Observed Signal · Aug 19, 2026 · Security Incident · Source: techcrunch · Impact: 3/5 · Sentiment: Negative

T-Mobile Cut a Cable to Expel Chinese Hackers

Executive Signal Summary

Reporting says a 2024 state-linked espionage campaign known as Salt Typhoon, widely attributed to the Chinese Ministry of State Security, compromised more than 200 targets in roughly 80 countries and infiltrated nine major U.S. telecommunications firms, including AT&T, Verizon and T‑Mobile. T‑Mobile personnel, led by executive Jeff Simon, located a compromised device at a carrier data‑center site (accounts variously cite Bellevue, WA and Chicago), physically severed its external connection and seized the hardware to isolate the intrusion. The campaign targeted edge networks to collect phone records and information on senior U.S. officials; Simon and others said intruders could observe metadata but did not obtain customer data.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A major telecom operator detected and removed state-linked intruders who were targeting phone records and sensitive data; this affects core network security, data/identity integrity, and could drive regulatory and operational changes across infrastructure providers.

SIGNAL RADAR

Track T-Mobile Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Salt Typhoon, attributed to the Chinese Ministry of State Security, hit >200 targets across ~80 countries in 2024.
  • Nine major U.S. telecoms were affected, including AT&T, Verizon and T‑Mobile.
  • T‑Mobile personnel led by Jeff Simon located a compromised device at a carrier data‑center site, cut its external connection and seized the device.
  • Attackers accessed edge networks and could have observed metadata; T‑Mobile says customer data was not exposed.
  • The campaign sought phone records and information on senior U.S. officials.

Connected Companies & Entities

7 Entities mapped

“New reporting from Bloomberg revealed how cybersecurity staff at U.S. phone provider T-Mobile identified and expelled Chinese hackers from i...”

“Hacked companies included AT&T, Verizon, satellite phone network Viasat, and network infrastructure giants Charter and Windstream....”

“New reporting from Bloomberg revealed how cybersecurity staff at U.S. phone provider T-Mobile identified and expelled Chinese hackers from i...”

“Hacked companies included AT&T, Verizon, satellite phone network Viasat, and network infrastructure giants Charter and Windstream....”

“Hacked companies included AT&T, Verizon, satellite phone network Viasat, and network infrastructure giants Charter and Windstream....”

“Hacked companies included AT&T, Verizon, satellite phone network Viasat, and network infrastructure giants Charter and Windstream....”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Aug 19, 2026
Original Coverage Title: “T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

SecuritySep 20, 2026

T-Mobile Technician Cuts Cable to Thwart Salt Typhoon Hack

Bloomberg reports that T-Mobile's cybersecurity team ended a Salt Typhoon espionage attack by physically cutting a cable at a data center in Chicago. In autumn 2024, the Chinese hacking campaign infiltrated nine major US telecoms, including Verizon, AT&T, and T-Mobile, compromising routers and accessing metadata of millions of customers. T-Mobile's security team traced a suspicious signal to a manipulated router in Chicago that was spoofed as a T-Mobile device, operated by attackers. A technician drove to the site and cut the router's cable with scissors, halting the attack. The attackers only gained access to external networks, not customer data, according to T-Mobile's CIO Jeff Simon. The severed cable is now displayed in a frame at T-Mobile as a memento of the physical response to cyber threats.

Read assessment
InfrastructureMar 9, 2026

Salt Typhoon: Global Espionage Campaign Targets Telecom Giants

Security researchers and U.S. officials attribute a broad espionage campaign to a China-linked hacking group known as Salt Typhoon. The group has targeted telecom and internet providers worldwide, exploiting Cisco routers at network edges and compromising surveillance devices that enable lawful intercept. Researchers and the FBI say Salt Typhoon has hacked at least 200 companies and stolen tens of millions of phone records, including call records, texts and captured phone audio from senior U.S. officials. Confirmed U.S. victims include AT&T, Verizon, CenturyLink (now Lumen), Viasat, Charter Communications (Spectrum), Windstream and Consolidated Communications; T-Mobile reported it was targeted but said customer communications were not accessed. Security firms Recorded Future and Trend Micro have observed activity across the Americas, Europe, Asia, Africa and Oceania, and the FBI urged U.S. users to adopt end-to-end encrypted messaging.

Read assessment
CybersecurityMar 5, 2026

FBI Networks Breached: Hackers Target Surveillance Systems

TechCrunch reports that hackers breached FBI networks, reportedly affecting a system used to manage wiretaps and foreign intelligence surveillance warrants, according to CNN. The FBI told TechCrunch it identified and addressed suspicious activity on its networks and used technical capabilities to respond but declined to provide details. The article places the incident in the context of recent major intrusions into U.S. government and corporate systems, noting prior breaches of the U.S. Treasury, the National Nuclear Security Administration, and the U.S. Courts’ filing system. The piece also cites the FBI saying the Chinese government-linked hacking group Salt Typhoon has compromised at least 200 U.S. companies, with confirmed victims including AT&T, Verizon, Lumen, Charter Communications and Windstream.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.