×
×

T-Mobile Engineers Cut Cable to Oust Chinese Hackers, Bloomberg Says

In the fall of 2024, as Chinese state-sponsored hackers swept through American telecommunications networks, T-Mobile‘s cybersecurity team found itself hunting for an intruder that refused to show itself. Months of searching turned up nothing. Then, a clue emerged from an unexpected place: another telecom’s router.

According to new reporting from Bloomberg, the discovery led to a decidedly low-tech solution. Jeff Simon, T-Mobile’s chief security officer, and three colleagues drove to a data center near the company’s Bellevue, Washington headquarters. They located the compromised system, pulled out a pair of scissors, and snipped the cable connecting the box to the outside world.

The intrusion was the work of Salt Typhoon, a hacking group tied to the Chinese government. The broader campaign hit dozens of phone companies, internet giants, and data center providers, with an eye on call records and intelligence about senior U.S. officials and then-presidential candidates.

Victims included AT&T, Verizon, satellite phone network Viasat, and network infrastructure providers Charter and Windstream. But T-Mobile escaped a widescale breach, in large part because its team caught the activity early. The physical cable cut was a last resort after digital defenses failed to isolate the attacker.

Simon told Bloomberg that the team had spent months looking for suspected hackers inside T-Mobile’s network without success. Eventually, they spotted unusual behavior on one of their systems, traced to a router belonging to another, unnamed telecom company. It was enough to pinpoint the breach.

Reached by TechCrunch, T-Mobile declined to comment.