How T-Mobile Severed a Cable to Expel Chinese Hackers From Its Network
Cybersecurity personnel at United States telecommunications provider T-Mobile took the drastic step of physically cutting a network cable to remove Chinese state-backed hackers from their systems in 2024, according to reporting by Bloomberg. The incident occurred amid a broader campaign targeting major communications networks across the country.
What Happened
In 2024, Chinese government-sponsored hackers belonging to the group known as Salt Typhoon launched widespread cyber intrusions aimed at telecommunications firms, data centers, and internet service providers. While T-Mobile’s cybersecurity specialists spent months searching for signs of intrusions inside their infrastructure without success, they eventually spotted unusual activity on an internal system. The anomalous traffic was traced back to a router belonging to another telecom company, which has not been publicly identified.
Upon confirming the breach, T-Mobile Chief Cybersecurity Officer Jeff Simon and three colleagues traveled directly to a data center situated near the company’s Bellevue, Washington headquarters. After locating the affected machine, the team utilized a pair of scissors to physically snip the connection cable, immediately severing the compromised device from the outside network. T-Mobile managed to prevent a wide-scale breach of its systems due to this early detection and physical disconnection.
Key Highlights
- Targeted Actor: The breach attempt was conducted by Salt Typhoon, a Chinese state-backed cyber group.
- Broad Infiltration: Salt Typhoon compromised hundreds of internet providers, phone carriers, and data center operators to harvest phone records and data belonging to senior U.S. officials, including presidential candidates.
- Impacted Providers: Affected telecommunications and infrastructure firms included Verizon, AT&T, Viasat, Charter, and Windstream.
- Physical Intervention: T-Mobile’s cybersecurity head Jeff Simon and three team members physically snipped the affected server cable in a Bellevue data center to eliminate outside access.
- External Router: The intrusion routed into T-Mobile’s environment via hardware owned by an unnamed third-party telecom provider.
Why This Matters
The incident illustrates the severe operational reach of the Salt Typhoon espionage campaign, which successfully penetrated critical national telecommunications infrastructure. The intrusions focused on intercepting sensitive communications records and tracking high-level government figures and political candidates. By taking rapid and direct physical action to disconnect the compromised system, T-Mobile was able to halt the intrusion before it escalated into a broader network compromise, even as major peers such as AT&T, Verizon, Charter, Windstream, and Viasat suffered breaches.
What to Watch Next
Following the revelations published by Bloomberg, T-Mobile declined to provide comment when approached by TechCrunch. Official details regarding how the unnamed telecom partner was initially compromised or whether further security safeguards have been established at shared network junctures have not been disclosed.
Frequently Asked Questions
Who conducted the cyber intrusions against T-Mobile?
The attacks were carried out by Salt Typhoon, a cyber group backed by the Chinese government that aimed to harvest customer communications data and target senior political officials.
How did the hackers gain entry to T-Mobile’s system?
According to Bloomberg, T-Mobile identified suspicious activity on one of its machines that originated from a router owned by another telecommunications company, which was not identified.
How was the compromised system disconnected?
T-Mobile cybersecurity chief Jeff Simon and three team members drove to a data center near Bellevue, Washington, found the affected hardware, and cut the external connectivity cable using a pair of scissors.
Source: Based on reporting from Bloomberg and TechCrunch.
