Tag: Salt Typhoon

  • Eight U.S. Carriers Form C2 ISAC: Telecom Closes Ranks on Cyber Defense

    Eight U.S. Carriers Form C2 ISAC: Telecom Closes Ranks on Cyber Defense

    Eight of the largest U.S. communications companies have formed the C2 ISAC — an Information Sharing and Analysis Center dedicated to cybersecurity collaboration across the telecom sector. The announcement, distributed May 18, 2026 via the AT&T Newsroom, positions the new body as a vehicle for member carriers to exchange threat intelligence and coordinate defenses against attacks on communications infrastructure.

    Executive Summary

    An ISAC is a member-run clearinghouse where companies in one industry share indicators of compromise, attack patterns, and defensive playbooks — a model pioneered by the financial sector’s FS-ISAC in 1999 and since replicated across critical infrastructure. What is notable here is not the model but the participants: eight direct competitors, including AT&T, standing up a purpose-built cybersecurity body for communications rather than relying solely on existing government-coordinated channels.

    The move lands in a sector still absorbing the lessons of the publicly reported Salt Typhoon intrusions, in which a China-linked espionage campaign penetrated multiple major U.S. carriers and was disclosed beginning in late 2024. Whatever the C2 ISAC’s precise mandate turns out to be, its formation is a clear signal that the operators of America’s communications backbone believe collective, industry-led defense is now table stakes — and that the existing sharing arrangements were not enough on their own.

    Why Telecom Is Building Its Own War Room

    Telecom networks are uniquely attractive targets: compromise one carrier and you can potentially observe the communications of millions of customers, including government and enterprise traffic. The Salt Typhoon campaign made that risk concrete, with public reporting indicating intruders reached deep into carrier systems, including infrastructure tied to lawful-intercept functions. Against that backdrop, a formal, carrier-owned threat-sharing body reads as an institutional response — turning ad-hoc cooperation during a crisis into a standing capability.

    The sector was not starting from zero. Communications companies have long participated in government-coordinated sharing through bodies descended from the Communications ISAC and in cross-sector work with the Cybersecurity and Infrastructure Security Agency (CISA). Creating a new, industry-controlled center suggests the founders wanted something those channels did not fully provide — plausibly faster peer-to-peer exchange, tighter operational trust among a small membership, or an agenda set by carriers rather than convened by government. The release headline emphasizes collaboration; the substance will be in how the body differs from what already existed.

    The Economics of Shared Defense

    Cyber threat intelligence has an unusual economic property: sharing it costs the giver little and can save the receiver enormously, because attackers reuse infrastructure and techniques across targets. An indicator of compromise spotted on one carrier’s network — a malicious IP address, a tampered configuration, a phishing kit — is often the early warning that lets seven others block the same campaign. Pooling that signal across eight national-scale networks creates a sensor grid no single company could build alone.

    The catch is that sharing bodies live or die on trust and reciprocity. Members must be willing to disclose incidents that are commercially embarrassing, and to do so fast enough for the intelligence to matter. The U.S. Cybersecurity Information Sharing Act of 2015 provides liability protections designed to encourage exactly this, but ISACs across industries have historically struggled with free-riding — members who consume intelligence without contributing. A small founding group of eight peers, rather than a sprawling open membership, may be a deliberate design choice to keep contribution norms enforceable.

    Ripple Effects Down the Infrastructure Stack

    Carriers do not defend their networks in isolation. Their infrastructure runs through data centers, interconnection points, and cloud platforms, and their security posture directly affects every enterprise that buys transit, transport, or managed services from them. If the C2 ISAC succeeds in shortening the time between one member detecting a campaign and all members blocking it, the benefit flows downstream to customers who never see the machinery — fewer carrier-side compromises means fewer avenues into the businesses that ride those networks.

    There is also a competitive dimension. Security is increasingly a procurement criterion for enterprise and government connectivity contracts, and visible participation in a serious sharing body is a credential. For carriers outside the founding eight — regional operators, rural providers, wireless resellers — the open question is access: whether the C2 ISAC’s intelligence eventually reaches the broader ecosystem, or whether it deepens a capability gap between the largest operators and everyone else. Smaller operators have historically been the softer targets, so the sector-wide payoff depends on how far the sharing extends.

    Background

    ISACs trace to Presidential Decision Directive 63 in 1998, which urged each critical-infrastructure sector to build a hub for sharing threat information; the financial sector’s FS-ISAC, founded in 1999, became the template. The communications sector has participated in government-coordinated sharing for decades, but the disclosures beginning in late 2024 of the Salt Typhoon espionage campaign — which publicly reported accounts say penetrated multiple major U.S. carriers — sharpened scrutiny of whether existing arrangements moved fast enough. The C2 ISAC, announced in May 2026 with AT&T among its eight founding firms, is the sector’s most visible institutional answer to that question so far.

    Source: Eight Leading U.S. Communications Firms Form C2 ISAC to Strengthen Cybersecurity Collaboration — AT&T Newsroom release announcing the formation of a telecom-sector cybersecurity information sharing and analysis center.

  • Salt Typhoon Breach of IBM Subsidiary in Italy Puts Europe’s Enterprise Core on Notice

    Salt Typhoon Breach of IBM Subsidiary in Italy Puts Europe’s Enterprise Core on Notice

    Security Affairs reported on May 2, 2026 that Salt Typhoon — the threat actor Western governments have linked to Chinese state espionage — breached an IBM subsidiary in Italy. The report frames the intrusion as a warning for Europe’s digital defenses, signaling that a campaign best known for compromising U.S. telecommunications carriers is now reaching into the European enterprise technology sector.

    Executive Summary

    According to the Security Affairs report, an Italian subsidiary of IBM — one of the world’s largest enterprise IT and consulting companies — was compromised by Salt Typhoon, a hacking group that U.S. agencies have attributed to China’s state security apparatus. The report positions the incident less as an isolated breach and more as evidence that Chinese state-aligned intrusion campaigns are expanding beyond American telecom networks into Europe’s corporate and IT-services core.

    Why it matters: IT-services and consulting firms sit inside the trust boundary of hundreds or thousands of client organizations. A foothold in one such firm can become a staging point for espionage against banks, governments, telecoms, and critical infrastructure downstream. If the attribution holds, this is the kind of supply-chain-adjacent intrusion that European regulators designed the NIS2 directive — the EU’s updated cybersecurity law for essential and important entities — to surface and contain. The public reporting, however, is thin on specifics, and the material questions remain open.

    From Phone Networks to the Enterprise Back Office

    Salt Typhoon earned its notoriety through a sweeping campaign against U.S. telecommunications carriers, disclosed beginning in late 2024, in which intruders reportedly reached systems used for lawful intercept — the infrastructure carriers maintain to comply with court-ordered wiretaps. That campaign established the group’s signature: patient, infrastructure-level espionage aimed at the systems that other systems depend on. A breach of an IBM subsidiary in Italy, if confirmed in the terms reported, would fit that pattern while marking a geographic and sectoral expansion — from American carriers to a European arm of a global IT-services giant.

    The logic is straightforward. An IT-services firm holds privileged credentials, remote-access pathways, and architectural knowledge for its clients. Compromising one is economically efficient espionage: a single intrusion can yield visibility into many organizations at once. Security practitioners call this a trusted-relationship or supply-chain attack, and it has been a recurring theme in state-linked campaigns for a decade.

    What the Report Establishes — and What It Doesn’t

    It is worth being precise about the evidentiary picture. The public reporting names the actor (Salt Typhoon), the victim category (an IBM subsidiary), and the location (Italy). It does not, in the material available, name the specific subsidiary, describe the intrusion method, quantify what was accessed, or state whether client environments were touched. Attribution to a specific state-linked group is a technical judgment that typically rests on tooling, infrastructure overlaps, and tradecraft — evidence the public report does not lay out. None of that means the report is wrong; it means readers should treat scope and impact as unestablished until the company or a government agency speaks on the record.

    That caution cuts both ways. Vendors and victims have incentives to minimize; incident reporting sometimes outruns confirmed facts. The responsible reading on May 2, 2026 is that a credible security outlet has flagged a serious claim that warrants verification, notification, and follow-up — not that the full blast radius is known.

    Europe’s Regulatory Moment Meets Its Threat Moment

    The timing lands squarely in Europe’s post-NIS2 era. The directive, which EU member states were required to transpose into national law by late 2024, obliges essential and important entities — a category that captures much of the IT-services sector — to report significant incidents on tight timelines and imposes management-level accountability. Italy’s national cybersecurity agency, ACN, is among the bodies that would ordinarily be in the notification chain for an incident of this description, alongside GDPR obligations if personal data were involved.

    For buyers of IT services, the practical takeaway is not to churn vendors on the strength of a single report. It is to exercise the rights modern contracts and regulations already provide: ask providers directly about exposure, review the privileged access those providers hold, and verify that monitoring covers the vendor-facing pathways into your own environment. State-aligned espionage campaigns target the seams between organizations; that is where defensive attention should concentrate.

    Background

    IBM is one of the world’s largest enterprise technology companies, operating consulting, software, and infrastructure businesses through subsidiaries in most major markets, including Italy. Salt Typhoon entered public awareness in late 2024, when U.S. officials disclosed that the China-linked group had penetrated major American telecommunications carriers in what some officials described as among the most serious telecom intrusions on record. Western governments have attributed the group’s activity to Chinese state intelligence interests, a characterization Beijing has consistently denied.

    The reported Italian incident arrives as Europe implements NIS2, its toughened cybersecurity regime for critical and important sectors, and as governments on both sides of the Atlantic warn that state-aligned actors are pre-positioning inside infrastructure and service-provider networks. IT-services firms occupy a particularly sensitive position in that landscape because their access spans so many client organizations at once.

    Source: Salt Typhoon breach IBM subsidiary in Italy: a warning for Europe’s digital defenses — Security Affairs report, May 2, 2026, on a China-linked intrusion at an IBM subsidiary in Italy.