Gridware Logo

ASIO Confirms Telecom Probing Involving Salt Typhoon

By Ahmed Khanji Updated 13 November 2025 2 min read

in 𝕏
ASIO Confirms Telecom Probing Involving Salt Typhoon

What’s happening right now

For months Gridware’s been covering incidents that involved Australian telecom providers along with major attacks overseas. A lot of this activity has been lining up the same way. Someone has been learning how carrier networks operate and testing small entry points. Groups like Salt Typhoon have been showing up in these environments more often, and the pattern has been growing through the year.

ASIO has now confirmed this activity

ASIO has stated that operators outside Australia have been probing local telecom networks and other essential systems. What they are seeing matches what many internal teams have been picking up in their own logs. ASIO shared that espionage cost Australia an estimated $12.5 billion last year, including $2 billion in trade secrets and intellectual property.

This kind of impact usually comes from long-term access that stays hidden for long periods, which is why this update matters.

Telecom networks support most sectors in the country. Banks, transport systems, hospitals and government services all need stable carrier networks to function. When someone attacks these environments, the effect reaches many different providers.

Why attack your telecom provider?

Telecom networks are an attractive target for attackers because disruption moves quickly through the services that rely on them.

What this means for organisations

Many organisations depend on their carriers without having a clear view of how those dependencies work in practice.

A carrier outage doesn’t stay in one place. It moves into the services that rely on it. This includes services like payments, transport schedules, hospital communication systems and government functions.

What leaders should focus on right now

Leaders should know which of their services rely directly on carrier networks. This includes payment flows, cloud access, internal communication tools and any system that stops working the moment an outage starts. A short list is enough because it shows you where disruption will hit first.

It’s also important to understand how long these services can operate during an outage. Some stop immediately. Some continue with limited function. This will show where your organisation is most exposed.

The last step is making sure your teams can monitor these external links properly. Many incidents begin with small attempts that look unrelated or random. Without basic visibility, these early signs are missed.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.