T-Mobile cybersecurity staff drove to a data center near Bellevue, Washington, and physically cut a cable to push suspected Salt Typhoon hackers out of its network in 2024. The company had spent months looking for intruders without finding them, then finally found a compromised system and snipped the line connecting it to the outside world.
The move matters because Salt Typhoon was not a one-off breach. It was part of a Chinese government-backed campaign that hit hundreds of phone companies, internet giants and data center providers, with the aim of collecting phone records and information on senior U.S. government officials, including then-presidential candidates. T-Mobile escaped a widescale breach by catching the activity early, but only after the intrusion had already reached a system it could not safely leave in place.
Jeff Simon said he and three others drove to the nearby data center from T-Mobile’s Bellevue headquarters after the company found unusual behavior on one of its systems. That behavior, he said, was coming through another router tied to a different telecom company. The team located the compromised system, pulled out a set of scissors and cut the cable by hand, a blunt response to a problem that had resisted months of internal searching.
That detail underscores how difficult the Salt Typhoon campaign was to spot. Even when T-Mobile knew something was wrong, the company still had to search, locate and physically disconnect the device before it could be sure the hackers were gone. The same campaign also reached AT&T, Verizon, Viasat, Charter and Windstream, showing how widely the intrusions spread across the communications sector.
For T-Mobile, the most important lesson is already clear: early detection spared it from the kind of broader compromise that hit other companies, but the cleanup still ended with a cable being cut in person. What remains unresolved is how many other networks were touched in the same way before anyone knew to look.

