Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Salt Typhoon Telecom Intrusions 2025: How Stolen Credentials…
Breach analysis Incident: 20 Feb 2025

Salt Typhoon Telecom Intrusions 2025: How Stolen Credentials and Network Device Secrets Kept China-Linked Hackers Inside for Years

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 7 min read
Category: NHI
On this page

In February 2025, Cisco Talos published its findings on Salt Typhoon, the China-linked group behind widespread intrusions into major US telecommunications companies. The most striking finding was how little it relied on vulnerabilities. Talos found only one case where a Cisco flaw, CVE-2018-0171 in the Smart Install feature, was likely abused. "In all the other incidents we have investigated to date, the initial access to Cisco devices was determined to be gained through the threat actor obtaining legitimate victim login credentials." Once inside, the group harvested more credentials from network device configurations, including weakly protected local account passwords, and captured SNMP, TACACS and RADIUS traffic including the secret keys shared between devices and authentication servers. It moved from device to device, and from one telecom to another, and in one case stayed inside for more than three years.

Key takeaways

  • Talos found legitimate stolen credentials were the initial access route in every Salt Typhoon incident it investigated except one, where CVE-2018-0171 was likely exploited.
  • How the first credentials were obtained is unknown, according to Talos.
  • The group stole device configurations containing SNMP read/write community strings and local accounts with weak password encryption, which Talos said can be trivially decrypted offline.
  • It captured SNMP, TACACS and RADIUS traffic, including the shared secret keys between network devices and authentication servers, to collect more credentials.
  • The identity lesson: network devices are full of non-human credentials (community strings, shared keys, local admin accounts), and they are rarely rotated or monitored like other identities.

At a glance

OrganisationsSeveral major US telecommunications companies; Cisco (analysis of its network devices)
WhenIntrusions reported from late 2024; Cisco Talos analysis published 20 February 2025; access in one case lasted more than three years
AttackerSalt Typhoon, a China-linked state-sponsored group
Entry pointLegitimate victim login credentials for network devices in most cases; CVE-2018-0171 likely exploited in one case
Identities abusedNetwork device login credentials; SNMP community strings; local accounts with weak password types; TACACS and RADIUS shared secret keys; attacker-created local and Linux-level accounts and SSH keys
ImpactLong-term access to core telecom network infrastructure, packet capture and pivoting between providers
CategoryNHI. Incident class: confirmed NHI breach (stolen device credentials and network authentication secrets)

What happened

Salt Typhoon's intrusions into US telecoms were first reported in late 2024 and later confirmed by the US government. Cisco Talos, working with victims and law enforcement, published what it had seen on Cisco equipment on 20 February 2025. "There was only one case in which we found evidence suggesting that a Cisco vulnerability (CVE-2018-0171) was likely abused," Talos wrote. Everywhere else, access came from legitimate credentials. "The use of valid, stolen credentials has been observed throughout this campaign, though it is unknown at this time exactly how the initial credentials in all cases were obtained by the threat actor." Talos found no new Cisco vulnerabilities and said it had not identified evidence to confirm reports that three other known Cisco flaws had been used. Separately, CyberScoop noted that Recorded Future had reported further telecom intrusions attributed to Salt Typhoon via two Cisco IOS XE vulnerabilities between early December 2024 and late January 2025.

Once inside, the group expanded its credential haul. It exfiltrated device configurations, often over TFTP or FTP, which "often contained sensitive authentication material, such as SNMP Read/Write (R/W) community strings and local accounts with weak password encryption types in use." Talos noted that the weak password type "would allow an attacker to trivially decrypt the password itself offline." The group also captured "SNMP, TACACS, and RADIUS traffic, including the secret keys used between network devices and TACACS/RADIUS servers," almost certainly to collect more credentials.

With those credentials it pivoted "machine to machine" through trusted infrastructure, including from one telecom's device to another telecom's. It modified configurations: changing AAA and TACACS+ server addresses, creating unexpected local accounts, altering ACLs and SNMP community strings, starting SSH servers on high ports and adding SSH authorized keys at the Linux level. It used a custom tool, JumbledPath, to capture packets through chains of devices while clearing logs. The group "demonstrated their ability to persist in target environments across equipment from multiple vendors for extended periods, maintaining access in one instance for over three years," Talos wrote. CyberScoop noted this was the first time Cisco acknowledged its equipment's role in the attacks.

Timeline

DateEvent
Late 2024Intrusions into US telecom networks are reported and later confirmed by the US government.
20 February 2025Cisco Talos publishes its analysis of Salt Typhoon's techniques.
20 February 2025CyberScoop reports Cisco's confirmation that Salt Typhoon gained initial access through Cisco devices.
21 February 2025SecurityWeek reports Talos's findings on network hopping and credential theft.

How it happened: the identity attack path

  1. Stolen credentials. The group logged in to network devices with legitimate victim credentials obtained by unknown means.
  2. Configuration theft. It exfiltrated device configurations containing SNMP community strings and weakly protected local passwords.
  3. Secret harvesting. It captured SNMP, TACACS and RADIUS traffic to obtain shared keys and more credentials.
  4. Persistence. It created local and Linux accounts, added SSH keys and redirected AAA servers to its own infrastructure.
  5. Pivoting and collection. It moved between devices and providers and captured traffic, sometimes for years.

Impact

  • Telecom networks: long-term access to core infrastructure at several major US providers, with packet capture capability.
  • Cross-provider risk: devices at one telecom were used as hop points to reach others.
  • Credential exposure: community strings, shared authentication keys and local account passwords across multi-vendor equipment.

What this means for NHI governance

Network infrastructure runs on non-human credentials: SNMP community strings, TACACS and RADIUS shared secrets, local administrator accounts on each device, and SSH keys. They are often configured once, copied into many device configurations and never rotated. Salt Typhoon shows what that means in practice: one set of stolen logins led to configurations full of more secrets, and those secrets let the group spread and persist for years without needing an exploit.

Treating network credentials as identities means inventorying them, eliminating weak password types and default or shared community strings, rotating shared secrets, centralising device authentication with MFA, and alerting on configuration changes such as new local accounts or changed AAA servers. See our OT and ICS Identity and Access Guide, Secrets Management Guide and ITDR Guide.

Recommendations

  • Remove weak password types from device configurations. Use strong password hashing on every network device and rotate any passwords stored weakly.
  • Rotate SNMP community strings and AAA shared secrets. Move to SNMPv3 where possible and treat shared keys as secrets with owners and rotation. See our Secrets Management Guide.
  • Protect device configurations. Configurations contain credentials; restrict and monitor TFTP and FTP transfers and store backups securely.
  • Alert on identity changes on devices. New local accounts, added SSH keys and changed TACACS or RADIUS servers should trigger investigation. See the ITDR Guide.
  • Use MFA and centralised authentication for device administration. Stolen passwords alone should not open network devices. See the Privileged Access Management Guide.

Frequently asked questions

How did Salt Typhoon hack US telecoms?

Cisco Talos found that in almost every case it investigated, Salt Typhoon logged in to network devices with legitimate stolen credentials. It likely exploited CVE-2018-0171 in one case. How the first credentials were obtained is unknown.

What credentials did Salt Typhoon steal from network devices?

Device configurations with SNMP community strings and weakly encrypted local passwords, plus SNMP, TACACS and RADIUS traffic containing the secret keys shared between devices and authentication servers.

How long did Salt Typhoon stay inside networks?

In one case Talos observed, the group maintained access for more than three years.

BeyondTrust Breach 2024 · Ivanti Connect Secure Exploitation 2024 · OT and ICS Identity and Access Guide · Secrets Management Guide · ITDR Guide

How NHI Mgmt Group can help

Network device credentials are one of the least governed groups of non-human identities. We help infrastructure teams inventory them, remove weak and shared secrets and monitor for identity changes on devices. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org