Fast and Effective

T-Mobile Cut Off Chinese Hackers With a Pair of Scissors

T-Mobile, T-Mobile hack, Salt Typhoon, Chinese hackers, how T-Mobile stopped Chinese hackers, T-Mobile Salt Typhoon cyberattack, Chinese hackers in US telecom networks
Facebook
X
LinkedIn
Reddit
WhatsApp

When T-Mobile discovered Chinese hackers inside its network in 2024, the company took a radical approach: Four security staff rushed to a data center and physically cut the connection.

According to a report by Bloomberg, T-Mobile’s security team had spent months searching unsuccessfully for signs of a potential breach in its infrastructure. Eventually, the specialists detected unusual activity on one system. The source was traced back to a router operated by another telecommunications company, which was not named in the report.

Ad

Jeff Simon, the T-Mobile executive responsible for cybersecurity, described what happened next to Bloomberg: He and three colleagues drove to a data center near the company’s headquarters in Washington state. Once there, they located the affected system, grabbed a pair of scissors and cut the cable carrying the external connection. In this case, it was the fastest and most effective way to sever the link.

The piece of cable apparently remains preserved to this day. It hangs framed at T-Mobile US headquarters in Bellevue, bearing the inscription: “Vigilant by design, secure by action.”

The Salt Typhoon Campaign

The attacks have been attributed to Salt Typhoon, a suspected Chinese state backed hacking group. According to the FBI, at least 200 U.S. companies across the telecommunications, internet services and data center sectors may have been affected. The campaign reportedly aimed to steal telephone data as well as information on senior U.S. government officials. Individuals targeted at the time allegedly included candidates running for the U.S. presidency.

Ad

Companies linked to the broader incident include telecommunications providers AT&T and Verizon, satellite communications provider Viasat, and network infrastructure companies Charter Communications and Windstream.

T-Mobile Escaped a More Serious Breach

Because the suspicious activity was detected early enough, T-Mobile said it avoided a more extensive compromise of its network infrastructure. The incident highlights how differently U.S. telecommunications companies were affected by the wave of attacks. It also demonstrates that alongside sophisticated technical countermeasures, a simple physical intervention can sometimes be an effective way to disconnect an attacker from a network immediately.

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel