Skip to content
News

T-Mobile Severed a Cable to Stop Salt Typhoon Hackers

T-Mobile Severed a Cable to Stop Salt Typhoon Hackers
T-Mobile stopped a Salt Typhoon hacking attempt by severing a cable link to a compromised wireline provider, protecting customer data from the intrusion.

T-Mobile relied on a decidedly low-tech method to keep intruders out of its network during a wave of attacks on American telecommunications providers. In 2024, several US carriers, including AT&T and Verizon, were infiltrated by a Chinese state-backed group known as Salt Typhoon. The attackers came close to reaching T-Mobile as well, but a straightforward move stopped them.

Jeff Simon, then T-Mobile’s Chief Security Officer and since promoted to Chief Information Officer, disclosed in 2024 that hackers had tried to enter the operator’s network through a wireline company’s network that was connected to it. The carrier detected the threat early enough to block access to customer data and cut the connection to the compromised provider’s network.

How the Intrusion Was Traced

T-Mobile was already on heightened alert following a 2023 breach that exposed the data of 37 million customers. When staff learned of the Salt Typhoon campaign, they flagged a router behaving oddly at a California data centre, which was communicating with another T-Mobile device. On inspection, the router was found to be powered off.

Simon ordered the device removed. Since the suspicious activity could not have originated from the switched-off router, the team investigated further and traced the traffic to another provider’s router in Chicago. That router had been disguised to imitate the California unit, making it easier to connect with a T-Mobile device at a data centre near the company’s Bellevue headquarters.

Simon and his colleagues travelled to the location and cut the cable linking the device to the network with a pair of scissors. The severed cable is now displayed at the company’s headquarters.

What the Attackers Reached

T-Mobile later reactivated the router in an isolated environment and analysed it, though the attackers were long gone by then. While the group did not breach T-Mobile’s core infrastructure or subscriber data, it did access other routing infrastructure at the edge of the network.

Simon noted that a virtual shutdown was possible, but explained that a low-tech solution sometimes works best. “There’s nothing that replaces cutting the cord,” he said in August 2026.

Access to T-Mobile’s core routers could have allowed the hackers to siphon off information, redirect traffic, and inject malicious software. US officials believed the campaign was aimed primarily at intelligence gathering. The same group successfully entered the systems of AT&T and Verizon, stealing phone data from millions of people across the United States and targeting the handsets of Donald Trump, JD Vance, and Kamala Harris.

Source
Image: phonearena.com

The UK tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your UK list is ready.

Shop on Amazon UK — Discover deals Shop on Amazon UK — Discover deals