Skip to content

Chinese hackers exploited Cisco training to help build Salt Typhoon attacks

Sdxcentral December 11, 2025

Former Networking Academy trainees identified as perpetrators in global cybersecurity espionage campaign

Two former Cisco Networking Academy trainees may have partly orchestrated the infamous state- Salt Typhoon attacks that targeted critical networks in 2024.

A report from SentinelLabs claims to have identified two potential perpetrators – Qiu Daibing and Yu Yang – who used knowledge accrued from Cisco training programs to help build offensive cybersecurity capabilities for a campaign that targeted more than 80 carriers and telecom operators globally.

The report claims the pair took part in the Cisco Network Academy Cup in 2012, a competition that challenges students and instructors in the Cisco Networking Academy to test and develop their skills.

Both Daibing and Yang are believed to have appeared on different teams while representing their school, Southwest Petroleum University. Daibing’s team took first prize and eventually won third place nationally, while Yang’s team won second place in Sichuan.

They went on to co-found Beijing Huanyu Tianqiong, while Yang also has reported ties to Sichuan Zhixin Ruijie. Both companies are believed to have developed technologies and services provided to China's Ministry of State Security and People's Liberation Army, and then used in the mass cybersecurity espionage campaign.

Among the Cisco products exploited during the Salt Typhoon attacks, including Cisco IOS and ASA Firewalls, were covered in the vendor’s Networking Academy, with SentinelLabs suggesting that today’s students could well become tomorrow’s rivals.

“Cisco Network Academy has trained more than 200,000 students in China since the rollout of its program in the late 90s. No doubt that other graduates have gone on to participate in offensive operations against its products, but the vast majority do not,” Dakota Cary, a strategic advisory consultant at SentinelLabs, wrote. “The program itself is not cause for concern, nor should participation in it be construed as such.”

While there is a potential risk of education initiatives inadvertently boosting foreign offensive research, SentinelLabs suggests it’s not just a China-only problem and that hands-on learning is far more integral to success than one’s choice of university.

“Two students from a regional university, with limited recognition in IT and cybersecurity education, participated in the Cisco Network Academy and went on to run one of the most expansive collection operations against global telecommunications firms ever detected and disclosed publicly,” Cary wrote.

“Hiring processes for cybersecurity roles should emphasize demonstration of technical competencies, similar to coding interviews for software engineers, as the university degree may itself be a modest indicator of potential success in the workplace. China does an excellent job emphasizing hands-on learning for cybersecurity students.”

In a statement provided to SDxCentral , a Cisco Spokesperson said: “Cisco Networking Academy (NetAcad) is a skills-to-jobs program that teaches foundational technology skills and digital literacy, helping millions of students obtain basic certifications for entry-level IT jobs each year. This program is open to everyone.

"Since its inception in 1997, the program has educated over 28 million students across 195 countries, in partnership with more than 12,000 institutions and organizations."

"Cisco remains committed to helping people around the world gain the foundational digital skills needed to access careers in technology and the opportunities they provide," the spokesperson added.

The fallout from Salt Typhoon is still being felt today, with a Cisco-based flaw exploited by the Chinese hacking group found to have been used to target devices in Australia as recently as late October .

Australia’s security authority warned that the attack, dubbed BadCandy , affects Cisco IOS XE devices with a basic web shell based on Lua coding, allowing bad actors to create an administrator account on said devices.

Despite the havoc caused by Salt Typhoon, the Federal Communications Commission (FCC) has decided to repeal a Biden-era directive that encouraged internet service providers (ISPs) to shore up their defenses – with FCC Chairman Brendan Carr claiming the rule “exceeded the agency’s authority.”

Extracted Entities

APT Groups (1)

Attack Types (1)

Countries (1)

Industries (1)

Malware (1)

MITRE ATT&CK (1)