Security News

US Senators Push New Bill to Strengthen Telecom Security After Salt Typhoon Hack

CyberScoop · 25 Sept 2026
Key Takeaway Even as government policy on telecom security evolves, businesses should not assume their communications providers are fully protected and should independently verify the security practices of any telecom vendors they rely on.

Nearly two years after the Salt Typhoon hacking campaign came to light, US Senators Mark Warner and Ted Cruz have introduced the Telecommunications Cybersecurity and Resilience Act. The bill responds to what Warner called the worst telecom hack in the nation's history, an operation blamed on a Chinese-linked group that infiltrated major telecom carriers and stole data linked to presidential campaigns and candidates.

Rather than imposing strict federal rules, the legislation takes a voluntary approach. It would establish a telecom cybersecurity working group within the National Telecommunications and Information Administration, bringing together carriers, equipment suppliers, security experts and government agencies. This group would be tasked with developing industry-wide best practices within 18 months of the bill's passage, with reviews every two years or after major security incidents.

Officials have warned that the threat behind Salt Typhoon remains active, even as public attention has faded. Some cyber policy experts have expressed concern that this waning interest has slowed momentum for stronger telecom security rules, with one previous initiative already rolled back under the Trump administration.

Salt Typhoon telecom security cybersecurity legislation

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.