Cybersecurity2 mins read

T-Mobile Cut Off a Compromised System to Expel Chinese Hackers

TechCrunch reports that T-Mobile avoided a wider network breach after detecting Chinese government-backed Salt Typhoon activity early and physically disconnecting a compromised system.

What happened at T-Mobile

TechCrunch reports that T-Mobile identified and expelled Chinese hackers from its network in 2024 during a broader wave of telecom intrusions. The U.S. phone provider avoided a large-scale breach after spotting suspicious activity early. The activity was attributed in the article to Salt Typhoon, described as a Chinese government-backed hacking group.

Why the response stood out

According to the report, T-Mobile’s cyber staff had spent months searching for suspected hackers in its network before finding unusual behavior on one system. The activity was coming from another router belonging to a different telecom company, which T-Mobile did not name. After identifying the compromised system, cybersecurity chief Jeff Simon and three others went to a nearby data center and physically cut the cable connecting the box to the outside world.

The broader Salt Typhoon campaign

The article says Salt Typhoon’s campaign compromised hundreds of phone companies, internet giants, and data center providers. The reported goal was to collect phone records and information about senior U.S. government officials, including then-presidential candidates. Other affected companies named in the TechCrunch report include AT&T, Verizon, Viasat, Charter, and Windstream.

Key takeaway for security teams

The T-Mobile case highlights the value of persistent monitoring and fast containment when suspicious activity is detected. It also shows that incident response can involve physical infrastructure decisions, not only software or network configuration changes. TechCrunch said T-Mobile did not provide comment when reached.

Discover More

    The Danish flag flies outside a polling station at City Hall in Copenhagen, Denmark, on March 24, 2026.
    Denmark CPR Breach

    A Danish government database breach exposed records tied to about 8 million people.

    CybersecurityData breach
    AI agents, AI swarm, agent hackers
    Armadin Raises $255.5M

    Kevin Mandia’s new agent swarm security startup is now valued at more than $2.5 billion.

    CybersecurityStartups