Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > How T-Mobile’s Security Team Cut a Cable to Physically Kick Salt Typhoon Off Its Network
How T-Mobile’s Security Team Cut a Cable to Physically Kick Salt Typhoon Off Its Network
Read Time:3 Minute, 24 Second

When the fastest fix was a pair of scissors

New reporting has surfaced a striking detail from T-Mobile’s 2024 encounter with Salt Typhoon, the Chinese state-linked hacking group that spent much of the past two years burrowing into U.S. telecom networks: when T-Mobile’s security team finally located the intruders’ foothold, they didn’t wait for a remote fix. They drove to the data center and cut the cable.

Jeff Simon, T-Mobile’s Chief Security Officer, and three colleagues traced suspicious traffic to a router owned by another, unnamed telecom carrier, sitting in a data center near the company’s Bellevue, Washington headquarters. After months of hunting without a clean lead, the team physically located the hardware and severed the external network connection with scissors on the spot — immediately cutting off the attackers’ access rather than risking a slower, detectable remote takedown. The cable was later framed and put on display at T-Mobile’s headquarters, a memento of a fight that, for once, ended with the defenders moving faster than the attackers.

Who Salt Typhoon is

Salt Typhoon is the name U.S. officials use for a Chinese government-linked hacking operation that the FBI says has compromised at least 200 companies across roughly 80 countries. Rather than smash-and-grab data theft, the group has focused on quietly living inside telecommunications infrastructure — the routers and switches that carry everyone else’s traffic — for long-term intelligence collection.

The group’s approach leans on exploiting the trust relationships between telecom networks: once inside one carrier’s equipment, that access can be a springboard into traffic flowing to and from other providers. Its stated priority, according to investigators, was harvesting phone records and communications metadata belonging to senior U.S. government officials and presidential candidates — intelligence value far beyond ordinary consumer data.

The scale of the telecom breach wave

T-Mobile is one of several major U.S. carriers Salt Typhoon is confirmed to have targeted, alongside AT&T, Verizon, Lumen, Charter Communications and Windstream. In some cases the group reached systems telecom providers are legally required to maintain for lawful-intercept (wiretap) capabilities — systems whose compromise carries obvious national-security weight beyond a typical data breach.

T-Mobile’s own account of the incident, first disclosed publicly in November 2024, draws a contrast with peers: the company has stated it “largely avoided the wide-scale breach that hit peers like AT&T and Verizon,” crediting its security team’s early detection and rapid, hands-on response for limiting the damage.

Why the physical response stands out

Cybersecurity incident response is normally an entirely digital affair: isolate the host, kill the session, rotate credentials, patch the hole. Physically traveling to a facility and cutting a cable is a last-resort move, typically reserved for situations where remote remediation risks tipping off a sophisticated adversary who could simply pivot to another access point the moment they sense they’ve been detected. Against an actor as patient and well-resourced as Salt Typhoon — one capable of maintaining access inside a network for months without detection — that calculus can make sense: cutting the physical link removes any ambiguity about whether the connection is truly severed.

What it signals for the sector

The episode underscores two things security teams at other carriers and critical-infrastructure operators are still absorbing. First, nation-state actors targeting telecom infrastructure can dwell for extended periods before discovery, which argues for sustained threat-hunting rather than one-time audits. Second, when an intrusion reaches infrastructure as sensitive as lawful-intercept systems, response speed and certainty can outweigh the elegance of the fix — sometimes the most reliable way to be sure an adversary is gone is to make the disconnection undeniable.

Salt Typhoon has not gone away. With the FBI’s 200-company, 80-country tally likely to grow as investigations continue, telecom and critical-infrastructure security teams should treat this less as a closed case study and more as a preview of the kind of long-dwell, high-value espionage operations they should expect to keep encountering.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on How T-Mobile’s Security Team Cut a Cable to Physically Kick Salt Typhoon Off Its Network, use the discussion on Forum.

>> forum community

Comments

Leave a Reply