By citing the disclosure of informed information, T-Mobile eventually stopped hackers from remaining in its system by cutting off the physical connection of the affected equipment to the external network in response to a web invasion of the United States communications industry in 2024.
The attack was attributed to Salt Typhoon, a hacker organization supported by the Chinese Government. It was reported that the organization had targeted a number of telephone companies, Internet businesses and data centre operators with the intention of obtaining user communications records and information from senior United States officials.
The invasion affected many communications companies.
In addition to T-Mobile, AT&T, Verizon, the satellite communications network Viasat, and network infrastructure enterprises such as Charter, Windstream are also listed as affected. It was reported that the key to T-Mobile ' s failure to achieve a wider loss was the early detection of unusual activity.
T-Mobile ' s security team allegedly spent months searching the inside network for the attackers, but has never found a clear entry point. Until then, the company discovered unusual behaviour on a system and the traffic came from a router of another telecommunications company.
Security team to hangar disposal
According to Bloomberg, following the identification of the affected equipment, the Chief Information Security Officer of T-Mobile, Jeff Simon, together with three other individuals, travelled to the data centre near Bellevue, Washington State, to find the corresponding system and cut the cable linking the equipment to the external network directly.
This approach essentially isolates the affected nodes from the outside world. In the case of communications operators, this treatment, while direct, also indicates that the disposal of events was at a high priority stage.
There's no public leak.
Salt Typhoon has been associated with infiltrations of United States communications systems on several occasions. Such attacks do not focus solely on single enterprise data, but also on broader communications records and sensitive target information.
TechCrunch states that T-Mobile has been asked for more details in this regard, and the report will be updated if responded. The current public information has not shown that T-Mobile has experienced a large-scale outburst of customer data during the incident.
