T-Mobile reportedly expelled Chinese state-backed hackers from its network during a 2024 intrusion tied to Salt Typhoon, a broad espionage campaign against telecom and internet infrastructure. After detecting suspicious activity and spending months tracing it through its environment, the carrier identified a compromised system in a data center near Bellevue, Washington and physically disconnected it by cutting a network cable, halting the attackers’ access before a larger breach took hold.
The intrusion was part of a wider operation that U.S. authorities have linked to Salt Typhoon, which allegedly targeted hundreds of telecom, internet, and datacenter providers and sought phone records and communications metadata tied to senior U.S. government officials, including then-presidential candidates. Reports said the malicious traffic was traced to a router associated with another unnamed telecom company, underscoring how the group moved laterally through interconnected carrier infrastructure; other affected firms in the broader campaign reportedly included AT&T, Verizon, Viasat, Charter, and Windstream.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
In November 2024, The Wall Street Journal first connected T-Mobile to the broader Salt Typhoon telecom espionage campaign. At that time, T-Mobile said it had no evidence that customer data was significantly affected.
In 2024, T-Mobile identified suspicious activity tied to a compromised system during a months-long hunt for intruders linked to Salt Typhoon. After tracing the activity to hardware in a data center near Bellevue, Washington, its security team physically severed the cable connecting the system to the outside world to stop the intrusion path.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcetechcrunch.com
Open sourcebloomberg.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.