VYPR
breachPublished Aug 20, 2026· 1 source

T-Mobile Physically Cuts Network Cable to Evict Chinese State-Sponsored Hackers

In a rare low-tech maneuver, T-Mobile's security team physically severed a network cable to expel Chinese state-backed hackers from its systems after months of unsuccessful remote hunting.

T-Mobile's cybersecurity team employed an unconventional, low-tech solution in 2024 to combat a sophisticated, high-tech threat: they physically cut a network cable to sever the access of Chinese state-backed hackers. This drastic measure was taken after the telecom giant spent months attempting to remotely identify and remove intruders from its network without success. The incident is linked to the expansive Salt Typhoon espionage campaign, a Chinese government-sponsored operation that has targeted telecommunications and internet infrastructure across the United States.

The Salt Typhoon campaign's primary objective was to harvest sensitive data, including phone records and communications metadata, particularly targeting individuals connected to senior U.S. government officials and presidential candidates. The FBI has attributed this campaign to China-linked threat actors and has reported breaches at over 200 companies globally, with victims including major U.S. carriers such as AT&T, Verizon, Lumen, Charter Communications, and Windstream. The hackers exploited trust relationships between telecom routers, enabling lateral movement across interconnected networks to siphon critical traffic.

T-Mobile first became aware of its entanglement in the Salt Typhoon campaign in November 2024, following a report that indicated the carrier was among the affected entities. At the time, the company stated it had found no evidence of significant customer data compromise. This disclosure coincided with a joint advisory from the FBI and CISA, which highlighted the campaign's focus on wiretap systems maintained by telecom providers—systems holding highly sensitive data.

According to recent reports, T-Mobile's security personnel eventually identified unusual network activity originating from a router belonging to an unnamed, external telecom company. This discovery provided the critical lead needed by Chief Security Officer Jeff Simon and his team. Rather than relying solely on remote remediation, the team took decisive physical action.

In a move that underscored the urgency and nature of the threat, Simon and three colleagues traveled to a data center near T-Mobile's Bellevue, Washington headquarters. There, they located the compromised hardware and, using a pair of scissors, physically disconnected the cable that provided the hackers with external access. This direct intervention effectively cut off the intruders' presence within T-Mobile's network.

This improvised solution proved successful, with T-Mobile largely avoiding the widespread breaches that impacted its industry peers. The severed cable was reportedly later framed and displayed at T-Mobile's headquarters as a symbol of the incident. The company declined to comment on the specifics of the event.

The episode serves as a stark illustration of the extreme measures security teams may need to employ against persistent, state-sponsored adversaries. Salt Typhoon's ability to leverage shared infrastructure and exploit inter-carrier trust has made it one of the most significant intrusions into the U.S. telecom sector. Despite ongoing efforts by law enforcement and security agencies, the campaign's broad reach suggests the threat remains active across global telecom networks.

Ultimately, T-Mobile's decision to physically disconnect a network cable highlights a critical point: in the face of advanced persistent threats, sometimes the most effective defense is a direct, physical disruption, a reminder that traditional digital defenses are not always sufficient against determined nation-state actors.

Synthesized by Vypr AI