T-Mobile Staff Physically Cut a Cable to Stop Salt Typhoon Intrusion

T-Mobile Salt Typhoon cyberattack network cable cut China telecommunications hack

T-Mobile specialists were forced to literally cut a network cable to prevent hackers from penetrating the carrier’s infrastructure. The incident took place in 2024, during a large-scale espionage campaign that U.S. authorities have linked to the Chinese state-affiliated threat group Salt Typhoon.

Suspicious Activity Detected in November 2024

T-Mobile first detected suspicious activity in November 2024. In its official statement, T-Mobile explained that someone had attempted to penetrate its infrastructure through the network of another wired telecommunications provider connected to its own systems. The company did not name the provider involved.

Tracing the Intrusion to a Data Center Near Company Headquarters

As later became clear, T-Mobile specialists spent considerable time trying to trace the source of the unusual activity. The trail ultimately led to a network device located in a data center near the company’s headquarters in Bellevue, Washington. T-Mobile’s Chief Information Security Officer, Jeff Simon, traveled there personally alongside three staff members. Upon locating the compromised equipment, the team physically severed the cable connecting the device to the external network.

Back in 2024, T-Mobile had already confirmed that it rapidly disconnected from the other carrier’s network after determining it had been compromised. According to the company, attackers were unable to advance any further, disrupt any services, or gain access to customer calls, voicemail, messages, or other confidential customer information.

Connecting the Dots to Salt Typhoon

At the time, T-Mobile stopped short of definitively attributing the intrusion attempt to Salt Typhoon, instead handing the collected evidence over to U.S. authorities. The FBI later confirmed that the China-linked Salt Typhoon group had breached several American telecommunications companies as part of a broad espionage operation.

Attackers stole call detail records, gained access to the personal communications of a limited number of specifically targeted victims, and copied select information tied to requests from U.S. law enforcement agencies. In August 2025, the FBI reported that traces of Salt Typhoon’s activity had been identified in at least 80 countries, with hundreds of organizations across the United States receiving notifications related to the campaign.

How Salt Typhoon Targeted Network Infrastructure

Salt Typhoon’s primary targets were routers and other network infrastructure belonging to telecommunications carriers. In a joint advisory, U.S. and foreign government agencies noted that the Chinese hackers modified router configurations, established persistence within the networks, and pivoted through trusted connections to reach the infrastructure of other organizations.

Federal Guidance Issued for Telecom Operators

After the campaign came to light, U.S. federal agencies issued dedicated recommendations for telecommunications operators. The agencies advise restricting the set of systems trusted to manage network devices, monitoring configuration changes closely, disabling unnecessary connections, and installing security updates more promptly.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply