In late 2024, U.S. telecom operators discovered they had been compromised — not through a zero-day vulnerability in customer-facing systems, not through a supply chain attack on third-party software, but through the lawful intercept infrastructure they are required by federal law to maintain. The adversary was Salt Typhoon, a Chinese state-sponsored group linked to the Ministry of State Security. The access point was CALEA.
What Salt Typhoon actually did
Salt Typhoon breached the CALEA-compliant intercept systems of at least eight major U.S. telecom operators, including AT&T and Verizon. The FBI notified more than 600 organisations across 80+ countries of potential compromise.
Critically, the attackers did not need to break encryption protecting communications in transit. They accessed the intercept interface that telecom operators are legally required to maintain for law enforcement use — where traffic is available in plaintext before delivery to the requesting agency. The breach gave Salt Typhoon persistent, real-time access to communications data for an extended period before detection.
The CALEA architecture problem
CALEA, the Communications Assistance for Law Enforcement Act, was enacted in 1994 to ensure that as telecommunications networks went digital, law enforcement retained the technical capability to conduct court-authorised intercepts. The Act requires telecom operators to design their networks with intercept capability built in — accessible, reliable, and standardised.
That architectural requirement is precisely what Salt Typhoon exploited. Intercept interfaces, by design, aggregate sensitive traffic and make it accessible through a defined technical pathway. When that pathway is hardened only to the standards of 1994 — or not meaningfully updated since — it becomes one of the most valuable targets on a carrier's network. Salt Typhoon did not need to compromise individual user accounts or crack encryption. They found the engineered front door.
The FCC's failed response
The FCC moved quickly in January 2025, issuing a Declaratory Ruling that imposed an affirmative duty on telecom operators to secure their CALEA-compliant networks. For the first time in decades, the Commission put telecom operators on explicit notice that cybersecurity of intercept infrastructure was a compliance matter, not just a risk management decision.
Ten months later, the new Commission reversed it. A 2–1 vote in November 2025 struck down the January ruling as an "unlawful misconstruction" of CALEA — determining that the FCC had overstepped its authority in imposing cybersecurity obligations under the CALEA statutory framework. Telecom operators that had begun investing in hardening their intercept infrastructure were left with no federal mandate behind the effort. Telecom operators that had not were let off the hook.
Where telecom operators stand now
As of December 2025, the position for U.S. telecom operators — and international operators watching the U.S. response — is this: CALEA compliance remains mandatory. Maintaining accessible, standardised intercept interfaces is a legal obligation. Federal authorities have publicly confirmed that Salt Typhoon still has persistent access to carrier networks. And there is no updated federal standard specifying what a secure CALEA implementation looks like.
The Senate Commerce Committee stated in December 2025 that experts agree U.S. communications networks remain vulnerable. Congressional hearings in April confirmed the same. No new rulemaking is imminent. Telecom operators are carrying the risk alone.
The only defensible posture
The FCC reversal did not make telecom operators' intercept infrastructure safer. It removed the regulatory floor that was beginning to form around it. Telecom operators waiting for a new standard before investing in intercept security hardening are not making a rational decision — they are making a bet that the next breach will not be theirs.
Secure-by-design LI architecture is no longer a differentiator. It is the minimum defensible position.
- Probe-free, software-defined intercept platforms that do not create persistent, accessible aggregation points in the network fabric.
- Strict authentication and access control on intercept interfaces — not just for law enforcement delivery, but for the provisioning systems that manage them.
- Audit trails that can detect anomalous access patterns before exfiltration, not after.
- Regular penetration testing of intercept infrastructure, treated with the same rigour as external-facing systems.


