T-Mobile cybersecurity staff identified and expelled a Chinese government-backed hacking group from its network in 2024, according to a new report from Bloomberg. The action came during a wave of industry-wide intrusions attributed to a hacking group called Salt Typhoon, which targeted U.S. phone carriers and other major firms. The campaign aimed to collect phone records and information about senior U.S. government officials, including then-presidential candidates. The hacks compromised hundreds of phone companies, internet giants, and data center providers across the country.
The affected companies named in the report include AT&T, Verizon, satellite phone network Viasat, and network infrastructure giants Charter and Windstream. T-Mobile largely avoided a widescale breach by detecting the suspicious activity early, Bloomberg reported. The company’s cybersecurity staff spent months searching for hackers in its network without success. Eventually, they found unusual behavior on one of T-Mobile’s systems, originating from a router owned by another unnamed telecom company.
After identifying the breach, T-Mobile’s cybersecurity chief, Jeff Simon, took direct action, according to Bloomberg. Simon told the publication that he and three colleagues drove to a data center in nearby Bellevue, Washington. Once there, they located the compromised system, pulled out a set of scissors, and cut the cable connecting the box to the outside world. This physical disconnection effectively expelled the hackers from the network.
The report highlights the severity of the Salt Typhoon campaign, which targeted American telecommunications infrastructure on a broad scale. The hackers’ goal was to steal customer data and intelligence on high-level U.S. officials, including presidential candidates. T-Mobile’s response underscores the lengths companies may go to in order to secure their networks against state-sponsored intrusions. Unlike some of its rivals, T-Mobile appears to have avoided a full-scale data breach.
T-Mobile has not yet publicly commented on the Bloomberg report, and TechManNews has reached out to the company for additional details. The broader industry impact remains under scrutiny, as many of the targeted firms were hit during the same period. The Salt Typhoon intrusions have raised concerns about the security of U.S. telecom infrastructure and the vulnerability of sensitive communications. The incident also illustrates the challenge of detecting sophisticated hackers who can hide inside networks for extended periods. Further updates on T-Mobile’s response may follow as more information becomes available.







