Salt Typhoon Campaign is a threat campaign tracked across 5 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed January 8, 2026; most recent activity May 26, 2026.
Salt Typhoon is a threat campaign linked to a nation-state actor that targeted the US congressional email system, exposing vulnerabilities in core government communications infrastructure. The operation highlights that essential messaging channels remain attractive targets for state-sponsored actors and underscores defenses gaps in critical governmental networks.
New Zealand's Cyber Security Strategy 2026-2030 highlights increasing cyber-attacks on critical infrastructure, with 80% of organizations lacking basic cyber hygiene. The National Cyber Security Centre reported a surge…
Chinese hackers, identified as part of the Salt Typhoon operation, have infiltrated at least nine major U.S. communications networks, raising alarms among U.S. policymakers. The operation has been characterized by…
In July 2025, an advanced persistent threat actor known as UNC3886 targeted Singapore's four telecommunications companies, compromising critical infrastructure. The attack was detected by the Infocomm Media Development…
U.S. officials are investigating a cyber campaign linked to Salt Typhoon that has compromised email systems of congressional staff. This incident is part of a series of attacks targeting U.S. government communications,…
Nick Andersen, acting director of CISA, announced a shift towards operationalizing partnerships with critical infrastructure operators during the McCrary Cyber Summit on March 17, 2026. CISA aims to improve resilience…