UK Government
Incident posture
Linked entities
- Victim
- UK Government
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Chinese state-linked hackers, identified as the group Salt Typhoon, conducted a multi-year cyber-espionage campaign targeting global telecommunications networks, reportedly breaching mobile phones "right into the heart of Downing Street." The breaches, which U.S. intelligence agencies believe date back several years, were first identified and disclosed by U.S. authorities after allies were alerted. The campaign targeted multiple countries, including members of the Five Eyes intelligence alliance, granting the hackers access to phone data of millions, the ability to eavesdrop on calls, read text messages, track locations, and record calls at will. In the UK, concerns were raised that senior government figures and Downing Street staff may have been exposed, with sources noting numerous attacks occurred particularly during a former prime minister's tenure.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Chinese state-linked hackers compromised mobile phones at the heart of Downing Street as part of a broader global cyber-espionage campaign that targeted telecommunications networks across multiple countries over several years. U.S. officials first alerted their international allies in 2024 after discovering that hacking groups had gained access to telecom companies around the world, according to reporting by The Associated Press. The campaign targeted the United States and the other members of the Five Eyes intelligence alliance, including Australia, Canada, and New Zealand, in addition to the United Kingdom. The breaches allegedly provided China with access to the phone data of millions of users and the potential ability to eavesdrop on calls, read text messages, and track users' locations. A source told The Telegraph that the breach penetrated "right into the heart of Downing Street," indicating that senior government figures in the U.K. may have been exposed through their mobile communications.
According to Anne Neuberger, who served as deputy U.S. national security adviser between January 2021 and January 2025, the hackers possessed the ability to record calls "at will." Neuberger stated that the Chinese gained access to networks and essentially had broad and full access, giving them the capability to geolocate millions of individuals and record phone calls at will. U.S. intelligence agencies believe the breaches date back to at least 2021, though they were only identified and publicly disclosed by U.S. authorities in 2024. In the United Kingdom, officials expressed concerns that senior government figures may also have been affected by the espionage campaign. Reporting from The Telegraph indicated that there were "many" different hacking attacks targeting the phones of Downing Street staff and across wider government, particularly during the period when Rishi Sunak served as prime minister between 2022 and 2024.
In response to the discoveries, U.S. federal authorities in 2024 urged telecommunications companies to enhance their network security posture. The guidance, issued jointly by the FBI and the Cybersecurity and Infrastructure Security Agency, was intended to help root out the hackers and prevent similar attacks from succeeding in the future. A subsequent joint cybersecurity advisory was issued in August 2025, with the U.S. National Security Agency and allied partners warning that Chinese state-sponsored actors were targeting networks globally. According to an NSA release, the malicious activity outlined in the advisory partially overlaps with cybersecurity industry reporting on Chinese state-sponsored threat actors referred to by names such as Salt Typhoon. Yuval Wollman, a former Israeli intelligence chief now working with cybersecurity platform CyberProof, described Salt Typhoon as "one of the most prominent names" in the cyber-espionage world. Wollman noted that while much of the public reporting had focused on U.S. targets, Salt Typhoon's operations had extended into Europe, the Middle East, and Africa, where the group targeted telecoms firms, government entities, and technology companies.
China's foreign ministry dismissed the allegations as "baseless" and "lacking evidence," according to The Telegraph. The breach into Downing Street communications represents one component of a wider operation that compromised telecommunications infrastructure across the Five Eyes alliance and beyond, giving the attackers potential access to call recordings, text messages, location data, and other sensitive mobile communications of millions of individuals including government personnel.
Sources
Sources available to members: 1 source.