T-Mobile’s cybersecurity team reportedly turned to an unusually simple containment measure during its fight against the Chinese state-backed Salt Typhoon hacking group.
The team physically cut a network cable to disrupt the threat actor’s access.
Key takeaways
- T-Mobile physically cut a network cable to disrupt Salt Typhoon’s access after tracing suspicious activity to infrastructure connected to another telecom provider.
- The Salt Typhoon campaign reportedly compromised at least 200 organizations across 80 countries, with telecommunications infrastructure among its primary targets.
- Trusted network relationships can create attack paths that allow threat actors to leverage compromised providers and interconnected infrastructure to access other environments.
- Organizations should validate containment capabilities by strengthening network segmentation, monitoring third-party connections, hardening network devices, and regularly testing incident response plans.
Inside the Salt Typhoon attack on T-Mobile
This incident was part of the broader Salt Typhoon espionage campaign targeting telecommunications and internet infrastructure in the United States and abroad.
The Chinese government-linked group reportedly compromised at least 200 organizations across 80 countries, targeting communications data and metadata tied to government officials and other sensitive targets.
T-Mobile was first publicly connected to the campaign in November 2024, as telecommunications providers across the United States investigated similar compromises.
At the time, the carrier said it had not found evidence that customer data was affected.
Other organizations linked to the wider Salt Typhoon campaign have included AT&T, Verizon, Lumen, Charter Communications, and Windstream.
How Salt Typhoon exploited trusted networks
The attackers focused heavily on telecommunications infrastructure, including routers and other network devices that can provide access to sensitive traffic or trusted connections between carriers.
Interconnected environments can increase risk by enabling threat actors to leverage a compromised provider’s trusted network relationships to move laterally through other connected systems.
That appears to have been a key factor in T-Mobile’s investigation.
According to Bloomberg’s reporting, the company’s security team spent months searching for signs of the intruders before detecting unusual activity on an internal system.
Investigators eventually traced the suspicious traffic to a router belonging to another, unnamed telecommunications provider connected to T-Mobile’s network.
How T-Mobile contained Salt Typhoon
The discovery gave T-Mobile’s security team a clearer path for containment.
Rather than rely on remote remediation, the team went to a nearby data center and physically cut the cable connecting the compromised hardware to the external network.
The incident highlights how trusted third-party and carrier-to-carrier connections can expose organizations to threats even when strong internal security controls may be in place.
How organizations can reduce risk from similar incidents
The Salt Typhoon campaign highlights the importance of protecting critical network infrastructure from sophisticated and persistent threats.
Organizations should take a layered approach that combines strong access controls, continuous monitoring, network hardening, and effective incident response.
Security teams should also account for risks introduced through trusted third parties and interconnected environments.
- Segment critical infrastructure by restricting communication between sensitive systems, network devices, and third-party environments to reduce lateral movement.
- Harden and patch network devices by promptly updating routers, firewalls, VPN appliances, and other edge devices while restricting unnecessary management interfaces.
- Strengthen privileged access by requiring strong authentication, including phishing-resistant MFA where supported, and regularly reviewing administrative accounts and permissions.
- Monitor network activity and configuration changes by establishing traffic baselines and alerting on unusual connections, routing changes, and unauthorized modifications.
- Maintain comprehensive logging by centralizing network, authentication, and administrative logs to support threat detection, investigations, and forensic analysis.
- Review third-party connections by continuously assessing trusted partners, service providers, and interconnected networks for unnecessary access and security risks.
- Test incident response plans through regular tabletop exercises and the use of attack simulation tools.
Collectively, these measures can help organizations reduce their overall exposure and build resilience.
Bottom line
The T-Mobile incident is less a lesson in basic network defense than a reminder to validate whether existing controls can contain an intrusion that originates through trusted infrastructure.
Salt Typhoon demonstrates the value of testing assumptions around interconnection points, third-party dependencies, and isolation capabilities before they become part of an active incident.
Using Zero Trust can help organizations reduce risk by continuously validating access across users, devices, applications, and interconnected environments.





