T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network
- ID
- 15682
- Status
- summarized
- Published
- 20 Aug 2026, 1:26 AM
- Fetched
- 20 Aug 2026, 1:51 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/08/19/t-mobile-chopped-a-cable-to-expel-chinese-hackers-from-its-network/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 4.0
- Created
- 20 Aug 2026, 1:52 AM
- Tags
- Audience
- developerssaas_startup_founders
What happened
Bloomberg reported that T-Mobile expelled Chinese state-backed hacking group Salt Typhoon from its network in 2024 by physically cutting the cable to a compromised system at a Bellevue, WA data center. The Salt Typhoon campaign compromised hundreds of telecom and internet companies including AT&T, Verizon, Viasat, Charter, and Windstream, aiming to steal phone records and data on senior US government officials. T-Mobile's cyber chief Jeff Simon and three colleagues drove to the data center and snipped the cable after months of searching failed to locate the intruders, who were found via unusual behavior traced to another telecom's router.
Why it matters
A useful reminder that when incident response tools and network monitoring fail to find persistent intruders, physical isolation of compromised systems is a valid last-resort playbook. For builders running their own infrastructure, the detail that the intrusion was detected via traffic from a different company's router highlights the value of cross-tenant and cross-network anomaly detection rather than relying solely on internal telemetry.
Discussion angle
When digital forensics and EDR tools can't find the threat, at what point do you escalate to physical disconnection—and what does that say about the limits of software-only incident response?