Salt Typhoon, changing messaging protections and the corporate COMSEC response
By Navid Sobbi, Founder and CEO, NSI Global
ORIGINALLY PUBLISHED: 5 December 2024 | SUBSTANTIVELY REVISED: 28 August 2026
The headline refers to the original 2024 warning. This update separates that event from later technology changes and distinct threat activity.
Key Judgements
- Sensitive business conversations need an approved channel, verified participants and appropriately managed devices. An encrypted application addresses only part of that requirement.
- The 2024 telecommunications warning remains relevant, but messaging technology has changed. Cross-platform RCS encryption is now available in supported configurations; check the actual conversation, not only the handset brand. [3–4]
- A separate FBI/CISA warning in March 2026 concerned attacks on messaging accounts, not a defeat of their encryption. Network interception and account compromise require different controls. [5]
An executive discussing an acquisition, a lawyer coordinating a confidential matter and a crisis team handling an incident have something in common: their conversation may be valuable before a formal document ever exists. Communications security, or COMSEC, should therefore start with what is being discussed, who needs to participate and how those people will communicate under pressure.
What the Original Warning Established
In November 2024, the FBI and the US Cybersecurity and Infrastructure Security Agency described Chinese state-affiliated intrusions into multiple telecommunications networks. Their statement distinguished stolen customer call records from private communications involving a limited group of people, mainly associated with government or political activity. It also identified copied information connected with court-authorised law-enforcement requests. These were different categories of exposure, not evidence that every subscriber’s conversation had been intercepted. [1]
The campaign commonly discussed as Salt Typhoon matters beyond the United States. A multinational advisory published by ASD’s Australian Cyber Security Centre in August 2025 described related Chinese state-sponsored network compromises and reported activity observed in Australia. Its authors cautioned that the activity only partially overlapped with several industry threat-group labels. [2]
That provides a concrete Australian reason to review communications arrangements. It does not establish that every Australian carrier, business or executive has been compromised. The proportionate response is to identify consequential conversations and reduce avoidable exposure, without making an unsupported finding about a particular organisation.
What Has Changed for iPhone and Android Messaging
On 11 May 2026, Apple announced the start of a beta rollout of end-to-end encrypted RCS between supported iPhone and Android configurations. The announcement specified iOS 26.5, participating carriers and the latest Google Messages on Android. This was a rollout, not an assurance of universal coverage. [3]
Apple’s current support guidance says an RCS conversation requires encryption support from every participant’s provider. An encrypted conversation displays a lock and an “Encrypted” label. SMS/MMS remain outside end-to-end encryption, and green message bubbles alone do not distinguish all these possibilities. [4]
For organisations, the practical consequence is straightforward: do not write a communications policy around the assumption that all cross-platform messages are unencrypted—or that all RCS messages are protected. Specify which service and configuration are approved for the information being exchanged. If staff cannot confirm the required protection, move the discussion to the pre-approved alternative instead of improvising a fallback.
Understand the Boundary of Encryption
End-to-end encryption is designed to restrict readable message content to the communicating endpoints. It is valuable against interception between those endpoints, but it is not a guarantee about everything that happens before a message is sent or after it arrives. ASD’s guidance separately addresses encrypted communications, device hardening and control of meeting participants. [6–7]
Use the following distinctions when evaluating a communications arrangement. They are management questions, not a certification checklist.
| Exposure | What must be assessed |
| Content intercepted in transit | Is end-to-end protection active for this conversation and its participants? Encryption of a network connection alone does not establish protection for the whole conversation. |
| Access to a participating device | Could an unauthorised person or malicious software obtain readable content at an endpoint? Review device access and management separately from the messaging protocol. |
| Wrong or unexpected participants | Who approved the membership, and how was identity checked? An encrypted discussion can still include someone who should not receive it. |
| Copies and communications records | Where do recordings, exports, backups and service records go? Assess each separately; do not assume the protection of live messages governs every retained copy. |
Content confidentiality is also different from concealing communications metadata. For example, Apple describes RCS service setup involving identifiers such as a phone number and, depending on the provider, an IP address. An encrypted message is not a promise of anonymity. [4]
Account Hijacking Is a Separate Threat
In March 2026, the FBI and CISA warned that Russian intelligence-linked actors were targeting commercial messaging accounts, including Signal accounts. The agencies described phishing involving impersonated support services, verification information and malicious device-linking requests. They explicitly distinguished account compromise from compromise of the applications or their encryption. This was a separate campaign, not a new attribution for Salt Typhoon. [5]
For sensitive groups, assign responsibility for checking unexpected membership or linked-device changes. Staff should know how to validate a purported support request independently, and never treat a familiar profile picture as proof of identity. These practices protect the people and access surrounding an encrypted conversation.
Give Sensitive Conversations a Short Operating Brief
NSI recommends a short communications brief for a defined activity—a transaction, executive trip or crisis response—rather than relying on a general instruction to “use encryption”. The following is a proposed planning approach, not a claim that one arrangement suits every organisation.
Define the Discussion and Its Owner
Name the activity, its accountable owner and the types of information expected. Distinguish meeting logistics from negotiation positions, unreleased financial information or confidential technical detail. Decide which material belongs in a controlled document repository rather than being copied into a chat.
This gives staff a usable boundary. A communications rule should help them decide what to do with the next message, not simply describe the importance of confidentiality.
Agree the Channel Before It Is Needed
Record the approved voice and messaging services, the people who administer them and the alternative route if the main channel is unavailable. Include external advisers in the test: a tool that only works for internal staff may fail at the moment a third party needs to join.
Run a short rehearsal using the intended participants and devices. Check how invitations, group changes and loss of connectivity appear to users. Establish who can authorise an exception and what information must be withheld until an approved channel is available.
Check Participation and the Physical Setting
Keep the participant list tied to the activity instead of maintaining an indefinitely growing executive group. Decide who may invite others and when access should end. ASD advises caution with large messaging groups and recommends private meeting locations and control of attendees. Those considerations remain relevant even when the software provides strong encryption. [6]
Make recording, transcription and meeting-assistant use an explicit decision. Participants should understand whether these functions are permitted and where their outputs would be stored before sensitive discussion begins.
Include Devices in the Arrangement
Identify which managed phones and computers are permitted to participate. Confirm that the responsible team can maintain updates, enforce appropriate access settings and manage applications throughout the activity. ASD’s enterprise mobility guidance treats a continuing management policy and timely security updates as distinct controls; an initially secure configuration can deteriorate. [7]
For travel, consider a reduced-data device where the risk assessment justifies it. Agree the contact method for a lost phone before departure. Avoid turning a temporary exception into a permanent, unmanaged communications route.
Decide What Must Be Kept
Agree how business decisions will be recorded, which message history is needed and who controls retention. Review backup and export arrangements as part of that decision. Disappearing messages should not be used to defeat recordkeeping or evidence-preservation obligations; the March 2026 FBI/CISA advice itself conditions message-expiration settings on applicable retention requirements. [5]
The useful distinction is between reducing unnecessary copies and discarding a record the organisation needs to preserve. Security, legal and records-management teams should resolve that distinction before the conversation starts.
When Enterprise-Managed COMSEC Is Appropriate
An organisation may need more than a staff-selected messaging app when it requires centrally controlled enrolment, consistent configuration, specific deployment arrangements or a supported service for a defined executive group. The reason to consider enterprise COMSEC is a documented requirement—not the assumption that every consumer application lacks effective encryption.
BlackBerry describes SecuSUITE as a secure voice and messaging offering with enterprise deployment options. That makes it a candidate for assessment, not an automatic answer for every business. Product selection should examine the actual version, supported devices, operating model and proposed implementation. [8]
Ask suppliers to demonstrate the features that matter to the engagement: participant enrolment and removal, device replacement, administrative access, service continuity and handling of retained information. Check how the proposed solution works with external participants and what happens when a required feature is unavailable.
If a procurement relies on a certification or government approval, obtain evidence for the exact product, configuration and permitted use. A general marketing description is not enough to establish suitability for a particular classification or contractual obligation.
If a Device or Conversation May Be Compromised
Use a separately verified device and channel to reach the security team when the existing route may be monitored. Distinguish a suspicious invitation from a lost handset or evidence of malicious software; these findings call for different investigation and containment decisions.
Record what prompted the concern and obtain incident-response advice before making changes that could remove useful evidence. Do not discuss the investigation in the suspect group. If unauthorised access is confirmed, the response should address affected participants and conversations as well as the technical access path. This is a communications-continuity issue, not simply a request to reinstall an application.
Frequently Asked Questions
Is Every iPhone-to-Android RCS Chat Encrypted?
No. Apple’s supported-provider rollout does not make every conversation eligible. Check the encryption status shown for the specific chat and confirm that the arrangement meets your organisation’s requirements. [4]
Can Encryption Protect a Phone That Has Spyware?
It does not remediate an infected endpoint. Readable information may be exposed on a participating device even where its transmission is encrypted. Device concerns need their own assessment. [7]
Does a Business Need Special Encrypted Handsets?
Not necessarily. Begin with the information sensitivity, participants and management requirements. The appropriate arrangement may use managed existing devices, a dedicated service or purpose-specific equipment; the label on the handset is not the assessment.
Are Disappearing Messages the Best Default?
There is no universal setting. Determine the required business record and applicable preservation needs first, then configure message history accordingly. Automatic deletion must not replace a retention decision. [5]
How NSI Global Can Assist
NSI Global provides communications security solutions for corporate and government requirements. A useful starting point is to discuss the conversations to be protected, their participants and the organisation’s operational constraints before selecting equipment or applications.
Where the concern is possible device monitoring, NSI’s forensic spyware and malware detection service provides a separate investigation pathway. Examination findings depend on the available device, evidence and scope; no communications product or forensic assessment can promise the absence of every threat.
Contact NSI Global to discuss the communications requirement or a suspected compromise. Keep sensitive details off any channel you believe may be affected.
Sources and Reading Notes
[1] FBI and CISA. Joint statement on Chinese targeting of commercial telecommunications infrastructure. 13 November 2024. Incident scope and categories of exposed information.
[2] ASD’s ACSC and international partners. Countering Chinese state-sponsored network compromises. 28 August 2025. Australian relevance and qualified threat-group naming.
[3] Apple. End-to-end encrypted RCS messaging begins rolling out in beta. 11 May 2026. Initial cross-platform rollout requirements.
[4] Apple Support. Differences between iMessage, RCS and SMS/MMS. 25 May 2026. Conversation indicators, provider dependencies and RCS identifiers.
[5] FBI and CISA. Russian intelligence services target commercial messaging application accounts. 20 March 2026. Separate account-targeting campaign and related precautions.
[6] ASD’s ACSC. Practical cyber security tips for business leaders. Used for group membership, meeting environment and travel considerations. Its older cross-platform messaging description is not used; current Apple documentation governs that discussion here.
[7] ASD’s ACSC. Information Security Manual: enterprise mobility. Reviewed 28 August 2026. Device-management principles; the article does not assert that every ISM control is mandatory for every private business.
[8] BlackBerry. SecuSUITE product information. Reviewed 28 August 2026. Vendor capability description, not independent assurance of a proposed deployment.