T-Mobile Cut Cable to Eject Salt Typhoon Hackers

T-Mobile ended its months-long hunt for Salt Typhoon in November 2024 by driving to a data center and physically cutting the network cable feeding a compromised router. Jeff Simon — the carrier's chief security officer during the campaign and now its chief information officer — disclosed the previously unreported details in an interview with Bloomberg News.

No CVE has been tied to the T-Mobile intrusion attempt, and the company has never named the wireline provider whose network the attackers pivoted from. Simon says the intruders reached edge routing infrastructure but never touched core systems or customer data — consistent with T-Mobile's November 2024 statement that it severed connectivity to a compromised partner network.

How the Spoofed Router Gave Salt Typhoon a Path In

The first signal was a router at a California data center that appeared to be talking to another T-Mobile machine. When a staffer went to inspect it, the device was powered off. The traffic was instead traced to a router in Chicago, owned by another telecom operator Simon declined to name, which had been disguised to impersonate the California device so the T-Mobile machine near Bellevue, Washington would trust it. Simon called the technique "a smart trick" used to jump between carriers.

Four staff members drove to the Bellevue-area facility, badged in and cut the cable with scissors. The router was later reactivated in an isolated environment for forensics, but the operators were gone. Simon conceded the device could have been disabled remotely — the physical cut was simply faster and left no doubt.

Salt Typhoon CVEs and Artifacts to Check Now

Salt Typhoon has not used zero-days. The CISA joint advisory AA25-239A names these n-days as its initial-access set:

CVEProductNote
CVE-2023-20198Cisco IOS XE Web UICVSS 10.0 auth bypass; WSMA paths often double-encoded
CVE-2023-20273Cisco IOS XEChained with the above for root
CVE-2018-0171Cisco Smart Install2018 flaw, still exploited in the wild
CVE-2024-3400Palo Alto PAN-OS GlobalProtectUnauthenticated RCE
CVE-2024-21887Ivanti Connect Secure / Policy SecureCommand injection

On the devices themselves, advisories point defenders at ACLs added under names such as access-list 20, unexpected GRE tunnels, SSH moved to non-standard ports, and packet capture aimed at TACACS+ traffic on TCP/49. A router that appears to be communicating while it is powered down, as at T-Mobile, is a spoofing indicator worth alerting on directly.