T-Mobile physically cut a cable to cut off Salt Typhoon hackers, security chief reveals

When T-Mobile discovered that Chinese state-backed hackers had gained a foothold in its network in 2024, the company's response wasn't purely digital. According to details revealed this week, T-Mobile's cybersecurity chief Jeff Simon and three colleagues physically traveled to a data center in Bellevue, Washington, located the compromised hardware, and cut the cable connecting it to the outside world with a pair of scissors.
The intrusion was part of Salt Typhoon, a sprawling Chinese government-backed espionage campaign that compromised telecommunications infrastructure across the United States, including AT&T, Verizon, Viasat, Charter, and Windstream. The campaign's stated goal was to gain access to customer call records and communications involving U.S. government officials and political figures.
Months of investigation before a low-tech fix
T-Mobile's security team spent months investigating unusual network activity before pinpointing the compromised system, which was connected to a router belonging to another telecommunications company. Rather than relying solely on remote remediation — patching, credential rotation, network segmentation — the team chose a method that left no ambiguity: physically severing the connection.
That decision reflects a broader lesson from the Salt Typhoon campaign. Sophisticated nation-state actors operating inside telecom infrastructure can persist for extended periods using legitimate-looking access paths, making purely software-based remediation risky if any foothold is missed. A physically cut cable removes that uncertainty entirely.
Why T-Mobile came out better than its peers
The distinguishing factor in T-Mobile's case was timing: the company detected and contained the intrusion early, before it could expand into the kind of large-scale data exposure that affected other carriers hit by the same campaign. AT&T, Verizon, and the other compromised firms faced broader breaches of customer data and, in some cases, prolonged remediation efforts that stretched over many months.
Salt Typhoon has been described by U.S. officials as one of the most significant telecommunications compromises in the country's history, both for its scale — hundreds of organizations — and for the sensitivity of what it targeted: metadata and communications tied to senior government officials. The campaign has driven renewed scrutiny of how carriers secure the lawful-intercept systems and backend infrastructure that make telecom networks a uniquely attractive target for espionage.
As reported by TechCrunch, the details of T-Mobile's response were disclosed on August 19, 2026, offering a rare look inside how one major carrier handled a nation-state intrusion differently from its peers.
Originally reported by TechCrunch. Read the original article for additional details.
View original source