threats. Begins at 0:13:08
Transcript
Highlights

Title

Salt Typhoon telecom hack and the Signal chat controversy

Purpose

The House Oversight Subcommittee on Military and Foreign Affairs held this hearing to examine the Salt Typhoon breach, a Chinese state-sponsored hack that compromised US telecom networks and intercepted communications of high-value government and political targets, and to hear expert recommendations on securing critical infrastructure from foreign cyber threats. Much of the hearing was also consumed by partisan dispute over a senior Trump administration Signal group chat that had shared details of a military strike on Yemen with a journalist. Begins at0:13:08

Who spoke

Chairman William Timmons (R-SC)0:13:08: Opened by describing Salt Typhoon as a coordinated Chinese campaign that compromised networks used by millions of Americans0:14:09, stressed telecom companies are not at fault0:14:39, and later questioned witnesses on the scale and significance of the breach0:31:48.

Ranking Member Jared Moskowitz (D-FL)0:17:10: Called Salt Typhoon one of the worst telecom breaches ever0:17:41 and pivoted to criticizing the administration's Signal chat leak involving strike plans, arguing it endangered troops and intelligence sources0:18:110:19:12.

Mr. Josh Steinman, CEO, Galvanick0:21:44: Said cyber threats extend beyond telecom to water, power, sewer, and defense infrastructure0:23:14; cautioned against overusing the word "attack" versus probing/collection0:32:18; later noted regulatory liability and information-sharing barriers hamper private-sector cooperation1:14:43.

Dr. Edward Amoroso, CEO, TAG Infosphere / former AT&T CISO0:24:14: Used a "potholes vs. sinkholes" metaphor, warning AI-driven attacks could make Salt Typhoon look like "child's play"0:25:45; argued the best defense against nation-state actors is a strong defense rather than retaliation0:36:21; said state cyber agencies uniformly report insufficient resources1:39:26.

Professor Matt Blaze, Georgetown Law0:26:16: Traced telecom wiretap vulnerabilities to the 1994 CALEA law mandating built-in wiretap backdoors0:27:16, explained that automation and virtualization have expanded the attack surface making an event like Salt Typhoon "inevitable"0:30:47; testified that end-to-end encryption like Signal's protects content from infrastructure-level attacks such as Salt Typhoon0:39:221:16:13, but is not authorized for classified use because it lacks recipient-clearance safeguards1:17:14.

Rep. Michael Cloud (R-TX)0:43:55: Criticized what he called politicization of the hearing, contrasted scrutiny of the Signal chat with lack of scrutiny of prior incidents0:43:55; asked whether quantum computing could eventually break Signal's encryption0:44:250:45:25.

Rep. Stephen Lynch (D-MA)0:50:59: Argued calling the Signal leak's outcome a "success" was dangerous given operational details on strike timing and targeting were shared on an insecure app0:52:31; asked about the impact of CISA layoffs on national security0:56:33.

Rep. Andy Biggs (R-AZ)0:58:04: Cited Internet Security Alliance estimates that 40–70% of cyber workforce time is spent navigating overlapping regulations0:58:35; asked witnesses about harmonizing federal cybersecurity frameworks0:59:05 and later pressed on whether Salt Typhoon victims were individually notified1:37:24.

Rep. Robert Garcia (D-CA)1:04:33: Argued Congress has a right to probe the Signal leak, calling for Defense Secretary Hegseth's resignation over the disclosure1:08:09 and citing a Wall Street Journal report on additional Signal chats and Gmail use by national security officials1:09:40.

Rep. Eli Crane (R-AZ)1:09:40: Defended Rep. Cloud's remarks, noted double standards over the 2021 Afghanistan withdrawal1:10:10, and asked witnesses about AI's role in cybersecurity and threats to the energy grid1:11:111:12:42.

Rep. (unspecified questioner, second round)1:15:13: Walked through the three components of the Signal episode (app, devices, content), had Blaze confirm Salt Typhoon could not read Signal's encrypted content1:15:43, and argued the leak caused no operational harm1:18:44.

Rep. Jared Moskowitz (second round)1:20:15: Entered articles into the record on prior Chinese targeting of Trump/Vance phones and Pentagon warnings against Signal use1:20:15; called for an investigation and admission of a mistake by the administration1:21:151:25:49.

Rep. Ryan McGuire? / Rep. from Virginia, Mr. McGuire (R-VA)1:25:49: Noted Salt Typhoon maintained undetected access for up to 18 months1:25:49; asked about regulatory barriers to information sharing1:26:19 and deterrence gaps in the 2023 National Cybersecurity Strategy1:27:20; criticized CISA's alleged role in social media censorship under the Biden administration1:29:20.

Rep. Andy Biggs (second round)1:36:53: Asked whether Salt Typhoon victims were notified (answer: generally no)1:37:24; questioned state-federal cyber coordination1:38:25; raised Hillary Clinton's email server as a comparison point1:40:56.

Rep. Eli Crane (second round)1:42:27: Noted Democratic members left after the hearing's first half1:42:57; asked how hard it is to remove embedded cyber threats1:43:27 and compared US versus adversary cyber spending1:45:29.

Ranking Member Moskowitz (closing)1:48:31: Said many fired CISA employees live in his district and were highly qualified, calling their termination illegal per a judge's ruling1:48:31; read constituent statements from military families criticizing the Signal leak1:50:32.

Chairman Timmons (closing)1:51:32: Said President Trump acknowledged Waltz "messed up"1:51:32; defended CISA layoffs citing $36 trillion in national debt1:52:32; proposed using tariffs as a deterrent tool against nations that breach US infrastructure1:53:33.

Key moments

Salt Typhoon compromised networks operated by Verizon and AT&T, intercepting real-time calls and messages from over a million users, focused on high-value government and political figures0:14:09.

Blaze testified the 1994 CALEA law required telecom switches to have built-in wiretap backdoors, a mandate he says has been "greatly amplified" into today's vulnerabilities and made an event like Salt Typhoon "inevitable"0:27:160:31:18.

Blaze confirmed that Salt Typhoon's attack was limited to unsecured infrastructure traffic, meaning encrypted apps like Signal would not have exposed message content to that specific attack1:15:431:16:13.

Steinman said quantum computing could theoretically break the Diffie-Hellman key exchange underlying Signal's encryption, and speculated adversaries may be further along in quantum cryptography than assumed0:45:250:45:55.

Amoroso disclosed that Salt Typhoon did not exploit any Huawei equipment, since AT&T had not used Huawei gear, showing the attack didn't rely on that vector0:49:27.

McGuire noted Salt Typhoon maintained undetected access to telecom networks for up to 18 months1:25:49.

Moskowitz and Lynch pressed that senior officials (Vance, Hegseth, Rubio, Waltz, Gabbard) discussed strike timing, aircraft types, and targeting on Signal, including a journalist inadvertently added to the chat0:18:410:52:31.

Biggs asked whether any of the roughly one million Salt Typhoon victims were individually notified; Steinman, Amoroso, and Blaze all indicated the answer is generally no1:37:241:37:54.

Timmons proposed using tariffs against countries harboring cyber adversaries as an economic deterrent, drawing an analogy to post-9/11 responses against countries harboring terrorists1:54:031:54:33.

Amoroso argued expanding federal regulatory frameworks (beyond a simplified NIST standard) wastes security resources, while state cyber agencies uniformly report inadequate staffing and funding0:59:351:39:26.

Metadata

CommitteeHouse Oversight and Government Reform Subcommittee on Military and Foreign Affairs
Chamber / CongressHouse · 119th Congress
Date2025-04-02
TypeHearing
Witnesses
Mr. Matt Blaze — Professor, Georgetown University Law Center
Mr. Josh Steinman — CEO, Galvanick
Dr. Edward Amoroso — CEO / TAG Infosphere, Inc., Research Professor / New York University
Videoyoutube
Transcript206 caption blocks · 17,256 words · 1:56:54 runtime
EventCongress.gov 118084