Four T-Mobile security staffers drove to a data center in Bellevue, Washington, located a compromised box, and cut its cable with scissors. That’s how a sophisticated state-backed espionage campaign got stopped — at least at one carrier. Chief Security Officer Jeff Simon made the call. What makes that remarkable isn’t just the scissors; it’s that software-driven network isolation exists precisely for moments like this, and yet the fastest move was still a drive across town and a physical snip.
The Biggest Telecom Hack You Barely Heard About
China’s Salt Typhoon group didn’t smash windows — it found the key under the doormat every U.S. telecom left there for law enforcement.
Salt Typhoon, a hacking group aligned with China’s Ministry of State Security, spent 2024 burrowing through U.S. telecommunications infrastructure on a scale that still isn’t fully understood. At least nine American carriers were compromised — AT&T, Verizon, T-Mobile, Lumen, Charter/Spectrum, Consolidated Communications, Windstream, and others. The FBI later confirmed more than 200 organizations across roughly 80 nations were hit.
The target wasn’t your group chat. Salt Typhoon went after lawful-intercept systems — the legal frameworks requiring carriers to maintain wiretap access for law enforcement, now turned against those same systems — plus call records and location data. Roughly 150 high-value individuals had communications actively monitored. U.S. officials confirmed that included personnel from both the Harris and Trump 2024 presidential campaigns. The entry points were mundane: unpatched edge devices from Ivanti, Fortinet, Sophos, and Cisco, left exposed through gaps in routine patch management.
- Salt Typhoon compromised 9 U.S. telecoms and 200-plus organizations globally in 2024
- Hackers accessed lawful-intercept platforms — surveillance infrastructure built for law enforcement, turned against it
- T-Mobile’s breach entry point: a router belonging to a connected wireline carrier’s router, not T-Mobile’s own hardware
- Simon stated publicly that customers’ calls, texts, and voicemails were not accessed
- The group continued targeting unpatched Cisco edge devices into early 2025, per Recorded Future’s Insikt Group
Scissors Beat Sophistication
When you know exactly which cable matters, software controls become optional.
T-Mobile’s security team spent months hunting Salt Typhoon activity without finding it. The break came when analysts spotted anomalous traffic on a T-Mobile system traced back to a router owned by another telecom — the attackers had piggybacked through a connected partner’s infrastructure as their entry point. Once identified, Simon and three colleagues drove to the Bellevue data center and snipped the cable. Physical isolation. Immediate.
This is the cybersecurity equivalent of pulling a fire alarm when the sprinkler system fails — crude, fast, and effective. Network isolation is standard incident response. T-Mobile just executed it with scissors because that was the fastest path to cutting the connection once the specific hardware was identified.
The broader picture is messier. AT&T, Verizon, and Lumen stated they contained their intrusions, but government researchers warn Salt Typhoon may have been inside some networks for one to two years. What was copied before eviction remains unclear — a database leak of that magnitude could take years to fully assess. Recorded Future’s Insikt Group documented the group continuing campaigns against unpatched Cisco devices well into early 2025 — a reminder that eviction and eradication are not the same thing.
In January 2025, the U.S. Treasury sanctioned Sichuan Juxinhe Network Technology Co., identifying it as Salt Typhoon’s corporate enabler, signaling an intent to impose real costs on the operation’s infrastructure. Expect tighter scrutiny around lawful-intercept systems and cross-carrier connectivity as policymakers reassess how easily foreign intelligence can exploit domestic surveillance architecture. The scissors worked once. The question is what happens when the next cable is harder to find.






























