T-Mobile Cyber Team Physically Cuts Cable to Remove Chinese Hackers From Network | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


T-Mobile’s security team resorted to an unusually low-tech fix for a high-tech problem in 2024, physically severing a network cable to cut off Chinese state-backed hackers’ access to its systems, according to new reporting from Bloomberg.

The dramatic move came amid a sprawling espionage campaign that compromised telecom and internet infrastructure across the United States.

The intrusion was part of a broader operation attributed to Salt Typhoon, a Chinese government-linked hacking group that the FBI says has now breached at least 200 companies across 80 countries, a scale far larger than initially disclosed.

The campaign’s primary objective was to harvest phone records and communications metadata tied to senior U.S. government officials, including individuals who were presidential candidates at the time.

T-Mobile Cyber Team Physically Cuts Cable

Victims of the broader Salt Typhoon campaign have included AT&T, Verizon, Lumen, Charter Communications, and Windstream, among others, with hackers targeting company routers to siphon sensitive network traffic.

T-Mobile was first linked to the Salt Typhoon intrusions in November 2024, when the Wall Street Journal reported the carrier had been swept into the same industry-wide campaign, though the company said at the time it had no evidence customer data was significantly affected.

That early disclosure came just as the FBI and CISA publicly warned that the espionage effort was targeting wiretap systems telecom providers are legally required to maintain, a detail that heightened concern given the sensitivity of the data at stake.

According to Bloomberg’s report, T-Mobile’s cybersecurity staff spent months hunting for the intruders inside its network without success before finally spotting unusual behavior on one internal system, traffic originating from a router belonging to another, unnamed telecom company.

That discovery gave Jeff Simon, T-Mobile’s chief security officer, and three colleagues the lead they needed. Rather than wait on a remote remediation process, the team drove to a data center near the company’s Bellevue, Washington headquarters, located the compromised hardware, and cut the physical cable connecting it to the outside world using a pair of scissors.

The improvised fix appears to have worked. T-Mobile has said it largely avoided the wide-scale breach that hit peers like AT&T and Verizon, and Bloomberg reports the severed cable was later mounted in a frame and displayed at T-Mobile’s headquarters as a memento of the incident. T-Mobile did not provide comment when contacted about the episode.

The episode underscores just how aggressively defenders had to respond to an adversary capable of pivoting between interconnected carrier networks. Salt Typhoon’s ability to move laterally through shared infrastructure, exploiting trust relationships between telecom routers, has made the campaign one of the most consequential state-sponsored intrusions in U.S. telecom history.

FBI officials have described the threat as ongoing, and the sheer number of confirmed victims suggests the group retains persistent access across parts of global telecom infrastructure even as individual companies like T-Mobile manage to physically and digitally lock it out.

For an industry built on redundancy and constant connectivity, a security team’s decision to reach for scissors instead of a software patch is a striking reminder that sometimes the fastest way to stop a nation-state hacker is to unplug them.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Click Here For The Original Source.

——————————————————–

..........

.

.