T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move followed months of investigation into activity linked to Salt Typhoon, the China-associated espionage group accused of infiltrating telecommunications and internet providers worldwide.
The event shows how serious the campaign is and how important it is for defenders to act fast when a skilled attacker gets into important network areas.
T-Mobile Cuts Network Cable to Kick Salt Typhoon Hackers
Analysts found strange activity on a system that seemed to come from a router used by another, unnamed telecom company. The discovery suggested a possible route into T-Mobile’s network via linked carrier systems.
Jeff Simon, T-Mobile’s chief security officer, and three colleagues reportedly traveled to a data center near the company’s Bellevue, Washington headquarters to locate the affected equipment.
Rather than relying solely on remote remediation or waiting for a more conventional containment process, the team used scissors to sever the physical cable connecting the suspected compromised hardware to the external network.
The action quickly separated the device and stopped the attackers from getting in. Bloomberg said the cable was later put in a frame and shown at T-Mobile’s headquarters to remind everyone of the event.
The episode shows how hard defenders had to work against an opponent that could shift between linked network systems. Salt Typhoon’s skill to move within shared systems, taking advantage of trusts between telecom routers, has made this campaign one of the most important state-backed attacks in U.S. telecom history.
FBI officials say the threat is still happening, and the high number of known victims shows that the group still has access to parts of global telecom systems, even though companies like T-Mobile are trying to shut them out.
A security team chose scissors over a software fix to stop a hacker. This shows that sometimes the quickest way to deal with a nation-state hacker is to disconnect them.
Salt Typhoon targeted telecom companies and network systems worldwide. U.S. Officials have reported that the group’s work centered on gathering private communication information, like call logs and data related to important government leaders and politicians.
The campaign reportedly impacted big telecom companies like AT&T, Verizon, Lumen, Charter Communications, and Windstream.
Related News:
China’s Salt Typhoon of espionage attacks: Norwegian intelligence discloses
T-Mobile Says Personal Information Stolen in New Data Breach
InfoSecBulletin Cybersecurity for mankind
