What happened
T-Mobile chief security officer Jeff Simon revealed this week — in an account first reported on August 18 — that the company once resorted to physically cutting a network cable to expel China-linked Salt Typhoon hackers. In 2024, after months of tracing suspicious activity that appeared to arrive through a router operated by another telecom provider, four members of T-Mobile's security team drove to a data center near Bellevue, Washington, and severed the connection to a compromised server with a pair of scissors. Salt Typhoon is the espionage group accused of burrowing into major carriers — reporting has named AT&T, Verizon, Lumen, Charter, and Windstream among affected organizations — to collect call records and communications metadata tied to government officials. T-Mobile says it caught the activity early, before the intruders reached customer data or core systems, and the snipped cable now sits framed at company headquarters.
Why it matters for your business
The story is colorful, but the lesson is practical. Salt Typhoon moved through trusted interconnections — one provider's compromised equipment became the doorway into another. Small businesses face the same dynamic at a smaller scale: your network is only as trustworthy as the vendors, providers, and managed devices plugged into it. The other lesson is speed. T-Mobile avoided the large-scale compromise its peers suffered because someone noticed anomalous traffic, investigated for months, and then acted decisively — even crudely — the moment containment was needed.
What to do about it
- Keep an inventory of every third-party connection into your network, from ISP equipment to vendor remote-access tools.
- Make sure someone — in-house or an MSP — is actually watching for unusual traffic, not just installing tools.
- Have an isolation plan: knowing how to disconnect a compromised system fast matters more than doing it gracefully.
