Gridware Logo

Salt Typhoon’s Tactics Seen in French Telecom Breach

By Ahmed Khanji Updated 7 August 2025 3 min read

in 𝕏
Salt Typhoon’s Tactics Seen in French Telecom Breach

A cyberattack on Orange, France’s largest telecommunications provider, was confirmed a week ago. The company stated that internal systems were compromised, disrupting corporate and consumer services in France.

Orange’s Paris headquarters. The telecom giant is one of Europe’s largest providers, with over 290 million customers worldwide.

Orange has not confirmed any data loss but has filed a complaint and alerted French authorities. The investigation is still currently ongoing.

Gridware’s own threat teams have been monitoring Salt Typhoon’s movement through telco networks for months, and this incident fits several familiar patterns.

France’s cyber agency has warned about targeted surveillance

In its latest annual review, France’s National Cybersecurity Agency disclosed multiple past intrusions into telecom infrastructure. It’s not the first time European telecom systems have been accessed for strategic surveillance.

These included compromises in mobile and satellite networks used for communication interception. Although attribution was not made public, Gridware’s watchpoint team noticed clear similarities to Salt Typhoon activity.

Salt Typhoon is still active across critical networks

Salt Typhoon, a group linked to China’s Ministry of State Security, was confirmed to have breached at least eight major US telcos. The group targeted communications metadata and specific call traffic from political officials. Investigations show that access had persisted for one to two years before discovery.

In addition, dozens of other countries are now believed to have been affected. Systems across the Indo Pacific, Europe, and other regions were likely accessed through different methods, often quietly.

Salt Typhoon is known for subtle tactics that make their activity hard to detect. Even once discovered, removing them completely from compromised networks takes time. In our view, their use of valid credentials, quiet traffic routing, and malware-free persistence techniques makes them especially hard to detect and remove.

Their success usually depends on blending in. This has made complete remediation a long-term effort for many organisations, and detection alone does not guarantee they’re gone.

Orange’s breach follows a familiar pattern

Orange stated that the breach triggered containment measures, which caused temporary outages. At this stage, the company says no customer or corporate data has been taken.

However**, incidents involving Salt Typhoon typically begin this way**, with low visibility, internal access, and minimal signs of intrusion.

If this attack is related, Orange would not be the first to face disruption without obvious loss.

Telecoms remain a high-value target for Salt Typhoon

Operators continue to rely on legacy infrastructure, which is the most difficult to monitor and secure. Compromises often go unnoticed for long periods. This is what allows campaigns like Salt Typhoon to gain traction.

These attackers are not focused on immediate financial gain. Their goal is long-term access to communications at the infrastructure level.

More to come on Salt Typhoon

Gridware is continuing to follow Salt Typhoon activity across the region, with a close eye on telecom infrastructure in Australia and Southeast Asia.

The Orange breach shows that European providers might already be under similar pressure.

What’s public so far is only part of the picture. Gridware will be releasing more soon.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.