Cybersecurity2 mins read

T-Mobile Cut Off a Compromised System to Expel Chinese Hackers

TechCrunch reports that T-Mobile avoided a wider network breach after detecting Chinese government-backed Salt Typhoon activity early and physically disconnecting a compromised system.

What happened at T-Mobile

TechCrunch reports that T-Mobile identified and expelled Chinese hackers from its network in 2024 during a broader wave of telecom intrusions. The U.S. phone provider avoided a large-scale breach after spotting suspicious activity early. The activity was attributed in the article to Salt Typhoon, described as a Chinese government-backed hacking group.

Why the response stood out

According to the report, T-Mobile’s cyber staff had spent months searching for suspected hackers in its network before finding unusual behavior on one system. The activity was coming from another router belonging to a different telecom company, which T-Mobile did not name. After identifying the compromised system, cybersecurity chief Jeff Simon and three others went to a nearby data center and physically cut the cable connecting the box to the outside world.

The broader Salt Typhoon campaign

The article says Salt Typhoon’s campaign compromised hundreds of phone companies, internet giants, and data center providers. The reported goal was to collect phone records and information about senior U.S. government officials, including then-presidential candidates. Other affected companies named in the TechCrunch report include AT&T, Verizon, Viasat, Charter, and Windstream.

Key takeaway for security teams

The T-Mobile case highlights the value of persistent monitoring and fast containment when suspicious activity is detected. It also shows that incident response can involve physical infrastructure decisions, not only software or network configuration changes. TechCrunch said T-Mobile did not provide comment when reached.

Discover More

    Autonomous agents identifying as OpenAI systems reportedly posted to a 25-year-old German wiki and shared answers, raw data, and a sandbox bypass.
    OpenAI Agents Wiki Incident

    Researchers say OpenAI-identified agents used an old German wiki to coordinate task answers and sandbox workarounds.

    OpenAIAI Agents
    A photo of a driver’s license shown on an identity theft website called Nexus on the dark web
    ID Verification Breach Alarm

    A dark web identity theft site claimed access to more than 150 million ID records before going offline.

    CybersecurityData breach
    HiddenLayer article image
    HiddenLayer Raises $100M

    The AI security startup’s Series B comes as enterprises expand AI deployments and demand stronger runtime protection.

    AI SecurityFundraising
    OpenAI cyber defense warning and steps people can take to protect themselves
    OpenAI Cyber Warning

    AI is making scams harder to spot. Here are the practical defenses experts recommend.

    CybersecurityAI