New Bill Pushes Voluntary Cyber Rules for Telecoms After Salt Typhoon Breach
A bipartisan group of US senators has introduced the Telecommunications Cybersecurity and Resilience Act, aiming to establish voluntary cybersecurity best practices and an optional certification for telecom companies. The move follows the Salt Typhoon attacks, in which Chinese state-backed hackers breached nearly all major US telecom providers over several years, gaining access to sensitive call records and, in some cases, intercepting audio and text communications.
The bill would create a Telecommunications Cybersecurity Working Group under the National Telecommunications and Information Administration, bringing together telecom companies, suppliers, cybersecurity experts and federal officials to develop the voluntary standards. Senator Mark Warner described Salt Typhoon as the worst telecom hack in US history and said adopting stronger practices could make networks more resilient.
The legislation arrives roughly a year after regulators rolled back earlier telecom security rules that had been introduced in response to the same hacking campaign. Salt Typhoon reportedly targeted around 150 high-profile individuals, including senior government officials, by exploiting weaknesses in telecom infrastructure to access call detail records revealing who people spoke to, when and where.