New reporting by
Bloomberg details how T-Mobile detected and removed China-backed Salt Typhoon hackers from its network during the group’s widespread 2024 campaign against telecommunications companies. T-Mobile security teams spent months searching for the attackers before identifying unusual activity reaching one of its systems through a router that was powered off but communicating with another T-Mobile machine. After locating the compromised equipment, T-Mobile cybersecurity chief Jeff Simon and three colleagues went to a data center near the company’s Bellevue, Washington headquarters and physically cut the cable connecting the system to the outside world. T-Mobile largely avoided the broader compromise experienced by other organizations targeted in the campaign, which affected hundreds of telecommunications companies, internet providers and data center operators and sought phone records and information on senior U.S. officials.
Larry Pesce, VP of Services, Finite State:
“Credit first: T-Mobile’s team hunted down Salt Typhoon in days when peer carriers had them resident for months, and that’s genuinely impressive work. But this article is written for a general audience, and it shows. It reads like a movie script, complete with the team piling into the CSO’s Tesla, and for anyone who has actually run an incident it leaves a lot of important questions on the cutting room floor.
“Start with the powered-off router in California. The likely explanation for the spoofing is mundane: the attackers were working from stale topology data and impersonated a device they didn’t know was dark. That mistake is probably what burned them. But flip it around and it’s less flattering: T-Mobile’s own telemetry was attributing live traffic to a device that its own asset inventory should have shown as powered off. The gap between what the network claimed and what the hardware was actually doing is the real story here. Accurate hardware inventory and device status is unglamorous work, and it’s exactly the kind of thing that determines how long an adversary gets to live in your network.
“Then there’s the handling of that router. Per the article, the CSO told a staffer to “rip” a device suspected of nation-state compromise out of the rack, put it in his car, and drive it hundreds of miles to headquarters. Set aside the scissors for a moment. Where’s the chain of custody? Where’s the forensic imaging before the device gets bounced down I-5 in a trunk? For an artifact that might end up mattering to a federal investigation into Salt Typhoon, that’s a detail that made me wince.
“As for the scissors: I’ve spent time in data centers of this caliber, and scissors are not part of the standard tech loadout. Every one of those links terminates somewhere you can unplug it, shut down at a patch panel, or kill via CLI. Simon concedes as much in the article, admitting they could have turned the device off virtually. Cutting the cable accomplished nothing that unseating a connector wouldn’t, except producing a frayed trophy now framed in the lobby. I don’t doubt the cable got cut. I just notice that the version that made a better artifact is the version that happened.
“The substantive issue is what the fast, loud response cost them. Walk the IR lifecycle: containment, absolutely, they nailed it. But by their own account, powering the device back up in an isolated environment later yielded little. The attackers were long gone, and so was the volatile evidence. Abruptly severing the link also told the adversary, unambiguously, that they’d been made. A more patient play, instrumenting the device and the interconnect while quietly constraining what the attackers could reach, likely would have produced far more intelligence about tooling, tradecraft, and other footholds. That matters a great deal when the adversary is a state actor with confirmed presence across nine other carriers. Containment without eradication just means round two happens somewhere you aren’t watching.
“To be clear, I’m confident T-Mobile’s IR capability is far more sophisticated than this telling suggests, and some of what looks like theater may just be what survives the corporate comms filter. But that’s exactly the problem. The sanitized, cinematic version is the one the industry got, and the useful version, the one about inventory hygiene, trusted carrier interconnects as an attack surface, evidence handling under pressure, and the real tradeoff between fast containment and thorough eradication, is the one we actually needed.”
Seemant Sehgal, Founder and CEO, BreachLock:
“Cutting a cable makes for good storytelling, but the real headline is that a disciplined security team found an adversary that had worked hard to stay hidden. The significance of the Salt Typhoon campaign is the scale and persistence of the operation, targeting telecommunications infrastructure to gain access to highly valuable data. Based on public reporting, the attackers appear to have leveraged network infrastructure and maintained covert access paths, which highlights how difficult these intrusions can be to detect once established. Many organizations in that situation would still be writing incident reports while the attacker moved laterally. T-Mobile’s team located the threat, made a call, and physically removed it from the equation. That takes clarity of judgment under pressure, and that is genuinely rare.”
Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:
“The dramatic part of this story is that T-Mobile physically cut a cable, but the bigger lesson is how difficult sophisticated nation-state actors can be to find and remove. Salt Typhoon demonstrates why organizations need visibility into what is actually communicating across their networks, not simply what their asset management tools say should be there. When you identify a compromised system, decisive containment matters more than elegant containment. Sometimes the right incident-response decision really is to pull the plug.”
John Strand, Owner, Black Hills Information Security:
“There’s only one firewall in existence that is 100% effective, and this is it. Physically cutting the line.
“I look at stories like this and think security teams need to be empowered to make that decision. For years, the idea of actually cutting network connections during an incident, potentially impacting operations, has been fraught with second-guessing. Hindsight is always 20/20, and security teams are often criticized afterward regardless of the decision they made.
“But this needs to be normalized. With the rate of attacks we’re seeing, especially with AI dramatically increasing the speed at which attacks can unfold, security teams need to have disconnecting network connections on the table as a legitimate course of action. Organizations should establish that authority before an incident happens, and security teams shouldn’t be punished for using it when the situation calls for it.”
Hayden Covington, Associate Director of Security Operations, Black Hills Information Security:
“What makes groups like Salt Typhoon dangerous is that they are difficult to detect; not just because they use living-off-the-land techniques, but also because they aren’t a smash and grab operation where eventually the threat actor runs ransomware and you know they’re there. Groups like this are focused on espionage, aiming for long dwell times while they quietly collect sensitive information. Catching an attacker like that often comes down to knowledge of your environment and the ability to dig into anomalies deep enough to know that something malicious is actually happening.”
I have to admit that this is crafty and full of old school thinking. But this needs to be normalized and not the exceptional because everyone everywhere needs to hunt down threat actors and kick them off of any network ASAP.
Related
This entry was posted on August 21, 2026 at 9:00 am and is filed under Commentary with tags T-Mobile. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
T-Mobile physically cuts network connection to eject Salt Typhoon hackers
Larry Pesce, VP of Services, Finite State:
“Credit first: T-Mobile’s team hunted down Salt Typhoon in days when peer carriers had them resident for months, and that’s genuinely impressive work. But this article is written for a general audience, and it shows. It reads like a movie script, complete with the team piling into the CSO’s Tesla, and for anyone who has actually run an incident it leaves a lot of important questions on the cutting room floor.
“Start with the powered-off router in California. The likely explanation for the spoofing is mundane: the attackers were working from stale topology data and impersonated a device they didn’t know was dark. That mistake is probably what burned them. But flip it around and it’s less flattering: T-Mobile’s own telemetry was attributing live traffic to a device that its own asset inventory should have shown as powered off. The gap between what the network claimed and what the hardware was actually doing is the real story here. Accurate hardware inventory and device status is unglamorous work, and it’s exactly the kind of thing that determines how long an adversary gets to live in your network.
“Then there’s the handling of that router. Per the article, the CSO told a staffer to “rip” a device suspected of nation-state compromise out of the rack, put it in his car, and drive it hundreds of miles to headquarters. Set aside the scissors for a moment. Where’s the chain of custody? Where’s the forensic imaging before the device gets bounced down I-5 in a trunk? For an artifact that might end up mattering to a federal investigation into Salt Typhoon, that’s a detail that made me wince.
“As for the scissors: I’ve spent time in data centers of this caliber, and scissors are not part of the standard tech loadout. Every one of those links terminates somewhere you can unplug it, shut down at a patch panel, or kill via CLI. Simon concedes as much in the article, admitting they could have turned the device off virtually. Cutting the cable accomplished nothing that unseating a connector wouldn’t, except producing a frayed trophy now framed in the lobby. I don’t doubt the cable got cut. I just notice that the version that made a better artifact is the version that happened.
“The substantive issue is what the fast, loud response cost them. Walk the IR lifecycle: containment, absolutely, they nailed it. But by their own account, powering the device back up in an isolated environment later yielded little. The attackers were long gone, and so was the volatile evidence. Abruptly severing the link also told the adversary, unambiguously, that they’d been made. A more patient play, instrumenting the device and the interconnect while quietly constraining what the attackers could reach, likely would have produced far more intelligence about tooling, tradecraft, and other footholds. That matters a great deal when the adversary is a state actor with confirmed presence across nine other carriers. Containment without eradication just means round two happens somewhere you aren’t watching.
“To be clear, I’m confident T-Mobile’s IR capability is far more sophisticated than this telling suggests, and some of what looks like theater may just be what survives the corporate comms filter. But that’s exactly the problem. The sanitized, cinematic version is the one the industry got, and the useful version, the one about inventory hygiene, trusted carrier interconnects as an attack surface, evidence handling under pressure, and the real tradeoff between fast containment and thorough eradication, is the one we actually needed.”
Seemant Sehgal, Founder and CEO, BreachLock:
“Cutting a cable makes for good storytelling, but the real headline is that a disciplined security team found an adversary that had worked hard to stay hidden. The significance of the Salt Typhoon campaign is the scale and persistence of the operation, targeting telecommunications infrastructure to gain access to highly valuable data. Based on public reporting, the attackers appear to have leveraged network infrastructure and maintained covert access paths, which highlights how difficult these intrusions can be to detect once established. Many organizations in that situation would still be writing incident reports while the attacker moved laterally. T-Mobile’s team located the threat, made a call, and physically removed it from the equation. That takes clarity of judgment under pressure, and that is genuinely rare.”
Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:
“The dramatic part of this story is that T-Mobile physically cut a cable, but the bigger lesson is how difficult sophisticated nation-state actors can be to find and remove. Salt Typhoon demonstrates why organizations need visibility into what is actually communicating across their networks, not simply what their asset management tools say should be there. When you identify a compromised system, decisive containment matters more than elegant containment. Sometimes the right incident-response decision really is to pull the plug.”
John Strand, Owner, Black Hills Information Security:
“There’s only one firewall in existence that is 100% effective, and this is it. Physically cutting the line.
“I look at stories like this and think security teams need to be empowered to make that decision. For years, the idea of actually cutting network connections during an incident, potentially impacting operations, has been fraught with second-guessing. Hindsight is always 20/20, and security teams are often criticized afterward regardless of the decision they made.
“But this needs to be normalized. With the rate of attacks we’re seeing, especially with AI dramatically increasing the speed at which attacks can unfold, security teams need to have disconnecting network connections on the table as a legitimate course of action. Organizations should establish that authority before an incident happens, and security teams shouldn’t be punished for using it when the situation calls for it.”
Hayden Covington, Associate Director of Security Operations, Black Hills Information Security:
“What makes groups like Salt Typhoon dangerous is that they are difficult to detect; not just because they use living-off-the-land techniques, but also because they aren’t a smash and grab operation where eventually the threat actor runs ransomware and you know they’re there. Groups like this are focused on espionage, aiming for long dwell times while they quietly collect sensitive information. Catching an attacker like that often comes down to knowledge of your environment and the ability to dig into anomalies deep enough to know that something malicious is actually happening.”
I have to admit that this is crafty and full of old school thinking. But this needs to be normalized and not the exceptional because everyone everywhere needs to hunt down threat actors and kick them off of any network ASAP.
Share this:
Like this:
Related
This entry was posted on August 21, 2026 at 9:00 am and is filed under Commentary with tags T-Mobile. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.