T-Mobile's cybersecurity chief and three colleagues drove to a Bellevue data center in November 2024, found a compromised network connection and snipped it with scissors, severing Chinese state-backed hackers from the company's systems in seconds.

A frayed piece of that yellow cable now hangs framed at T-Mobile's Bellevue headquarters.

Jeff Simon, T-Mobile's cybersecurity chief, recounted the incident to Bloomberg in an interview published Wednesday, Aug. 19. He called the framed wire "a small little trophy and a remembrance."

The hack was part of Salt Typhoon, a sweeping Chinese espionage campaign that compromised at least nine U.S. telecom companies and more than 200 organizations across roughly 80 countries in 2024, according to TechCrunch.

AT&T, Verizon, Charter and Windstream were among the victims. The hackers targeted lawful-intercept systems used for law enforcement wiretaps, call records and location data, and actively monitored communications of roughly 150 high-value individuals, including personnel from both the Harris and Trump presidential campaigns.

T-Mobile's security team had spent months hunting for Salt Typhoon activity on its network, using intelligence shared by government agencies and other carriers. The breakthrough came when analysts spotted anomalous traffic on a T-Mobile system and traced it to a router owned by another telecom company.

Simon told Mobile World Live the attackers used a disguised router in Chicago, made to appear as a California router, so it could communicate with a T-Mobile machine near the Bellevue headquarters. He called it "a smart trick" used to infiltrate multiple carriers.

Simon said his team could have disabled the router remotely but chose the physical cut because it was faster and more certain. "There's nothing that replaces cutting the cord," he told Bloomberg.

After severing the connection, investigators examined the router's data and reactivated it in an isolated environment. They found the intruders had already left, having reached only edge routing infrastructure rather than T-Mobile's core network or customer data. T-Mobile has maintained that no customer calls, texts or voicemails were accessed.

The FBI has said Salt Typhoon has been active since at least 2019. In January 2025, the U.S. Treasury sanctioned Sichuan Juxinhe Network Technology Co., identifying it as the group's corporate enabler. Beijing has denied involvement.

In May 2026, T-Mobile joined AT&T, Verizon, Comcast and four other carriers to form the Communications Cybersecurity Information Sharing and Analysis Center, a nonprofit aimed at strengthening sector-wide defenses against campaigns like Salt Typhoon.