T-Mobile physically cut a cable to expel Salt Typhoon hackers
Original: T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network
Why This Matters
The incident highlights physical-layer responses as a last resort in defending critical telecom infrastructure against nation-state threats.
In 2024, T-Mobile's cybersecurity team identified Salt Typhoon — a Chinese government-backed hacking group — inside its network and physically severed a cable at a Bellevue, Washington data center to cut off the compromised system, according to Bloomberg reporting published August 19, 2026.
Bloomberg revealed that T-Mobile cybersecurity staff spent months searching for suspected Chinese state-sponsored hackers within its network before detecting unusual activity on one of its systems. The suspicious traffic originated from a router belonging to an unnamed third-party telecom company. Upon confirming the breach, T-Mobile's Chief Security Officer Jeff Simon and three colleagues drove to the company's Bellevue, Washington data center, located the compromised system, and physically cut its external network cable using scissors. The Salt Typhoon hacking campaign — attributed to the Chinese government — targeted hundreds of telecommunications companies, internet providers, and data center operators across the U.S., with the goal of collecting phone records and intelligence on senior U.S. government officials, including then-presidential candidates. Other confirmed victims include AT&T, Verizon, satellite network Viasat, and infrastructure providers Charter and Windstream. T-Mobile's early detection is credited with preventing a larger-scale breach of its network. TechCrunch reached out to T-Mobile for comment.