Skip to main content
T-MobileSecurity incident

T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network

What happened

T-Mobile identified and expelled Chinese hackers, part of a group called Salt Typhoon, from its network in 2024.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

New reporting from Bloomberg revealed how cybersecurity staff at U.S. phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide intrusions by Beijing aimed at stealing customer data. The hacks were carried out by a Chinese government-backed hacking group called Salt Typhoon. The campaign compromised hundreds of phone companies, internet giants, and datacenter providers with the goal of collecting phone records and information about senior U.S. government officials, including then-presidential candidates. Hacked companies included AT&T, Verizon, satellite phone network Viasat, and network infrastructure giants Charter and Windstream. By and large, T-Mobile escaped a widescale breach of its network by catching the activity early - and resorted to physically cutting the cable to a compromised system, per Bloomberg. The publication said T-Mobile's cyber staff spent months looking for suspected hackers in its network without success. Eventually, the company found unusual behavior on one of its systems coming from another router belonging to a different telecom company, which T-Mobile did not name. After identifying the breach, T-Mobile's cybersecurity chief Jeff Simon told Bloomberg that he and three others drove to the nearby Bellevue, Washington, data center, found the compromised system, pulled out a set of...

Keep reading with a free account

The rest of this article, and every signal for T-Mobile, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Location
Bellevue, Washington, United States

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
Intrusion by Chinese government-backed hacking group called Salt Typhoon

Extraction

Confidence
90%
Detected
Aug 19, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for T-Mobile and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at T-Mobile this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/13350a4c-d113-f17a-4279-52ef2a33b381 returns this record as JSON. POST /v1/companies/enrich returns every signal for t-mobile.com.

{
  "signal_id": "13350a4c-d113-f17a-4279-52ef2a33b381",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-08-19T17:26:32+00:00",
  "company": {
    "name": "T-Mobile",
    "domain": "t-mobile.com"
  },
  "data": {
    "url": "https://techcrunch.com/2026/08/19/t-mobile-chopped-a-cable-to-expel-chinese-hackers-from-its-network/",
    "title": "T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network",
    "author": "Zack Whittaker",
    "excerpt": "New reporting from Bloomberg revealed how cybersecurity staff at U.S. phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide intrusions by Beijing aimed at stealing customer data. The hacks were carried out by a Chinese government-backed hacking group called Salt Typhoon . The campaign compromised hundreds of phone companies, internet giants, and datacenter providers with the goal of collecting phone records and information about senior U.S. government officials, including then-presidential candidates. Hacked companies included AT&T, Verizon , satellite phone network Viasat , and network infrastructure giants Charter and Windstream . By and large, T-Mobile escaped a widescale breach of its network by catching the activity early - and resorted to physically cutting the cable to a compromised system, per Bloomberg. The publication said T-Mobile’s cyber staff spent months looking for suspected hackers in its network without success. Eventually, the company found unusual behavior on one of its systems coming from another router belonging to a different telecom company, which T-Mobile did not name. After identifying the breach, T-Mobile’s cybersecurity chief Jeff Simon told Bloomberg that he and three others drove to the nearby Bellevue, Washington, data center, found the compromised system, pulled out a set of...",
    "summary": "T-Mobile identified and expelled Chinese hackers, part of a group called Salt Typhoon, from its network in 2024.",
    "location": "Bellevue, Washington, USA",
    "planning": false,
    "image_url": "https://techcrunch.com/wp-content/uploads/2025/01/t-mobile-store-times-square.jpg?resize=1200,800",
    "confidence": 0.9,
    "published_at": "2026-08-19T17:26:32Z",
    "location_data": [
      {
        "city": "Bellevue",
        "state": "Washington",
        "region": "Northern America",
        "country": "United States",
        "continent": "Americas",
        "fuzzy_match": false
      }
    ],
    "vulnerability": "Intrusion by Chinese government-backed hacking group called Salt Typhoon",
    "article_sentence": "New reporting from Bloomberg revealed how cybersecurity staff at U.S. phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide intrusions by Beijing aimed at stealing customer data."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.