Security News

New Bill Pushes Voluntary Cyber Rules for Telecoms After Salt Typhoon Breach

The Record · 25 Sept 2026
Key Takeaway Even without mandatory rules, Australian businesses relying on telecom and communication providers should ask vendors about their cybersecurity practices and avoid assuming call and message data is automatically protected.

A bipartisan group of US senators has introduced the Telecommunications Cybersecurity and Resilience Act, aiming to establish voluntary cybersecurity best practices and an optional certification for telecom companies. The move follows the Salt Typhoon attacks, in which Chinese state-backed hackers breached nearly all major US telecom providers over several years, gaining access to sensitive call records and, in some cases, intercepting audio and text communications.

The bill would create a Telecommunications Cybersecurity Working Group under the National Telecommunications and Information Administration, bringing together telecom companies, suppliers, cybersecurity experts and federal officials to develop the voluntary standards. Senator Mark Warner described Salt Typhoon as the worst telecom hack in US history and said adopting stronger practices could make networks more resilient.

The legislation arrives roughly a year after regulators rolled back earlier telecom security rules that had been introduced in response to the same hacking campaign. Salt Typhoon reportedly targeted around 150 high-profile individuals, including senior government officials, by exploiting weaknesses in telecom infrastructure to access call detail records revealing who people spoke to, when and where.

Salt Typhoon telecom security critical infrastructure state-sponsored hacking policy

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.