Insight·27 August 2026

T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
7 min read
Share
A gloved hand physically pulling the power supply from a rack-mounted server inside a dark telecom data centre
A gloved hand physically pulling the power supply from a rack-mounted server inside a dark telecom data centre

Why it matters

What this means for organisations holding critical data

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

What happened

Cyber security staff at US phone provider T-Mobile identified and expelled Chinese state-backed hackers from its network in 2024, an event now detailed in a Bloomberg report published in August 2026. Faced with an intrusion they could not remove by software means, the team fell back on the one control that could not be argued with: physical disconnection.

But here is what the coverage glosses over. Nobody flipped a switch. The decision to disconnect still had to be delivered by hand: get in the car, drive to the data centre, pass the identity checks, find the cabinet, identify the hardware and physically pull the power supply from the compromised unit. The machine died in their hands. It was the same improvised move Co-op made when it unplugged systems to stop its attackers. The right control, delivered at car-journey speed.

An industry-wide campaign

The intrusion formed part of a sprawling espionage operation attributed to Salt Typhoon, a group linked to the Chinese state and also tracked as OPERATOR PANDA, RedMike, UNC5807 and GhostEmperor. The FBI says the campaign has now reached at least 200 organisations across more than 80 countries. Its objective was to harvest call records and communications metadata tied to senior US government officials, including individuals who were presidential candidates at the time.

Confirmed victims of the wider campaign include AT&T, Verizon, Lumen, Charter Communications and Windstream. T-Mobile was first linked to the intrusions in November 2024, when the Wall Street Journal reported the carrier had been swept into the same industry-wide campaign, although the company said at the time it had no evidence customer data was significantly affected. That disclosure landed as the FBI and CISA warned publicly that the operation was targeting the lawful-intercept systems telecom providers are legally required to maintain.

The method was trust, not zero-days

The joint advisory published on 27 August 2025 by NSA, CISA, the FBI and international partners, catalogued as AA25-239A, is blunt about how this campaign achieved scale. The actors did not rely on novel undisclosed flaws. They targeted backbone, provider edge and customer edge routers that had not been patched, in some cases years after fixes were available, including the Cisco IOS XE authentication bypass tracked as CVE-2023-20198. They then modified those routers to hold long-term access and used trusted interconnections to pivot from one operator into the next.

That is the part every board should read twice. The attacker's advantage was not superior technique. It was the existence of permanent, trusted paths between networks that nobody could switch off.

Months of hunting, then a long drive

T-Mobile's security staff spent months searching for the intruders inside their own estate without success. The break came when they spotted unusual behaviour on one internal system: traffic arriving from a router belonging to another, unnamed telecom company. The path in was somebody else's network.

That gave Jeff Simon, T-Mobile's chief security officer, and three colleagues the lead they needed. Rather than run a remote remediation process across an estate the attacker could observe, they drove to a data centre near the firm's Bellevue, Washington headquarters, found the compromised hardware and cut it stone dead by pulling its power supply straight from the unit. No software command, no remote session, no dependence on a network the attacker could watch. T-Mobile has said it largely avoided the wide-scale breach that hit several of its peers, and Bloomberg reports a souvenir of the disconnection was later framed and displayed at headquarters.

Disconnection was right. The delivery was slow.

The break worked because it removed the attacker's medium. No credential reset, patch or firewall rule delivers that certainty, because each of them leaves the path in place and asks it to behave. Physical control of the connection is the only control an attacker cannot negotiate with.

But measure the response honestly. Months of undetected presence were followed by a containment action that ran on human logistics: a car journey, a security desk, a cabinet search. Every minute of that is time the attacker still holds. The lesson is not that T-Mobile acted. It is that disconnection existed only as an improvised act of last resort, not as an engineered control that could be executed the moment the decision was made.

The FBI describes the threat as ongoing. The number of confirmed victims suggests the group retains access across parts of global telecom infrastructure even where individual operators, T-Mobile among them, have managed to lock it out.

The same action, in under six milliseconds

In the time it took to get in the car, drive to the data centre, clear identity checks and find the cabinet, an engineered control could have taken the same action thousands of times over. That is the gap this story exposes: the decision was correct, but its delivery depended on a person reaching the hardware. No drive. No ID desk. No cabinet search. The action should be available the moment the decision is made.

What this means for control architecture

The lesson generalises well beyond telecoms. Wherever connectivity is the attacker's medium, the ability to disconnect on your own terms becomes a security control in its own right. Architectures that assume permanent connection hand an intruder permanent opportunity. Architectures built around deliberate, governed connection give the defender the final say.

Three design consequences follow directly from this incident:

  • Third-party paths are your paths. The route in belonged to another operator. Interconnections need the same governance as your own perimeter, with the ability to close them independently.
  • Containment must not depend on the compromised network. If severing hostile access requires the estate the attacker owns, containment is a negotiation. It should be an out-of-band action.
  • Disconnection should be engineered, not improvised. A car journey to a rack is a heroic outcome, not a repeatable one. The break needs to exist in the design before the intrusion, and it needs to act at machine speed.

Read the control blueprint

Firevault publishes the architecture behind each of these decisions. If this story is relevant to your estate, these are the blueprints to read next:

How Firevault applies these principles

At Firevault, we have developed a control blueprint that is designed to physically sever power, taking physical control of the network in under six milliseconds. This is why we talk about network evolution and rapid protection. Rather than leaving systems and data permanently reachable, Control maps an estate into zones and conduits and makes connection a decision instead of a default. Firebreak® opens and closes those paths on demand, so ending hostile access is an authorised, logged action taken out of band, designed to complete in under six milliseconds rather than a drive across town. Critical data sits in Offline Secure Storage®, reachable only through verified, logged retrieval, so a successful network intrusion finds nothing connected worth taking.

When the security team of a national carrier ends up killing a machine by pulling its power supply by hand, the argument for engineering disconnection into the architecture from the start writes itself.

Sources

  • Bloomberg, T-Mobile Cyber Staff Chopped Cable After Finding Chinese Hack, 19 August 2026
  • NSA, CISA, FBI and international partners, joint advisory AA25-239A, 27 August 2025
  • Wall Street Journal reporting on T-Mobile and the telecom intrusions, November 2024

Mark Fermor, Firevault

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Access decided by you, not assumed by the network

Control by Firevault removes standing pathways and replaces them with connection windows you approve, so stolen credentials and compromised suppliers have nothing standing to abuse.

No standing accessPaths exist only when you open them
VerificationIdentity confirmed before any connection is made
ContainmentA compromised account cannot reach what is disconnected
ControlEvery window and closure is under your command