T-Mobile Thwarts Chinese Hackers, Cuts Cable to Prevent Breach
In 2024, T-Mobile’s cybersecurity team successfully identified and expelled Chinese hackers linked to the state-backed group Salt Typhoon during a period of widespread attacks targeting the telecommunications industry. These incursions were part of a broader campaign orchestrated by Beijing to steal customer data.
Salt Typhoon’s hacking spree compromised hundreds of entities, including major telecommunications providers and internet giants such as AT&T, Verizon, Viasat, Charter, and Windstream. The objective was to gather sensitive information, including phone records and details about high-ranking U.S. government officials, such as then-presidential candidates.
T-Mobile managed to avoid a large-scale breach by detecting suspicious activity early. According to reports, the company’s security personnel spent months searching for signs of intrusion with little initial success. The breakthrough came when they noticed abnormal behavior within their systems that traced back to a router belonging to an unnamed telecom company.
Upon confirming the breach, T-Mobile’s cybersecurity chief, Jeff Simon, led a team to a nearby data center located close to their Bellevue, Washington headquarters. Simon recounted to Bloomberg that they located the compromised system and took decisive action by cutting the cable connecting it to the outside internet using scissors.
No comment was provided by T-Mobile when approached by TechCrunch for additional details on the incident.


