A pair of scissors became an unlikely cybersecurity tool at T-Mobile after the company discovered that Chinese state-backed hackers had found a way into its network through another telecom provider.
- A pair of scissors became an unlikely cybersecurity tool at T-Mobile after the company discovered that Chinese state-backed hackers had found a way into its network through another telecom provider.
- In a November 2024 statement, Simon said the intrusion originated from a wireline provider connected to T-Mobile's network and that the company had "quickly severed connectivity to the provider's network" because it believed the network was compromised.
- A senior U.S. official said a large amount of Americans' call-record metadata had been stolen, while officials alleged that hackers had obtained telephone audio intercepts and call records in some other cases.
In November 2024, T-Mobile’s security team was investigating unusual traffic involving a router at one of its California data centers. The equipment appeared to be communicating with another T-Mobile device. There was a problem: that second device was powered off.
That discrepancy helped the team uncover a more complicated intrusion. According to an account from T-Mobile CIO Jeff Simon reported by Bloomberg, the traffic was actually coming from a router belonging to another telecom provider in Chicago. The device had been spoofed to appear as if it were T-Mobile equipment, allowing the attackers to use the connection between the networks.
How T-Mobile Traced The Intrusion
Simon, who was T-Mobile’s chief security officer at the time, and three colleagues traveled to a data center near the company’s Bellevue, Washington, headquarters to deal with the compromised connection. The team located the equipment and physically severed the network cable with scissors.
The response was consistent with what T-Mobile had publicly described weeks earlier, although the company had not disclosed the unusual physical intervention. In a November 2024 statement, Simon said the intrusion originated from a wireline provider connected to T-Mobile’s network and that the company had “quickly severed connectivity to the provider’s network” because it believed the network was compromised.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseThe attackers had reached T-Mobile’s edge routing infrastructure, which sits closer to the network perimeter, rather than the company’s core systems holding sensitive customer information. T-Mobile said at the time that its defenses stopped the attackers from advancing and that they had no access to sensitive customer data, including calls, voicemails or texts.
The Broader Salt Typhoon Campaign
The incident unfolded as Salt Typhoon was conducting a much wider cyberespionage campaign against telecommunications companies in the United States and elsewhere. U.S. officials said the campaign had compromised at least eight telecommunications and telecom infrastructure firms by December 2024.
A senior U.S. official said a large amount of Americans’ call-record metadata had been stolen, while officials alleged that hackers had obtained telephone audio intercepts and call records in some other cases. T-Mobile initially stopped short of definitively attributing its own intrusion to Salt Typhoon. Simon wrote in November 2024 that the company could not “definitively identify the attacker’s identity” and had reported its findings to the U.S. government for assessment.
The later account from Simon provides a clearer picture of why the intrusion was difficult to spot. The suspicious traffic appeared to originate from trusted T-Mobile infrastructure, but the equipment supposedly generating it was not even operating. Investigators had to follow the network path beyond what initially appeared to be the source.
Senators Were Warned About The Same Threat
The T-Mobile incident also formed part of a larger national security problem that reached Capitol Hill. On Dec. 4, 2024, U.S. intelligence and law enforcement agencies gave all senators a classified briefing on Salt Typhoon’s efforts to penetrate American telecommunications networks and obtain information about U.S. calls. The FBI, Federal Communications Commission, National Security Council and Cybersecurity and Infrastructure Security Agency were among the agencies involved.
The government said the campaign had reached communications belonging to senior government and political figures. Senators later pressed for stronger safeguards across the telecom industry, while federal officials urged senior officials and politicians to move away from ordinary calls and text messages toward end-to-end encrypted communications.
For T-Mobile, however, the immediate answer was much narrower. The company identified the pathway, traced the deceptive traffic to an outside network and severed the connection. The cable was later kept at T-Mobile’s headquarters as a physical reminder of the incident.
The episode illustrates a basic reality of network security: sophisticated intrusions do not always require a sophisticated final response. Once T-Mobile had identified the pathway being used by the attackers, the fastest way to close it was to disconnect it.
The scissors were not the defense that found Salt Typhoon. They were the last step in cutting off the route the attackers had found.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





