On August 18, 2026, Jeff Simon — T-Mobile’s chief security officer during the Salt Typhoon campaign and now the carrier’s chief information officer — told Bloomberg how his team finally got China’s state-backed hackers off the network.
They drove to a data center in Bellevue, Washington, badged in, found the box, and cut its cable with a pair of scissors.
The frayed length of yellow cable now hangs framed at T-Mobile’s headquarters. Simon called it “a small little trophy and a remembrance.”
It is a good story, and — unusually for this beat — a story about a defense that worked. It is also a story about T-Mobile, a company that has disclosed a security incident in nearly every year since 2015 and has paid out, across settlements and regulatory penalties, more than half a billion dollars in publicly disclosed amounts. Both things are true, and the second is what makes the first worth examining closely.
What Actually Happened in November 2024
Through the second half of 2024, Salt Typhoon was tearing through American telecommunications. AT&T, Verizon, Lumen, Charter, Windstream, Consolidated Communications and Viasat were among the carriers ultimately named. The operation harvested call records and metadata, and reached the phones of senior political figures including Donald Trump, JD Vance and staff associated with Kamala Harris. Beijing has denied involvement throughout.
T-Mobile hunted for the group on its own network for months and found nothing.
What eventually surfaced was not malware on a T-Mobile server. It was anomalous traffic arriving from a connected wireline provider’s network — traffic originating from a router belonging to a different telecom that had a trusted connection into T-Mobile’s environment. The intruders had reached edge routing infrastructure. According to T-Mobile, they never reached core systems or customer data.
The response was to sever the connection physically rather than administratively. Simon and three colleagues went to the facility. One of them badged in. The cable came out.
Simon wrote in a public T-Mobile blog post at the time, in November 2024:
“We quickly severed connectivity to the provider’s network as we believe it was – and may still be – compromised.”
That sentence, read in 2024, sounded like standard incident-response boilerplate. Read against Bloomberg’s 2026 account, it is a literal description of four people with scissors.
Simon has said the attackers were present for a single-digit number of days — a dwell time far shorter than what other carriers experienced, several of whom hosted Salt Typhoon for months and, in some cases, inside the CALEA lawful-intercept systems themselves. T-Mobile reported no evidence of impacts to customer information.
Why the Scissors Are the Point
The instinct to read this as improvisation misses what it demonstrates.
Cutting a physical cable is the correct action when you cannot trust that a logical disconnect will hold. If an adversary has reached routing infrastructure, then the control plane you would use to shut down the interface is inside the blast radius. An ACL, a port shutdown, a firewall rule — each of those is a configuration change on equipment whose integrity is exactly what is in question. Layer 1 is the only layer an attacker with router access cannot roll back.
The second lesson is the one the industry keeps relearning and keeps failing to act on: the compromise came in over a trusted peer connection. T-Mobile’s own controls were not what failed. Another carrier’s were, and the interconnect between them carried the consequence. The telecom sector is a mesh of these trust relationships by design — peering, roaming, transit, wholesale — and Salt Typhoon has spent years demonstrating that the mesh is the attack surface. It is the same structural weakness that let the campaign reach Norway’s networks and House committee email systems.
Third: T-Mobile searched for months and found nothing, then found the intrusion by watching traffic from a partner rather than hunting for indicators inside itself. Detection worked because someone was monitoring the seams.
The Record That Makes This Complicated
T-Mobile’s Salt Typhoon response deserves the credit it is getting. It also arrived at a company that had, by 2024, been under a federal consent framework specifically because of how often it had been breached.
Here is the record.
October 2015 — Experian. Attackers breached Experian, which processed T-Mobile’s credit checks. Roughly 15 million people who applied for T-Mobile service or device financing between September 2013 and September 2015 had names, addresses, dates of birth, Social Security numbers, and driver’s license, military ID or passport numbers exposed. A multistate attorneys general settlement in 2022 resolved claims for $16 million.
October 2017. A flaw in a T-Mobile web tool allowed account data to be retrieved for arbitrary phone numbers. Researchers estimated the exposure could have reached tens of millions of accounts; T-Mobile said the issue was fixed within a day.
August 2018. An exploited API exposed data on approximately 2 million subscribers — names, account numbers, billing ZIP codes, phone numbers, email addresses.
November 2019. More than 1 million prepaid accounts exposed: names, addresses, phone numbers, account numbers.
March 2020. Compromise of employee email accounts exposed data on both employees and customers. For a subset, that included Social Security numbers and financial information.
December 2020. Approximately 200,000 customers had CPNI exposed — customer proprietary network information, meaning call records: numbers dialed, timestamps, call duration. CPNI is the category the FCC regulates most tightly, and the category Salt Typhoon would come hunting for four years later.
February 2020 — the SIM swap. Attackers convinced a T-Mobile employee to port entrepreneur Josh Jones’s phone number to a SIM they controlled, despite the account carrying an eight-digit PIN. They drained over 1,500 Bitcoin and roughly 60,000 Bitcoin Cash — about $38 million at the time. An arbitrator later found T-Mobile had violated the Federal Communications Act by failing to protect the customer’s information and awarded $33 million, including more than $6.5 million in fees. The award stayed confidential until a petition to confirm it made the case public — a detail we covered in our look at why old telecom breaches get more dangerous with age.
August 2021 — the big one. 76.6 million current, former and prospective customers. Names, dates of birth, Social Security numbers, driver’s license numbers. Around 7.8 million were active postpaid customers; roughly 40 million were former or prospective ones who had merely applied. Nearly a million prepaid customers also had phone numbers and account PINs exposed. John Erin Binns, operating as IRDev, claimed responsibility and attempted to sell the data on a dark web forum for about $270,000. T-Mobile settled the resulting class action for $350 million — among the largest data breach settlements in US history — and committed a further $150 million to security improvements. Final approval came June 29, 2023.
April 2022 — Lapsus$. The extortion crew, largely teenagers, used stolen credentials to get into T-Mobile’s internal environment, downloaded more than 30,000 source code repositories, and reached Atlas, an internal tool for managing customer accounts. Brian Krebs published the internal chat logs.
January 2023 — API again. An attacker abused an exposed API from November 25, 2022 to January 5, 2023, harvesting data on 37 million postpaid and prepaid accounts: names, billing addresses, emails, phone numbers, dates of birth, account numbers, line counts and plan features. T-Mobile detected it on January 5 and cut access the next day. Five years after the 2018 API breach, the same class of flaw produced eighteen times the victims.
April 2023. A smaller but more severe incident: 836 customers, with Social Security numbers, government ID numbers and account PINs exposed.
September 2023. Two separate events — an internal system error during a technology update briefly exposed account details for fewer than 100 customers, and a breach at Connectivity Source, a T-Mobile authorized retailer, exposed an 89 GB cache containing employee emails, partial SSNs and customer order records.
September 2024 — the FCC settles. T-Mobile agreed to $31.5 million to resolve FCC investigations into the 2021, 2022 and 2023 breaches: $15.75 million as a civil penalty and $15.75 million committed to security. The consent decree required phishing-resistant multifactor authentication company-wide, network segmentation to limit lateral movement, routine data minimization and deletion, and third-party security audits. The FCC noted the breaches “varied in their nature, exploitations, and apparent methods of attack” — regulator language for these were not one repeated mistake, they were many different ones.
Then, two months later, Salt Typhoon.
The Honest Reading
The sequence is not a coincidence, and it should not be read cynically either.
The 2021 breach cost T-Mobile half a billion dollars in settlement and committed security spending. The FCC decree mandated segmentation and phishing-resistant MFA on a deadline. In November 2024, the carrier detected a nation-state intrusion at the network edge in days, contained it before it reached core systems, and — by its own account and the absence of any subsequent contradicting disclosure — kept customer data out of it. That is what the money was supposed to buy. Occasionally it does.
But the pattern before it is the reason to hold the applause at a normal volume. Nine disclosed incidents in a decade. Two API breaches five years apart with the same root cause. A regulator concluding that the failures were varied rather than repeated. A $33 million arbitration award for a single SIM swap that eight-digit PIN protection did not prevent.
The framed cable is a real achievement. It is also, unavoidably, a monument mounted on a wall inside a building where the previous decade happened.
What This Means For You
If you operate a network with trusted peer or partner interconnects — telecom, financial messaging, healthcare clearinghouse, EDI, anything — the T-Mobile detection is the transferable part. The intrusion did not announce itself inside T-Mobile’s assets. It announced itself as anomalous traffic arriving from a partner. Instrument the interconnect as a monitored boundary, not as trusted internal space, and baseline what normal traffic from each partner looks like so abnormal is visible.
If you are writing an incident response plan, add the Layer 1 option explicitly. Establish in advance who can authorize a physical disconnect, who has 24/7 badge access to each colocation facility, and what the escalation path is at 2 a.m. Being right about the containment action is worthless if you cannot get into the building.
If you are a T-Mobile customer, the 2021 breach exposed Social Security numbers for tens of millions of people. That data does not expire. Freeze your credit at all three bureaus if you have not, and move your account off SMS-based authentication for anything financial — the SIM swap cases show that a PIN on the account is not a control that reliably holds against social engineering of retail staff.
If you assess vendors, note which risk T-Mobile’s spending actually retired. The money bought better detection and segmentation, which is what stopped a nation-state at the edge. It did not stop the API exposures, the retailer breach, or the SIM swaps, because those are different failures. Security investment is not fungible across categories, and a strong incident-response story tells you nothing about the state of a company’s access controls.
Sources
- TechCrunch: T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network
- Bloomberg: T-Mobile Cyber Staff Chopped Cable After Finding Chinese Hack
- Cybernews: T-Mobile cut cable by hand to stop Chinese hackers
- Mobile World Live: T-Mobile US CIO recounts hunt for Salt Typhoon hackers
- eSecurity Planet: T-Mobile Cuts Network Cable to Stop Salt Typhoon Hackers
- CyberScoop: T-Mobile reaches $31.5 million settlement with FCC over past data breaches
- Firewall Times: T-Mobile Data Breaches: Full Timeline
- Security.org: T-Mobile Data Breach — Full History and Settlements
- BleepingComputer: T-Mobile hacked to steal data of 37 million accounts in API data breach
- SecurityWeek: T-Mobile Coughed Up $33 Million in SIM Swap Lawsuit
- SecurityWeek: US States Announce $16M Settlement With Experian, T-Mobile



