• News/
  • https://www.bleepingcomputer.com/news/security/canada-says-salt-typhoon-hacked-telecom-firm-via-cisco-flaw/

Canada says Salt Typhoon hacked telecom firm via Cisco flaw

BleepingComputer
·
Bill Toulas
·
Published Jun 23, 2025
·
Updated

The Canadian Centre for Cyber Security and the FBI confirm that the Chinese state-sponsored 'Salt Typhoon' hacking group is also targeting Canadian telecommunication firms, breaching a telecom provider in February. During the February 2025 incident, Salt Typhoon exploited the CVE-2023-20198 flaw, a critical Cisco IOS XE vulnerability allowing remote, unauthenticated attackers to create arbitrary accounts and gain admin-level privileges. The flaw was first disclosed in October 2023, when it was reported that threat actors had exploited it as a zero-day to hack over 10,000 devices. Despite a significant period having passed, at least one major telecommunications provider in Canada still hadn't patched, giving Salt Typhoon an easy way to compromise devices. "Three network devices registered to a Canadian telecommunications company were compromised by likely Salt Typhoon actors in mid-February 2025," reads the bulletin. "The actors exploited CVE-2023-20198 to retrieve the running configuration files from all three devices and modified at least one of the files to configure a GRE tunnel, enabling traffic collection from the network." In October 2024, following Salt Typhoon breaches on multiple American broadband providers, the Canadian authorities flagged reconnaissance activity that targeted dozens of key organizations in the country. No actual breaches were confirmed at the time, and despite the calls to elevate security, some critical service providers didn't take the required...

Read full article

Affected Software

1 affected component
Cisco IOS XE

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the hacking activities of the state-sponsored group 'Salt Typhoon' targeting a Canadian telecom firm through a vulnerability in Cisco systems.

2

What security implications are discussed in the article?

The article highlights the risks posed by state-sponsored hacking groups and the vulnerabilities in widely used software that can lead to significant breaches.

3

What group is responsible for the attack mentioned in the article?

The article identifies the 'Salt Typhoon' hacking group, which is believed to be state-sponsored by China.

4

What specific vulnerability was exploited in the attack?

The article reports that the attack was executed through a flaw in Cisco IOS XE software.

5

What entities confirmed the hacking incident?

The Canadian Centre for Cyber Security and the FBI confirmed the hacking incident involving the telecom firm.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203