T-Mobile Severs Network Cable to Expel Hackers

31255892685?profile=RESIZE_180x180Cybersecurity staff at US phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide hacks by Beijing to steal customer data, and Bloomberg has now published a report on the event.   T-Mobile’s security team resorted to an unusually low-tech fix for a high-tech problem in 2024, physically severing a network cable to cut off Chinese state-backed hackers’ access to its systems.[1]

The dramatic move came amid a sprawling espionage campaign that compromised telecom and internet infrastructure across the US. This intrusion was part of a larger operation thought to have been conducted by Salt Typhoon, a Chinese government-linked hacking group that the FBI says has now breached at least 200 firms in 80 countries. The campaign’s primary objective was to harvest phone records and communications metadata tied to senior US government officials, including individuals who were presidential candidates at the time.

See:  https://redskyalliance.org/xindustry/salt-typhoon-hackers

Victims of the broader Salt Typhoon campaign have included AT&T, Verizon, Lumen, Charter Communications, and Windstream, among others, with hackers targeting company routers to siphon sensitive network traffic. T-Mobile was first linked to the Salt Typhoon intrusions in November 2024, when the Wall Street Journal reported the carrier had been swept into the same industry-wide campaign, though the company said at the time it had no evidence that customer data was significantly affected. That early disclosure came just as the FBI and CISA publicly warned that the espionage effort was targeting wiretap systems telecom providers are legally required to maintain, a detail that heightened concern given the sensitivity of the data at stake.

T-Mobile’s cybersecurity staff had spent months hunting for intruders inside its network without success before finally spotting unusual behavior on one internal system: traffic originating from a router belonging to another, unnamed telecom company.  That discovery gave Jeff Simon, T-Mobile’s chief security officer, and three colleagues the lead they needed. Rather than wait for a remote remediation process, the four drove to a data center near the firm’s Bellevue, Washington headquarters, located the compromised hardware, and then cut the physical cable connecting it to the outside world with scissors. The improvised fix appears to have worked.

T-Mobile has said it largely avoided the wide-scale breach that hit peers like AT&T and Verizon, and Bloomberg reports the severed cable was later mounted in a frame and displayed at T-Mobile’s headquarters as a memento of the incident.

The episode shows just how aggressively defenders had to respond to an adversary capable of pivoting between interconnected carrier networks. Salt Typhoon’s ability to move laterally through shared infrastructure, exploiting trust relationships between telecom routers, has made the campaign one of the most consequential state-sponsored intrusions in US telecom history. FBI officials have described the threat as ongoing, and the sheer number of confirmed victims suggests the group retains persistent access across parts of global telecom infrastructure even as individual companies like T-Mobile manage to physically and digitally lock it out.

For an industry built on redundancy and constant connectivity, a security team’s decision to reach for scissors instead of a software patch is a striking reminder that sometimes the fastest way to stop a nation-state hacker is to unplug them.

 

This AI-created article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929

 

[1] https://www.cybersecurityintelligence.com/blog/t-mobile-severs-network-cable-to-expel-hackers-9667.html

You need to be a member of Red Sky Alliance to add comments!