T-Mobile 'chopped a cable' to expel Chinese hackers from its network
TechCrunch
β’Wed, 19 Aug 2026 17:26:32 +0000
π° What Happened
Bloomberg reported that T-Mobile cybersecurity staff identified and expelled Chinese government-backed hackers from the Salt Typhoon group from its network in 2024, physically cutting the cable to a compromised system to disconnect it. After months of searching, T-Mobile found unusual activity tied to a router belonging to another, unnamed telecom company, and its cybersecurity chief Jeff Simon said he and three others drove to a data center in Bellevue, Washington and snipped the cable connecting the compromised box to the outside world. T-Mobile largely escaped a wide-scale breach by catching the activity early.
π The Backstory
Salt Typhoon is a Chinese state-backed hacking group whose campaign compromised hundreds of phone companies, internet giants and data-center providers, including AT&T, Verizon, Viasat, Charter and Windstream, aiming to collect phone records and information about senior US government officials and then-presidential candidates.
π― Why It Matters
The incident underscores the scale and seriousness of Chinese cyber intrusions into US telecommunications infrastructure and highlights the extreme but effective defensive measures companies have taken against sophisticated state-backed hackers.
Bloomberg reported that T-Mobile cybersecurity staff identified and expelled Chinese government-backed hackers from the Salt Typhoon group from its network in 2024, physically cutting the cable to a compromised system to disconnect it. After months of searching, T-Mobile found unusual activity tied to a router belonging to another, unnamed telecom company, and its cybersecurity chief Jeff Simon said he and three others drove to a data center in Bellevue, Washington and snipped the cable connecting the compromised box to the outside world. T-Mobile largely escaped a wide-scale breach by catching the activity early.
Salt Typhoon is a Chinese state-backed hacking group whose campaign compromised hundreds of phone companies, internet giants and data-center providers, including AT&T, Verizon, Viasat, Charter and Windstream, aiming to collect phone records and information about senior US government officials and then-presidential candidates.
The incident underscores the scale and seriousness of Chinese cyber intrusions into US telecommunications infrastructure and highlights the extreme but effective defensive measures companies have taken against sophisticated state-backed hackers.