T-Mobile Cut a Cable to Stop Salt Typhoon

Bloomberg says T-Mobile detected the Chinese state-backed group Salt Typhoon on its network in 2024 and contained it by physically disconnecting a compromised system at a Bellevue, Washington, data center. The company had spent months looking for the intrusion before spotting unusual traffic tied to a router owned by another telecom. The important detail is the path in: the activity arrived through carrier-to-carrier adjacency, so it looked like ordinary interconnect traffic rather than a direct break-in. Once T-Mobile found the box, it severed the cable instead of trying to clean the system in place, which stopped spread across the trusted link. For telecom operators and backbone teams, the exposure here sits on the peering path itself. If a partner carrier’s router can be the foothold, then containment has to account for interconnect trust, not just the host that finally shows signs of compromise.

Part of the PlainSec briefing for 2026-08-19

Every edition of this story: T-Mobile Cut a Cable to Stop Salt Typhoon

Sources