T-Mobile Cut a Cable to Stop Chinese Hackers From Its Network
T-Mobile physically cut a network cable after tracing suspicious activity linked to China-backed Salt Typhoon hackers during the 2024 telecom attacks.
T-Mobile took an unusually physical step to stop suspected Chinese hackers during the 2024 telecom cyberattacks: it cut a network cable connected to a compromised system. Bloomberg reported that the carrier acted after tracing suspicious activity to equipment connected through another telecommunications provider.
The activity was linked to Salt Typhoon, a Chinese government-backed hacking group that targeted telecom companies in a broad cyberespionage campaign. Attackers sought phone records and other communications data, including information connected to senior U.S. officials and political figures.
T-Mobile traced the suspicious connection
Bloomberg reported that T-Mobile’s cybersecurity team spent months searching for signs of intruders before detecting unusual activity involving one of its systems and a router belonging to another telecom provider, which was not identified.
T-Mobile cybersecurity chief Jeff Simon and three colleagues then travelled to a data centre in Bellevue, Washington. After locating the affected equipment, they physically cut the cable connecting it to the outside network, helping isolate the system before the intrusion became more extensive.
Salt Typhoon targeted major telecom companies
The wider Salt Typhoon campaign affected companies including AT&T, Verizon, Viasat, Charter and Windstream. T-Mobile largely avoided a broader compromise by identifying and severing the suspicious connection early.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0