The Wiretappers Got Wiretapped

The Wiretappers Got Wiretapped: 15 Observations About the FBI Hack That Has Absolutely No Irony Whatsoever

WASHINGTON, D.C. — In a development that surprised everyone except the people who designed the system being hacked, the FBI this week confirmed that its wiretapping infrastructure — the very same apparatus the Bureau uses to listen to you — has itself been listened to, by someone who did not ask permission and did not fill out the correct federal form in triplicate.

The incident has been officially designated a “major cyber incident,” which is government nomenclature for “we need a word larger than ‘oops’ but smaller than ‘we’re all going to jail.'”

The hack, attributed to Chinese state-sponsored group Salt Typhoon — a name that sounds less like a geopolitical threat and more like a flavor of energy drink you’d find at an airport vending machine at 2 a.m. — appears to have given foreign intelligence operatives a front-row seat to the FBI’s most sensitive surveillance operations. For what investigators believe was years.

The watchers were watched. The listeners were listened to. The eavesdroppers were eavesdropped upon. Somewhere, Aristotle is spinning in his grave, but honestly, he’s probably also taking notes.


The FBI Noticed “Suspicious Activity”… On Its Own Computers

You’ve got to admire the institutional pluck. The FBI — whose entire statutory mission involves identifying suspicious activity before it becomes catastrophic — finally detected suspicious activity happening directly to them. On their own systems. In their own house.

It’s like a lifeguard spending the summer handing out towels and blowing a whistle at small children splashing, only to look down in August and notice they themselves cannot swim and also are currently drowning.

“This is the nightmare scenario we always feared but never quite believed could happen,” one former senior FBI official told reporters, speaking anonymously, presumably because he feared someone was still listening.

He was not wrong to worry. According to investigators, Salt Typhoon maintained access to CALEA wiretapping systems for months — possibly years — before detection. In at least one case, Cisco reported the hackers remained inside a network for three full years. Three years. At that point, they’re not hackers. They’re tenants. They should be paying rent. They should have a parking spot.

Dr. Reginald Blunt, Senior Fellow at the Institute for Strategic Befuddlement (a nonpartisan think tank operating out of a WeWork in Arlington), called the timeline “breathtaking.”

“In government contracting terms,” Dr. Blunt explained, “three years of unauthorized access is actually quite efficient. That’s faster than most IT upgrades get approved.”


“Unclassified” Is Government Code for “Please Stop Making That Face”

The Surveillance System That Forgot to Surveil Itself

Officials were careful to note that some of the compromised data was “unclassified,” which is the federal equivalent of telling someone their house is on fire but reassuring them that the garage, technically, has not yet ignited.

The “unclassified” data in question reportedly included: personal information, phone call records, surveillance metadata, and detailed records of who the FBI was investigating and why.

Just your everyday non-classified pile of the most sensitive counterintelligence information in the Western hemisphere.

A FOIA request filed by this reporter for the internal memo defining “unclassified” was returned with the helpful notation: “This document has been classified.”

Metadata — the data they keep insisting isn’t really data — turned out to know everything worth knowing: who you called, when, how often, from where, for how long, and, in some cases, on behalf of which federal investigation. It knows everything about you except your mother’s maiden name, and frankly, if you gave it another afternoon, it would figure that out too.


LEAKED MEMO: FBI Cyber Division — Internal Guidance (UNCLASSIFIED)

TO: All Field Offices
FROM: Cyber Division, Washington HQ
RE: Recent “Major Incident” — Talking Points for Stakeholder Communication
CLASSIFICATION: UNCLASSIFIED (Please Do Not Publish)

Effective immediately, all staff are reminded to describe the recent intrusion as a result of “sophisticated tactics employed by a nation-state threat actor.” Under no circumstances are personnel to use the phrases “we forgot to update something,” “the door was open,” or “honestly, this was bound to happen.”

When asked about the duration of unauthorized access, staff should respond: “We are not able to comment on the operational timeline at this time,” and then immediately change the subject to encryption backdoors, which we still want.

Reminder: Congress has been notified. A formal hearing has been scheduled. Please have your “concerned but not alarmed” face ready. The “alarmed but competent” face is also acceptable. The “genuinely panicking” face is reserved for Deputy Directors only.

Additionally, all staff are encouraged to switch to encrypted messaging applications. Yes, the same ones we spent thirty years trying to outlaw. That is correct. Please do not mention this to journalists.

— Cyber Division Leadership
P.S. — The router still hasn’t been updated. IT says Q3. We said that last Q3.


The Wiretappers Got Wiretapped: A Brief History of Irony

The Surveillance System That Forgot to Surveil Itself

The hack targeted CALEA systems — infrastructure that American telecom companies are legally required to build and maintain specifically so that the government can listen to phone calls. Congress mandated this in 1994, when the internet was a novelty and “cybersecurity” was a word that appeared mainly in science fiction.

The logic was simple: build a door. Put a lock on it. Give the FBI the key. What could go wrong?

What went wrong, it turns out, is that when you build a mandatory backdoor into the backbone of American telecommunications infrastructure, you create a mandatory vulnerability in the backbone of American telecommunications infrastructure. The hackers — operating at the direction of China’s Ministry of State Security — simply knocked on the door that the government required everyone to install, tried the handle, and walked in.

“Something like Salt Typhoon was bound to occur and probably will again if nothing is changed,” testified cybersecurity expert Matt Blaze before Congress in April 2025, in the most politely delivered “I told you so” in the history of expert testimony.

The FBI’s response to this revelation? They are now recommending Americans use encrypted messaging apps — the very same encrypted apps the Bureau has spent three decades lobbying Congress to backdoor, ban, regulate, and generally treat as evidence of a suspicious character.

The lifeguard, having finally noticed they cannot swim, is now distributing flotation devices and recommending everyone stay out of the water.


China Might Be Responsible, Which Means This Is an International Potluck of Blame

U.S. officials have attributed the intrusion to Salt Typhoon, a Chinese state-sponsored hacking group linked to Beijing’s Ministry of State Security. By August 2025, the FBI confirmed the group had compromised over 200 companies across 80 countries, including AT&T, Verizon, T-Mobile, Lumen Technologies, Charter Communications, and Windstream — essentially every major American telecom you have yelled at on hold.

China has denied all involvement. This is standard operating procedure in international cyber espionage, equivalent to a man standing in your kitchen eating your sandwich and, when asked, explaining that he has never seen a sandwich and does not know what bread is.

The Treasury Department responded in January 2025 by sanctioning Sichuan Juxinhe Network Technology Co., a Chinese firm accused of “direct involvement” in the operation. The company has denied this. The sandwich, they note, was already on the counter.

Senator Mark Warner, Vice Chair of the Senate Intelligence Committee, called the telecom campaign “the worst telecom hack in our nation’s history” — a designation that represents remarkable competition given the year we’ve been having.

“From Salt Typhoon to Stryker to now this reported breach at the FBI, the pattern is clear,” Warner warned. “Our adversaries are probing for weaknesses, and they’re finding them.”

Dr. Constance Vague, Director of the Center for Geopolitical Obvious Observations, offered additional context: “When a foreign government spends years inside your surveillance infrastructure, that’s what we technically refer to in the field as ‘bad.'”


“All Technical Capabilities Deployed” Is Bureaucrat for “Someone Restarted a Router”

The FBI announced it had deployed “all technical capabilities” in response to the breach. This phrase sounds, on first reading, like Iron Man suiting up. In practice, it means a team of exhausted federal contractors drank a lot of coffee and changed some passwords that hadn’t been touched since the Obama administration.

“Sophisticated tactics” is the other phrase doing a lot of structural heavy lifting in official communications. Every government breach is sophisticated. Never routine. Never preventable. Never the result of a known vulnerability that had been sitting in a public advisory since 2017, unpatched, waiting patiently like a Golden Retriever by the front door.

Salt Typhoon’s actual entry method? They exploited known vulnerabilities in routers, firewalls, and VPN products — the digital equivalent of walking through a door labeled “DO NOT ENTER” while wearing a hi-vis vest that says “Authorized Personnel.”

The hack is sophisticated in the same way that a pickpocket is sophisticated when their target has left their wallet on the sidewalk with a note that reads “please do not steal.”


Congress Was Notified, a Hearing Has Been Scheduled, Nothing Will Be Fixed

America’s Surveillance System Just Became Everyone’s Surveillance System

Congress was formally notified of the breach, triggering the full apparatus of American legislative response: a scheduled hearing, a press statement, and a bipartisan display of furrowed brows.

Nothing strikes fear into the hearts of state-sponsored hackers like the knowledge that, in approximately six to eight weeks, a subcommittee will convene, and several senators who cannot explain what a router is will spend four hours asking a cybersecurity expert to explain what a router is, before adjourning without changing a single password.

The Cyber Safety Review Board was, in fact, investigating the original Salt Typhoon breach when the Trump administration fired all its members before the investigation could be completed. The board’s findings — potentially the most comprehensive government assessment of the hack’s scope and damage — remain unfinished.

This is what is technically known in policy circles as “not great timing.”

Meanwhile, the FBI is simultaneously facing proposed budget cuts of approximately $500 million, staff reductions, and three separate cybersecurity incidents in March 2026 alone — the surveillance network breach, the disclosure of a 2023 hack of the New York field office (exposing Epstein investigation files), and a breach of FBI Director Kash Patel’s personal email.

At some point, you stop calling these incidents and start calling them a subscription service.


The FBI Now Knows How It Feels to Be Everyone Else

For decades, ordinary Americans have operated under a quiet ambient understanding that someone, somewhere, is probably watching. That a phone call is never quite private. That metadata is collected. That the fiber optic cables singing under their feet carry, in addition to cat videos and payment confirmations, a faint hum of government attention.

Now the FBI gets to enjoy that same cozy blanket of ambient surveillance paranoia. Welcome to the club. Membership is free. There are no refreshments. The terms of service are forty pages long and nobody reads them.

“They weren’t just listening to Americans,” said a former senior official familiar with the investigation. “They were listening to us listening to Americans.”

It’s recursive. It’s Kafkaesque. It’s a Shakespeare play, but with more Wi-Fi and a $10 million FBI bounty for anyone who can identify the actors.


Somewhere, an Intern Is Being Asked If They Clicked Anything Weird

In every security incident in the history of institutional computing, there is a 23-year-old.

They are sitting in a conference room they were not expecting to be in. There is a cup of coffee in front of them, going cold. Someone with a tie — someone who has never fixed a printer in their life — is asking, with the measured calm of a person who is not calm: “Did you click anything unusual in the last… let’s say… two to three years?”

The intern is reconsidering their career choices. They are thinking about their college major. They are thinking about the agricultural sciences program they almost enrolled in. The cows, they reflect, cannot hack the cows.

The cows are fine. The cows don’t have CALEA compliance requirements.


📊 BOHINEY.COM POLL — National Survey on the FBI Hack

Q: When you heard the FBI’s surveillance system had been hacked, what was your first reaction?

  • ✅ 63% — “Wait… they lost what?
  • ✅ 19% — “Honestly, fair enough.”
  • ✅ 11% — “I need to call my cousin and make sure this is why he stopped texting.”
  • ✅ 5% — “This explains some things.”
  • ✅ 2% — “I would like to subscribe to the Salt Typhoon newsletter.”

Methodology: 1,200 respondents. Margin of error ±3.1%. Survey conducted via encrypted messaging app, because apparently that’s what we do now.


The Sincere Turn Nobody Asked For But Everybody Needed

The Surveillance System With a Backdoor and No Bouncer

Here’s the part where it stops being funny — or rather, where it was always never funny, and the jokes were just the wrapper we use when the actual contents are too uncomfortable to hand someone directly.

The FBI built a legal requirement — CALEA — that forced every American telecom to install a surveillance backdoor. The argument was always that only the good guys would use it. That the door would have a very good lock. That the key would never fall into the wrong hands.

Salt Typhoon found the door, picked the lock, walked in, sat down, and watched the FBI watch Americans for years. They saw the targets. The evidence. The investigations. The informants. The intelligence priorities of the United States government, laid out like a buffet.

This is not a story about hackers. It’s a story about what happens when government demands power it cannot secure, builds infrastructure it cannot protect, and then acts surprised when someone else uses it first.

The most expensive surveillance system in history just became the most expensive lesson in why backdoors are everyone’s problem — including the people who built them.

The watchers were watched. The question that lingers, quiet and uncomfortable beneath all the congressional hearings and press statements and rotating cast of official spokespeople, is simple:

What exactly did they see?


The FBI’s surveillance infrastructure, operating under the 1994 Communications Assistance for Law Enforcement Act, was compromised in what Senator Mark Warner called the worst telecom hack in American history. The hacking group Salt Typhoon, linked to China’s Ministry of State Security, breached at least nine major U.S. telecoms — including AT&T, Verizon, and T-Mobile — accessing call records for over a million Americans and intercepting communications from both the Trump and Harris presidential campaigns. Victims included phones belonging to Donald Trump and JD Vance. By August 2025, the FBI confirmed Salt Typhoon had compromised over 200 companies across 80 countries. The Trump administration disbanded the Cyber Safety Review Board before it completed its investigation of the breach. The FBI subsequently offered a $10 million bounty for information on Salt Typhoon operators and — in a striking reversal of its decades-long position — began recommending Americans use encrypted messaging apps. March 2026 brought three separate FBI cybersecurity incidents, including a breach of the surveillance network, exposure of Epstein investigation files, and a hack of Director Kash Patel’s personal email.

Auf Wiedersehen, amigo!

The Surveillance System That Got Surveilled

 

By Ingrid Fischer

Ingrid Fischer is an operations and logistics executive recognized for transforming large-scale distribution networks across Europe. She studied business engineering at the Karlsruhe Institute of Technology and later completed executive logistics training in Rotterdam. Her career includes leadership roles in Cologne, Rotterdam, and Copenhagen. Fischer’s expertise centers on operational resilience, ethical procurement, and data-driven performance metrics. She is known for transparent supplier relationships and strict enforcement of labor and sustainability standards. Her leadership style emphasizes accountability, safety, and long-term operational trust. Email: [email protected]