T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network

T-Mobile cybersecurity staff physically disconnected a compromised network cable to stop a breach by the Chinese state-backed hacking group Salt Typhoon. The incident was part of a broader campaign targeting major U.S. telecommunications providers.
Why it matters
This highlights the extreme measures companies must take to defend critical infrastructure against sophisticated state-sponsored cyber espionage.
New reporting from Bloomberg revealed how cybersecurity staff at U.S. phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide intrusions by Beijing aimed at stealing customer data.
The hacks were carried out by a Chinese government-backed hacking group called Salt Typhoon . The campaign compromised hundreds of phone companies, internet giants, and datacenter providers with the goal of collecting phone records and information about senior U.S. government officials, including then-presidential candidates. Hacked companies included AT&T, Verizon , satellite phone network Viasat , and network infrastructure giants Charter and Windstream .
By and large, T-Mobile escaped a widescale breach of its network by catching the activity early — and resorted to physically cutting the cable to a compromised system, per Bloomberg.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in