T-Mobile security team cuts the cord in Seattle to thwart Chinese cyber intrusion
Sometimes you gotta get physical.

Image by NurPhoto via Getty Images
- T-Mobile's security chief and three colleagues drove to a Seattle data center to physically cut a cable, instantly severing hacker access.
- Cutting the cable was the fastest, surest way to isolate the Salt Typhoon attack once the infected hardware was found.
- The intrusion occurred during an attack on America’s telecom networks in 2024.
- The snipped cable now sits framed at T-Mobile's HQ as a "trophy."
Four T-Mobile security staff drove to a Seattle data centre and physically snipped a cable to prevent China-linked cyber spies from snooping on the telecom’s networks, it has emerged.
T-Mobile’s security head Jeff Simon made the call at the height of an attack on America’s phone lines in 2024, when it was discovered that China-linked hackers were burrowing their way in US telecom companies.
At least 9 US telecom companies, and many more around the globe, were compromised during the attack by hacking group Salt Typhoon, including At&T, T-mobile, Lumen and Windstream.
Salt Typhoon is a China-linked threat actor famed for targeting government entities and telecom and specializes in lurking inside networks.
This allows hackers to snoop on conversations, launch cyberattacks, redirect internet traffic, spread malware, or access sensitive data.
While this physical approach may seem like an extreme example of network isolation, at the time, no one was sure how long they had been on the network and it was the fastest path to cutting the connection once the specific hardware was identified.
In a recent interview with Bloomberg, T-Mobile’s security chief provided new details about the company’s race to catch the attackers.
The hunt through America’s phone systems
T-Mobile reportedly spent months trying to smoke out criminal activity on its networks.
“Where are they? Have we found them? Have we made contact with the enemy?”T-Mobile's security head Jeff Simon recalls the hunt for Salt Typhoon.
Eventually, they saw suspicious communications coming from a T-Mobile router in a California data centre. But when an employee physically inspected it, the router was powered off.
The telecoms firm discovered that attackers had piggybacked through a connected partner’s infrastructure to gain entry.
According to Simon, the router in the Chicago data centre was disguised as a California-based router so it could connect more easily to another T-Mobile device near the company’s Bellevue headquarters.
“This was the method they were using to gain access to different teleco companies. It’s a smart trick,” he said.
Once they had identified the Washington data center that housed the infected device, Simon jumped into his Tesla with 3 colleagues to cut the cable.
To this day, a frayed piece of yellow cable is framed on display in T-Mobile’s Seattle-area headquarters.
“It’s a small little trophy and remembrance,” he added.
Salt Typhoon: America’s most wanted
The group is still on America’s most wanted list, with the FBI offering a $10 million reward for information on the threat actor.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Recent Salt Typhoon hits include a Canadian telecoms provider and the mobile phones of officials connected to former UK prime ministers Boris Johnson, Liz Truss, and Rishi Sunak.
In January 2025, the US Treasury sanctioned a Chinese cybersecurity firm and a Shanghai-based hacker over alleged links to Salt Typhoon.