CRBC News
Security

T‑Mobile Cut a Cable With Scissors to Stop China‑Linked Hackers — And Why It Matters

T‑Mobile Cut a Cable With Scissors to Stop China‑Linked Hackers — And Why It Matters
Image: Deposit Photos

T‑Mobile’s security team physically cut a cable at a Bellevue data center to halt Salt Typhoon, a China‑linked hacking group that infiltrated lawful‑intercept systems and other telecom infrastructure. The campaign affected at least nine U.S. carriers and more than 200 organizations worldwide, and roughly 150 high‑value individuals had communications monitored. The incident highlights risks from routine law‑enforcement access points and unpatched edge devices and has prompted sanctions and calls for tighter oversight.

Four T‑Mobile security staff drove to a Bellevue, Washington data center, located a compromised device and physically severed its cable with scissors to stop an active espionage intrusion. The drastic step — approved by Chief Security Officer Jeff Simon — immediately halted that connection and illustrated how, even in an era of sophisticated software controls, sometimes the fastest fix is a simple bit of hardware isolation.

Who Was Behind the Attack? Security investigators traced the campaign to Salt Typhoon, an intrusion group tied to China's Ministry of State Security. Throughout 2024 the group pursued a broad assault on telecommunications infrastructure, compromising at least nine U.S. carriers and more than 200 organizations in roughly 80 countries.

What They Targeted Salt Typhoon focused on lawful‑intercept systems — the access points carriers maintain to comply with court‑ordered surveillance — and turned those interfaces against carriers themselves. The attackers also harvested call records and location data. U.S. officials said roughly 150 high‑value individuals were monitored, including staff associated with both the Harris and Trump 2024 presidential campaigns.

How They Got In The intrusions often relied on mundane operational failures: unpatched edge devices from vendors such as Ivanti, Fortinet, Sophos, and Cisco. In T‑Mobile’s case, analysts traced malicious traffic back to a router owned by a connected wireline carrier rather than T‑Mobile’s own hardware. Once the specific device was identified, T‑Mobile’s team chose immediate physical isolation over slower software remedies.

“When you know exactly which cable matters, software controls become optional.”

Response and Aftermath T‑Mobile said its investigation indicated customers’ calls, texts and voicemails were not accessed. Other carriers — including AT&T, Verizon and Lumen — reported they contained similar intrusions. Still, government researchers warn Salt Typhoon may have been present in some networks for one to two years, and a full accounting of what was copied could take extensive time.

Recorded Future’s Insikt Group found the campaign continued to target unpatched Cisco edge devices into early 2025, underscoring that eviction from a network does not guarantee eradication. In January 2025 the U.S. Treasury sanctioned Sichuan Juxinhe Network Technology Co., identifying it as a corporate enabler for the operation.

Why This Episode Matters The scissors‑and‑cable moment is striking because it highlights two enduring problems in telecom cybersecurity: legacy lawful‑intercept access that can be abused, and persistent gaps in patch management. Policymakers and carriers are likely to face renewed pressure to tighten controls around cross‑carrier connectivity, harden lawful‑intercept systems, and accelerate routine patching to reduce easy entry points for state‑backed actors.

Bottom Line: The physical severing of a cable stopped one active intrusion, but the campaign’s breadth and longevity show that better software defenses, stronger operational hygiene, and policy changes are all needed to prevent the next incident from being harder to isolate.

Help us improve.

Related Articles

Trending