
T-Mobile cybersecurity staff physically cut a network cable in 2024 after tracing suspicious activity to a compromised system linked to China-backed hacking group Salt Typhoon, according to new reporting from Bloomberg. The intervention helped the U.S. carrier avoid the broader network breaches that affected several other telecommunications companies during the same campaign.
The Bloomberg report details how T-Mobile spent months searching its network for signs of the attackers. The breakthrough came when staff detected unusual behavior on one of its systems that appeared to originate from a router belonging to another unnamed telecom provider.
T-Mobile Staff Went Directly to the Data Center
After identifying the affected system, T-Mobile cybersecurity chief Jeff Simon and three colleagues drove to a data center near the company’s Bellevue, Washington headquarters. They located the compromised equipment and used scissors to cut the cable connecting it to the outside network, Bloomberg reported.
The physical disconnection removed the system from external access while the company dealt with the intrusion. T-Mobile had previously said it detected suspicious activity before Salt Typhoon could gain broader access to sensitive customer information.
Salt Typhoon is a Chinese government-backed hacking group linked to a large campaign targeting telecommunications and internet infrastructure. The operation compromised hundreds of companies as attackers sought phone records and information associated with senior U.S. government officials, including people who were presidential candidates at the time.
Salt Typhoon Targeted Major U.S. Telecom Networks
Companies affected by the campaign included AT&T, Verizon, Viasat, Charter, and Windstream. U.S. authorities have said the group compromised at least 200 American companies as part of a wider campaign spanning telecom providers, internet companies, and data center operators.
T-Mobile was also targeted, but the company appears to have avoided a large-scale compromise by detecting the activity before attackers gained deeper access to its network. Earlier reporting had linked suspicious activity at T-Mobile to the same Salt Typhoon campaign.
The incident highlights the unusual steps T-Mobile took after conventional monitoring failed to locate the attackers for months. In the end, identifying traffic from an external telecom router led the company to the compromised hardware and the decision to disconnect it physically.
Featured image credits: Wikimedia Commons
For more stories like it, click the +Follow button at the top of this page to follow us.
