logo

China-Backed Salt Typhoon Hacks US National Guard for Nearly a Year

ID: be9b83ce-7917-5ace-9cb8-079bcc3b0754

STIX ID: report--be9b83ce-7917-5ace-9cb8-079bcc3b0754

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-07-17

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Salt Typhoon, a China-linked APT, reportedly compromised a U.S. state Army National Guard network and remained undetected for roughly nine months, exfiltrating administrator credentials, network configuration files, topology diagrams, and personnel PII; the intrusion potentially exposed nationwide state-level cyber-defense details and could undermine response to PRC cyber campaigns. The DHS document notes the group's prior compromises of major telecom vendors, highlights telemetry of stolen configuration files across multiple sectors, and recommends hardening SMB traffic, network segmentation, credential hygiene, role-based access, and least privilege to mitigate similar intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.