T-Mobile Cut a Cable to Expel China Backed Salt Typhoon Hackers
T-Mobile stopped Salt Typhoon's 2024 intrusion after tracing suspicious traffic from another telecom, then cutting a Bellevue data center cable by hand.
Summary
Bloomberg reported that T-Mobile detected and expelled Chinese government backed Salt Typhoon hackers from its network in 2024, largely avoiding a widespread breach by catching the intrusion early. The campaign compromised hundreds of phone companies, internet companies and data center providers to collect phone records and information on senior U.S. government officials, including then presidential candidates. Victims included AT&T, Verizon, Viasat, Charter and Windstream.
T-Mobile cybersecurity staff searched unsuccessfully for months before finding unusual activity on one system originating from a router owned by an unnamed telecom company. Cybersecurity chief Jeff Simon and three colleagues drove to a nearby Bellevue, Washington, data center, located the compromised system and used scissors to cut its external cable. TechCrunch reported the account on August 19, 2026, and contacted T-Mobile for further information.
Positives
- T-Mobile largely avoided a widespread network breach by detecting Salt Typhoon's activity early in 2024.
- Jeff Simon and three colleagues physically isolated the compromised system at a Bellevue, Washington, data center.
- T-Mobile traced unusual system behavior to a router owned by another, unnamed telecom company.
Risks & concerns
- Salt Typhoon compromised hundreds of phone companies, internet companies and data center providers.
- AT&T, Verizon, Viasat, Charter and Windstream were among the companies breached during the Chinese government backed campaign.
- T-Mobile cybersecurity staff searched for suspected hackers for months before locating the intrusion.
- Salt Typhoon sought phone records and information about senior U.S. officials, including then presidential candidates.