PLATFORMS Signal 395
T-Mobile evaded the 2024 Salt Typhoon telecom campaign by snipping a compromised cable at a Bellevue data center
T-Mobile's cybersecurity chief drove to a Bellevue, Washington data center in 2024 and physically cut a cable to a compromised system with scissors to expel the Chinese state-backed Salt Typhoon group, avoiding a breach that hit AT&T, Verizon, Viasat, Charter, and Windstream.
For network operators, the incident shows that months of software-based detection failed and a physical cable cut was needed to contain a state-backed intrusion. The compromise entered via a router belonging to another telecom, exposing peering-trust risk between carriers. T-Mobile's escape was an exception: the Salt Typhoon campaign compromised hundreds of firms and targeted senior U.S. government phone records, revealing a systemic weakness in telecom interconnections rather than a solved problem.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
T-Mobile cybersecurity chief Jeff Simon and three others drove to a Bellevue, Washington data center in 2024 and used scissors to cut the cable connecting a compromised system to the outside world, expelling the Chinese-backed Salt Typhoon group.
T-Mobile's cyber staff had spent months searching for the hackers without success before spotting unusual behavior on one system originating from a router belonging to a different, unnamed telecom company.
The broader Salt Typhoon campaign compromised hundreds of phone companies, internet providers, and data center operators including AT&T, Verizon, Viasat, Charter, and Windstream, targeting phone records and information about senior U.S. government officials and then-presidential candidates.
THE CLUSTER
↗