The Breach That Won’t Stay Contained
In December 2024, the U.S. government confirmed what security researchers had suspected for months: Salt Typhoon, a Chinese state-sponsored threat group, had systematically compromised at least nine major U.S. telecommunications providers. We’re talking AT&T, Verizon, and others. The attackers didn’t just peek at the network; they extracted metadata on over a million individuals and appear to have maintained persistent access to core infrastructure. If you think this is contained and remediated, I have a bridge in Brooklyn I’d like to discuss.
Here’s where it gets uncomfortable for those of us building APIs: these telecom breaches are more than a headline. They’re an active, ongoing threat to the authentication mechanisms we depend on. The February 2026 Mandiant report demonstrated that Salt Typhoon hasn’t packed up and left. Unpatched edge devices, particularly Cisco IOS XE and Fortinet FortiGate appliances, continue to be initial access vectors. The persistence is almost elegant in its mundanity: attackers found vulnerable gear, maintained footholds, and adapted as some systems were patched. This is what happens when you’re playing network defense against a well-funded, patient adversary.
SMS-Based Authentication Just Got Messier
Let’s talk about what this means for the APIs you’re shipping. In January 2026, CISA released updated guidance that should have sent shivers down the spine of anyone still relying on SMS for two-factor authentication. The recommendation was explicit: deprecate SMS-dependent authentication flows and move toward end-to-end encrypted communications. That’s not a gentle suggestion. That’s a warning backed by evidence of what happens when attackers control telecommunications infrastructure.
The problem with SMS is architectural. When you send a one-time password via text message, you’re trusting a system that’s been compromised. An attacker with access to telecom metadata and call routing can intercept or redirect those messages. We’ve known this theoretically for years; Salt Typhoon made it practical reality. If your application is still using SMS as your primary second factor, especially for sensitive operations like API key generation, account recovery, or privilege escalation, you’re running on borrowed time. The CISA guidance on People’s Republic of China telecom intrusions wasn’t released as pleasant reading material. It’s a canary in the coalmine.
Passkeys Are Having Their Moment—And It’s Justified
Here’s the silver lining, and it’s actually genuine: the FIDO Alliance reported a 210% increase in passkey adoption among the top 1000 websites between Q1 2025 and Q1 2026. That’s not hype-driven adoption. That’s enterprises and forward-thinking product teams making calculated decisions in response to real threat intelligence. Passkeys work because they’re fundamentally different from SMS. They’re cryptographic, device-bound, and resistant to phishing. An attacker can’t intercept what doesn’t transit untrusted networks.
If you haven’t experimented with passkey integration, now’s the time. The ecosystem is mature enough. Libraries exist. User experience has improved dramatically from the early days. More importantly, your enterprise customers are starting to expect it. Security teams that have briefed their executive sponsors about Salt Typhoon are now making platform requirements around passwordless authentication. It’s not optional anymore; it’s table stakes. The implementation requires thought, including recovery flows, fallback mechanisms, and cross-device considerations, but these are solvable engineering problems, not architectural impossibilities.
Post-Quantum Cryptography Stops Being Optional
While everyone was focused on the immediate threat of Salt Typhoon, NIST finalized post-quantum cryptography standards in August 2024. If that felt like background noise, stop. At least 14 new state and federal procurement requirements are taking effect in 2026 that cite these standards. This means any vendor seeking government contracts, direct or indirect, needs to demonstrate a migration roadmap. For API developers, this translates to a hard deadline you might not have noticed yet.
The NIST post-quantum cryptography standards aren’t a distant futuristic concern anymore. They’re specification documents with algorithm choices and implementation guidance. If your API relies on traditional RSA or ECC for certificate validation, key exchange, or cryptographic signing, you need to be planning transition pathways now. Hybrid approaches, running both classical and post-quantum algorithms in parallel, are the pragmatic move for 2026. Full replacement can follow, but the groundwork needs to start immediately.
What This Means for Your 2026 API Strategy
Pull together your authentication and cryptography architecture. Start with a brutally honest inventory: where are you using SMS? Where are you still dependent on classical cryptography? What edge devices do you control or depend on? Prioritize deprecating SMS-based 2FA, particularly for privileged operations. Investigate passkey implementation libraries and run pilot programs with early adopters. For cryptography, work with your infrastructure and security teams to develop a post-quantum roadmap. This isn’t a rip-and-replace situation; it’s a multi-quarter evolution.
The uncomfortable truth is that Salt Typhoon represents a shift in the threat model. We’re no longer dealing with opportunistic attackers or even sophisticated but isolated threat groups. We’re dealing with state-level actors with sustained access to critical infrastructure and the patience to maintain it. Your API sits downstream from that infrastructure. That doesn’t mean panic; it means precision. Solid cryptography, passwordless authentication, and deliberate architecture choices are the tools you have. Use them thoughtfully. What’s your current blocker on moving away from SMS-based 2FA? I’d genuinely like to hear what’s stopping teams from making this transition.