started · updated
T-Mobile engineers physically cut cable to stop Chinese hackers
T-Mobile’s cybersecurity team resorted to a physical solution to combat a sophisticated cyberattack by Salt Typhoon, a Chinese state-sponsored hacking group. After months of failing to locate an intruder through digital means, security staff identified unusual activity traced to a router belonging to another telecommunications company.
To isolate the threat, T-Mobile’s chief security officer, Jeff Simon, and three colleagues traveled to a data center near the company’s Bellevue, Washington headquarters and physically severed the cable connecting the compromised system to the outside world. This low-tech intervention helped prevent a widespread breach at T-Mobile, even as the broader Salt Typhoon campaign successfully targeted dozens of other major American telecommunications and internet infrastructure providers, including AT&T, Verizon, Charter, and Windstream.
The espionage campaign aimed to harvest sensitive communications metadata and phone records, specifically targeting senior U.S. government officials and presidential candidates. The FBI has indicated that the Salt Typhoon group has breached at least 200 companies across 80 countries, often targeting wiretap systems maintained by telecom providers.
Entities
CISA · FBI · Jeff Simon · Salt Typhoon · T-Mobile