T-Mobile chopped a cable to expel Salt Typhoon hackers
T-Mobile cybersecurity staff physically chopped a network cable in 2024 after spotting Salt Typhoon, a Chinese government-backed hacking group, trying to piggyback into the carrier through another telecom's router. The low-tech cut, near T-Mobile's Bellevue headquarters, helped the company avoid a widescale breach of customer data even as rivals including AT&T and Verizon were hit.
Key Takeaways
- T-Mobile staff used scissors to cut a cable and expel suspected Salt Typhoon access in 2024.
- The activity came from an unnamed partner telecom's router, not T-Mobile's powered-off California box.
- Core systems and subscriber data were not breached, though some edge routing infrastructure was reached.
- The same campaign hit AT&T, Verizon, Viasat, Charter, and Windstream, according to reporting.
What did T-Mobile actually cut, and why?
According to TechCrunch, citing Bloomberg, T-Mobile's cyber team spent months hunting suspected hackers without success. Unusual traffic on a T-Mobile system was eventually traced to a router owned by a different, unnamed telecom company.
PhoneArena, also citing Bloomberg, says staff first flagged a router at a California data center that appeared to communicate with another T-Mobile device. When they checked, that router was powered off. Then-chief security officer Jeff Simon, later promoted to chief information officer, ordered the device ripped out.
Investigators traced the traffic to another provider's router in Chicago. PhoneArena reports it had been disguised to imitate the California unit so it could connect with a T-Mobile device at a data center near Bellevue, Washington headquarters.
Simon told Bloomberg he and colleagues drove to the site and snipped the cable with scissors. TechCrunch says Simon and three others made the trip. T-Mobile did not comment when TechCrunch asked.
Did Salt Typhoon steal T-Mobile customer data?
No, according to the accounts T-Mobile later expanded for Bloomberg. The Un-carrier said it detected the threat early enough to block access to customer data and severed the connection to the compromised provider's network.
Attackers did not reach T-Mobile's core infrastructure or subscriber data. They did get into some other routing infrastructure on the edge of the network. Staff later reactivated the router in an isolated environment, but the attackers were already gone.
Simon said a remote shutdown was possible, but a physical cut left no doubt. “There's nothing that replaces cutting the cord,” he said. The severed cable is displayed at headquarters as a badge of honor.
T-Mobile was already on alert after a 2023 breach that exposed data of 37 million customers. That history helps explain why a visible, irreversible disconnect was chosen over a purely virtual isolation.
Why does the Salt Typhoon campaign still matter?
Salt Typhoon is described as a Chinese state-backed group that infiltrated several U.S. telecom providers in 2024, including AT&T and Verizon. TechCrunch reports the campaign compromised hundreds of phone companies, internet giants, and data center providers.
The goal was collecting phone records and information about senior U.S. officials, including then-presidential candidates. PhoneArena says U.S. officials viewed the effort as intelligence gathering, and that hackers stole phone data of millions and targeted handsets of Donald Trump, JD Vance, and Kamala Harris.
Access to core routers could have let attackers siphon information, redirect traffic, and inject malicious software. T-Mobile's edge-only impact is the contrast with peers who were more deeply compromised.
For readers who watch identity theft, payments fraud, and account takeovers in our Fintech & Crypto Alerts coverage, a carrier-level spy campaign is the upstream risk: if call records and routing are exposed, financial accounts can follow.