T-Mobile cybersecurity chief Jeff Simon said the company found Salt Typhoon activity in 2024 and physically cut a cable to remove a compromised system from its network. The move stopped one system with unusual behavior after months of searching. It also shows how far a telecom may go when software tools are not enough.
Jeff Simon and the scissors
Simon said he and three others drove to a nearby data center and used scissors to snip the cable connecting the box to the outside world. The box sat close to T-Mobile’s Bellevue, Washington headquarters. That detail turns an abstract intrusion into a hands-on containment job.
Months of searching on T-Mobile
T-Mobile cyber staff spent months looking for suspected hackers in its network without success before they found the compromised system. The unusual behavior came from another router belonging to a different telecom company. In practice, that means the problem did not appear as a clean, obvious break-in.
Salt Typhoon’s wider campaign
The same Salt Typhoon campaign compromised hundreds of phone companies, internet giants, and data center providers. It also hit AT&T, Verizon, Viasat, Charter, and Windstream. The campaign aimed to collect phone records and information about senior U.S. government officials, including then-presidential candidates.
T-Mobile’s unanswered next step
T-Mobile caught the activity early and avoided a widescale breach of its network. TechCrunch said the company did not provide comment when reached. The remaining question is which other telecom company owned the router that led staff to the compromised system in Bellevue.







