T-Mobile Severed Data Center Cable to Expel State-Backed Chinese Hackers
Cybersecurity staff took physical measures at a Washington facility to halt intrusions tied to the Salt Typhoon espionage campaign.

T-Mobile cybersecurity personnel resorted to manually severing a physical network connection in 2024 to purge state-sponsored Chinese hackers from its systems, according to details from Bloomberg first reported by TechCrunch. The measure was part of a broader response to a widespread espionage campaign targeting major telecommunications operators across the United States.
The cyber intrusions were attributed to Salt Typhoon, a state-backed hacking unit associated with the Chinese government. The group launched an extensive effort that impacted hundreds of telephone service providers, internet routing entities, and data center operators. The overarching objective was the harvesting of call logs, user metadata, and confidential intelligence regarding high-ranking American government officials and political figures, including presidential contenders.
Numerous high-profile enterprise and infrastructure players were compromised during the sweeping campaign. Affected organizations included major mobile and broadband providers AT&T and Verizon, satellite communications firm Viasat, as well as network infrastructure operators Charter Communications and Windstream.
Unlike several of its industry peers, T-Mobile managed to prevent a wide-scale systemic breach by identifying the unauthorized activity at an early stage. The containment effort ultimately required physical intervention rather than purely software-based isolation techniques.
Security personnel at T-Mobile had previously spent several months searching through internal networks for indicators of compromise tied to suspected threat actors. For an extended period, these internal investigations failed to locate active footholds within the carrier’s primary infrastructure.
Detection efforts eventually progressed when internal analysts flagged anomalous data flows on a T-Mobile system. The unusual traffic was traced back to an external router operated by an unnamed third-party telecommunications provider.
Upon pinpointing the source of the breach, T-Mobile Chief Security Officer Jeff Simon took direct action alongside three members of his cybersecurity team. The group traveled to a facility in Bellevue, Washington, where the affected hardware was housed.
Once on site at the Bellevue data center, the security team identified the compromised hardware unit. To guarantee an immediate and complete severance from external access, Simon used a pair of scissors to physically cut the network cable linking the machine to outside connections, effectively isolating the system and terminating the intrusion.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



