New reporting from Bloomberg revealed how cybersecurity staff at U.S. phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide intrusions by Beijing aimed at stealing customer data.
The hacks were carried out by a Chinese government-backed hacking group called Salt Typhoon. The campaign compromised hundreds of phone companies, internet giants, and datacenter providers with the goal of collecting phone records and information about senior U.S. government officials, including then-presidential candidates. Hacked companies included AT&T, Verizon, satellite phone network Viasat, and network infrastructure giants Charter and Windstream.
By and large, T-Mobile escaped a widescale breach of its network by catching the activity early — and resorted to physically cutting the cable to a compromised system, per Bloomberg.
The publication said T-Mobile’s cyber staff spent months looking for suspected hackers in its network without success. Eventually, the company found unusual behavior on one of its systems coming from another router belonging to a different telecom company, which T-Mobile did not name.
After identifying the breach, T-Mobile’s cybersecurity chief Jeff Simon told Bloomberg that he and three others drove to the nearby Bellevue, Washington, data center, found the compromised system, pulled out a set of scissors and snipped the cable connecting the box to the outside world.
We’ve reached out to T-Mobile for more information, and we’ll update this story if we hear back.