T-Mobile's cybersecurity team identified and removed Chinese government-backed hackers, known as Salt Typhoon, from its network in 2024. This action was taken during a period of industry-wide intrusions by Beijing aimed at acquiring customer data and information on U.S. government officials.
To contain the breach, T-Mobile resorted to physically disconnecting a compromised system. After months of searching, unusual activity was detected on one of its systems originating from a router belonging to another telecom company. T-Mobile's cybersecurity chief, Jeff Simon, and three others drove to a data center in Bellevue, Washington, and physically cut the cable connecting the affected box.
The Salt Typhoon campaign compromised hundreds of phone companies, internet giants, and data center providers. Affected companies included AT&T, Verizon, Viasat, Charter, and Windstream. The objective was to collect phone records and information about senior U.S. government officials, including then-presidential candidates.
T-Mobile largely avoided a widespread breach by detecting the activity early and taking decisive action. The physical disconnection prevented further access and data exfiltration from the compromised system, mitigating the potential impact of the broader hacking campaign on its network.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
T-Mobile cybersecurity staff identified and removed Chinese government-backed hackers, known as Salt Typhoon, from its network in 2024 by physically cutting a cable to a compromised system. This action prevented a widespread breach during a campaign targeting multiple U.S. telecom companies to steal customer data and information on government officials.