---
reference_key: fbi-salt
title: "CyberScoop --- FBI confirms Salt Typhoon still ongoing (Feb 2026)"
url: "https://cyberscoop.com/fbi-salt-typhoon-ongoing-threat-cybertalks-2026/"
availability: available
capture_method: primary
captured_at: 2026-06-23T03:31:28Z
document_id: REF-fbi-salt
---

# CyberScoop --- FBI confirms Salt Typhoon still ongoing (Feb 2026)

| Field | Value |
|-------|-------|
| **Reference key** | `fbi-salt` |
| **Availability** | AVAILABLE |
| **Capture method** | `primary` |
| **Source type** | remote_url |
| **URL / path** | https://cyberscoop.com/fbi-salt-typhoon-ongoing-threat-cybertalks-2026/ |
| **Captured (UTC)** | 2026-06-23T03:31:28Z |
| **Content type** | text/html; charset=UTF-8 |
| **HTTP status** | 200 |

## Boardroom Citation Context

Salt Typhoon ongoing confirmation.

## Source Location

https://cyberscoop.com/fbi-salt-typhoon-ongoing-threat-cybertalks-2026/





## Captured Content

```text
FBI: Threats from Salt Typhoon are still very much ongoing | CyberScoop Skip to main content Advertisement CyberScoop AIScoop FedScoop DefenseScoop StateScoop EdScoop Advertise Search Close Search for: Search Open navigation Topics Back AI Cybercrime Commentary Financial Government Policy Privacy Technology Threats Research Workforce Special Reports Events Podcasts Videos Insights CyberScoop 50 Switch Site CyberScoop AIScoop FedScoop DefenseScoop StateScoop EdScoop Subscribe Advertisement Subscribe to our daily newsletter. Subscribe Close Government FBI: Threats from Salt Typhoon are still very much ongoing By Derek B. Johnson February 19, 2026 Listen to this article 0:00 Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment. Michael Machtinger, deputy assistant director for cyber intelligence at the FBI, speaks at CyberTalks on Thursday, Feb. 19, 2026. (James Kim / EPNAC) A top FBI cyber official said Salt Typhoon, the Chinese cyber espionage group behind the widespread compromise of U.S. telecommunications infrastructure in 2024, continues to pose a broad threat to both Americas private and public sectors. Michael Machtinger, deputy assistant director for cyber intelligence at the FBI, touted improved partnerships between the telecommunications industry and government in the wake of the campaign while speaking at CyberTalks, presented by CyberScoop, in Washington D.C. Thursday. Companies who engaged with the FBI and federal agencies like CISA early after the campaign went public have been without a doubt the most successful in mitigating the impact of the Salt Typhoon intrusions, he claimed. Last year, CyberScoops reporting found that the U.S. telecommunications sector was riddled with basic cybersecurity vulnerabilities and patchwork consolidated networks, and Salt Typhoon took advantage of these weaknesses to gain widespread, persistent access to major telecom networks. Advertisement Machtinger echoed a similar sentiment in describing lessons the FBI took away from the episode, saying that despite all the advances in cybersecurity tools and strategies, it is still the most basic vulnerabilities that provide entry points. Cybersecurity leaders and network defenders have a responsibility to understand their own vulnerabilities and implement fundamental cybersecurity practices such as zero trust, least-privilege access, secure-by-design principles, end-to-end encryption and other protections. Despite an increasingly complex threat and technology environment, phishing attacks or targeting vulnerable legacy systems are still the most common ways the FBI sees hacking groups gain access to their victims. While foreign intelligence agencies do use zero-day vulnerabilities and other sophisticated tools to compromise well-defended systems, by and large this is not what we are seeing, and it is not what we saw in Salt Typhoon. None of these concepts are new...and truthfully theyre not all that advanced, but they are increasingly essential as adversaries adapt their tactics and our attack surface becomes more widespread, said Machtinger. If were going to safeguard our personal and proprietary information, it is just as important for us to lock the doors inside the house as it is to lock the front door. But these lessons havent diminished the threat . Machtinger estimated that Salt Typhoons intrusions have impacted more than 80 countries, often following the same playbook of pairing broad access with indiscriminate targeting and collection. Advertisement It is important to recognize that the threat posed by Salt Typhoon actors and the rest of the PRC intelligence apparatus and enabling infrastructure is still very, very much ongoing, Machtinger said. Written by Derek B. Johnson Derek B. Johnson is a reporter at CyberScoop, where his beat includes cybersecurity, elections and the federal government. Prior to that, he has provided award-winning coverage of cybersecurity news across the public and private sectors for various publications since 2017. Derek has a bachelors degree in print journalism from Hofstra University in New York and a masters degree in public policy from George Mason University in Virginia. In This Story FBI Salt Typhoon Share Facebook LinkedIn Twitter Copy Link Advertisement Advertisement More Like This Court rules SAVE database illegal, orders it dismantled By Derek B. Johnson Trump executive orders speed up post-quantum migration, boost industry By Derek B. Johnson Madison Alder Authorities disrupt Evil Corps SocGholish botnet By Matt Kapko Advertisement Top Stories Intel agencies: Frontier AI models will reshape cybersecurity faster than expected By Derek B. Johnson Advertisement More Scoops (Getty Images) Lawmakers from both parties say CISA cuts have gone too far Reps. Don Bacon, R-Neb., and James Walkinshaw, D-Va., found rare bipartisan agreement that the agency tasked with defending civilian networks has been diminished at a moment when... By Greg Otto A pipe carrying potable water is seen in a water purification plant. (Getty Images) CISA wants critical infrastructure to operate weeks to months in isolation during conflict By Derek B. Johnson (Getty Images) Chinese national extradited to US for pandemic-era Silk Typhoon attacks By Matt Kapko CISA official advises agencies not to get too hung up on who takes lead in critical infrastructure sectors By Tim Starks Officials worry Salt Typhoon apathy is killing momentum for tougher telecom security rules By Derek B. Johnson FBI targeted with suspicious activity on its networks By Tim Starks Cantwell claims telecoms blocked release of Salt Typhoon report By Derek B. Johnson Latest Podcasts When iPhone exploits turn into commodities Zero days, zero order: The chaos reshaping vulnerability disclosure Why the autonomous SOC is the wrong goal The last layer standing Government Congress tees up No FAKES Act, aiming at AI-generated deepfakes Lawmakers leery about Trump administrations Anthropic order A case for how to shape ingredient lists for AI models Google exposes China espionage group thats been lurking in networks undetected since 2023 Technology Accenture shells out $4.18B on three companies in big industrial cybersecurity push AIs constant patching treadmill can be a security problem Cybersecurity experts dont think Anthropics Fable 5 presents a unique threat Microsoft breaks Patch Tuesday record with 206 vulnerabilities Threats How software development's speed obsession enabled TeamPCPs chaos crusade Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April FBI takes down massive China-based cybercrime network that caused $1.9B in losses US, France, and Italian authorities shut down massive deepfake porn site Policy CISA directive orders agencies to prioritize vulnerability patching in a new way CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector DOD wants to integrate cyber in all operations, and integrate security into AI Trump administration releases scaled-back AI executive order Advertisement About Us FedScoop DefenseScoop StateScoop EdScoop CyberScoop AIScoop Newsletters Advertise with us Ad specs (202) 887-8001 hello@cyberscoop.com FB TW LinkedIn IG YT Close Ad Continue to CyberScoop
```

---

*Archived reference article for AICSR-STUDY-2026-001 footnote corpus.*
