T-Mobile 'Chopped a Cable' to Expel Chinese Hackers from Its Network A cybersecurity incident involving a Chinese government-backed hacking group, Salt Typhoon, has been detailed in a report by Bloomberg, highlighting how T-Mobile’s cybersecurity team managed to thwart a large-scale data breach in 2024. The attack, part of a broader campaign targeting U.S. infrastructure, aimed to steal customer data and information about senior government officials, including then-presidential candidates. The breach affected hundreds of companies across multiple sectors, including major telecommunications providers like AT&T and Verizon, satellite phone network Viasat, and infrastructure giants Charter and Windstream. T-Mobile’s cybersecurity team identified the breach early, though it took months of investigation to trace the source of the intrusion. The hackers exploited a compromised system linked to a router belonging to a different telecom company, which T-Mobile did not name. Once the breach was confirmed, the company’s cybersecurity chief, Jeff Simon, took a physical approach to neutralize the threat. According to Bloomberg, Simon and three colleagues traveled to a data center near T-Mobile’s Bellevue, Washington, headquarters. There, they located the compromised system and physically severed the cable connecting it to the external network using a pair of scissors. The method of cutting the cable was described as a last-resort measure to isolate the infected system and prevent further data exfiltration. Bloomberg noted that T-Mobile’s ability to detect the breach early likely prevented a widespread compromise of its network. The company’s actions were part of a larger pattern of attacks by Salt Typhoon, which has been linked to state-sponsored cyber operations targeting U.S. entities.#bloomberg #t_mobile #salt_typhoon #jeff_simon #bellevue_washington
