---
title: "T-Mobile pulled the plug on Salt Typhoon. It to… | Firevault"
description: "T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026#webpage",
      "url": "https://fire-vault.com/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026",
      "name": "T-Mobile pulled the plug on Salt Typhoon. It to…",
      "description": "T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.",
          "item": "https://fire-vault.com/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.",
      "description": "T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.",
      "url": "https://fire-vault.com/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-08-27T07:00:00+00:00",
      "dateModified": "2026-08-28T16:10:49.007537+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Insight",
      "wordCount": 1308,
      "keywords": "T-Mobile, Insight, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "## What happened Cyber security staff at US phone provider T-Mobile identified and expelled Chinese state-backed hackers from its network in 2024, an event now detailed in a Bloomberg report published in August 2026. Faced with an intrusion they could not remove by software means, the team fell back on the one control that could not be argued with: physical disconnection. But here is what the cove",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What happenedAn industry-wide campaignThe method was trust, not zero-daysMonths of hunting, then a long d…Disconnection was right. The del…The same action, in under six mi…What this means for control arch…Read the control blueprintHow Firevault applies these prin…More Resources

[Knowledge Vault](/learn/knowledge)/ [Insight](/learn/knowledge?filter=insight)

Insight · 27 August 2026 

# T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

7 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftmobile-severs-network-cable-salt-typhoon-hackers-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftmobile-severs-network-cable-salt-typhoon-hackers-2026&text=T-Mobile%20pulled%20the%20plug%20on%20Salt%20Typhoon.%20It%20took%20a%20car%20journey%20to%20get%20there.%0A%0AT-Mobile's%20security%20chief%20ended%20months%20of%20failed%20software%20remediation%20by%20driving%20to%20the%20data%20centre%2C%20clearing%20ID%2C%20finding%20the%20cabinet%20and%20physically%20pulling%20the%20power%20supply%20from%20the%20compromised%20hardware.%20Disconnection%20was%20the%20right%20control.%20Firevault%20Control%20is%20designed%20to%20take%20the%20same%20action%20in%20under%20six%20milliseconds.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftmobile-severs-network-cable-salt-typhoon-hackers-2026)[](mailto:?subject=T-Mobile%20pulled%20the%20plug%20on%20Salt%20Typhoon.%20It%20took%20a%20car%20journey%20to%20get%20there.&body=T-Mobile's%20security%20chief%20ended%20months%20of%20failed%20software%20remediation%20by%20driving%20to%20the%20data%20centre%2C%20clearing%20ID%2C%20finding%20the%20cabinet%20and%20physically%20pulling%20the%20power%20supply%20from%20the%20compromised%20hardware.%20Disconnection%20was%20the%20right%20control.%20Firevault%20Control%20is%20designed%20to%20take%20the%20same%20action%20in%20under%20six%20milliseconds.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Ftmobile-severs-network-cable-salt-typhoon-hackers-2026)

![A gloved hand physically pulling the power supply from a rack-mounted server inside a dark telecom data centre](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

A gloved hand physically pulling the power supply from a rack-mounted server inside a dark telecom data centre

Why it matters

## What this means for organisations holding critical data

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [An industry-wide campaign](#section-1)
3.  03 [The method was trust, not zero-days](#section-2)
4.  04 [Months of hunting, then a long d…](#section-3)
5.  05 [Disconnection was right. The del…](#section-4)
6.  06 [The same action, in under six mi…](#section-5)

**On this page**[What happened](#section-0)[An industry-wide campaign](#section-1)[The method was trust, not zero-days](#section-2)[Months of hunting, then a long d…](#section-3)[Disconnection was right. The del…](#section-4)[The same action, in under six mi…](#section-5)[What this means for control arch…](#section-6)[Read the control blueprint](#section-7)

## What happened

Cyber security staff at US phone provider T-Mobile identified and expelled Chinese state-backed hackers from its network in 2024, an event now detailed in a Bloomberg report published in August 2026. Faced with an intrusion they could not remove by software means, the team fell back on the one control that could not be argued with: physical disconnection.

But here is what the coverage glosses over. Nobody flipped a switch. The decision to disconnect still had to be delivered by hand: get in the car, drive to the data centre, pass the identity checks, find the cabinet, identify the hardware and physically pull the power supply from the compromised unit. The machine died in their hands. It was the same improvised move Co-op made when it unplugged systems to stop its attackers. The right control, delivered at car-journey speed.

## An industry-wide campaign

The intrusion formed part of a sprawling espionage operation attributed to Salt Typhoon, a group linked to the Chinese state and also tracked as OPERATOR PANDA, RedMike, UNC5807 and GhostEmperor. The FBI says the campaign has now reached at least 200 organisations across more than 80 countries. Its objective was to harvest call records and communications metadata tied to senior US government officials, including individuals who were presidential candidates at the time.

Confirmed victims of the wider campaign include AT&T, Verizon, Lumen, Charter Communications and Windstream. T-Mobile was first linked to the intrusions in November 2024, when the Wall Street Journal reported the carrier had been swept into the same industry-wide campaign, although the company said at the time it had no evidence customer data was significantly affected. That disclosure landed as the FBI and CISA warned publicly that the operation was targeting the lawful-intercept systems telecom providers are legally required to maintain.

## The method was trust, not zero-days

The joint advisory published on 27 August 2025 by NSA, CISA, the FBI and international partners, catalogued as [AA25-239A](https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a), is blunt about how this campaign achieved scale. The actors did not rely on novel undisclosed flaws. They targeted backbone, provider edge and customer edge routers that had not been patched, in some cases years after fixes were available, including the Cisco IOS XE authentication bypass tracked as CVE-2023-20198. They then modified those routers to hold long-term access and used trusted interconnections to pivot from one operator into the next.

That is the part every board should read twice. The attacker's advantage was not superior technique. It was the existence of permanent, trusted paths between networks that nobody could switch off.

## Months of hunting, then a long drive

T-Mobile's security staff spent months searching for the intruders inside their own estate without success. The break came when they spotted unusual behaviour on one internal system: traffic arriving from a router belonging to another, unnamed telecom company. The path in was somebody else's network.

That gave Jeff Simon, T-Mobile's chief security officer, and three colleagues the lead they needed. Rather than run a remote remediation process across an estate the attacker could observe, they drove to a data centre near the firm's Bellevue, Washington headquarters, found the compromised hardware and cut it stone dead by pulling its power supply straight from the unit. No software command, no remote session, no dependence on a network the attacker could watch. T-Mobile has said it largely avoided the wide-scale breach that hit several of its peers, and Bloomberg reports a souvenir of the disconnection was later framed and displayed at headquarters.

## Disconnection was right. The delivery was slow.

The break worked because it removed the attacker's medium. No credential reset, patch or firewall rule delivers that certainty, because each of them leaves the path in place and asks it to behave. Physical control of the connection is the only control an attacker cannot negotiate with.

But measure the response honestly. Months of undetected presence were followed by a containment action that ran on human logistics: a car journey, a security desk, a cabinet search. Every minute of that is time the attacker still holds. The lesson is not that T-Mobile acted. It is that disconnection existed only as an improvised act of last resort, not as an engineered control that could be executed the moment the decision was made.

The FBI describes the threat as ongoing. The number of confirmed victims suggests the group retains access across parts of global telecom infrastructure even where individual operators, T-Mobile among them, have managed to lock it out.

## The same action, in under six milliseconds

In the time it took to get in the car, drive to the data centre, clear identity checks and find the cabinet, an engineered control could have taken the same action thousands of times over. That is the gap this story exposes: the decision was correct, but its delivery depended on a person reaching the hardware. No drive. No ID desk. No cabinet search. The action should be available the moment the decision is made.

## What this means for control architecture

The lesson generalises well beyond telecoms. Wherever connectivity is the attacker's medium, the ability to disconnect on your own terms becomes a security control in its own right. Architectures that assume permanent connection hand an intruder permanent opportunity. Architectures built around deliberate, governed connection give the defender the final say.

Three design consequences follow directly from this incident:

-   **Third-party paths are your paths.** The route in belonged to another operator. Interconnections need the same governance as your own perimeter, with the ability to close them independently.
-   **Containment must not depend on the compromised network.** If severing hostile access requires the estate the attacker owns, containment is a negotiation. It should be an out-of-band action.
-   **Disconnection should be engineered, not improvised.** A car journey to a rack is a heroic outcome, not a repeatable one. The break needs to exist in the design before the intrusion, and it needs to act at machine speed.

## Read the control blueprint

Firevault publishes the architecture behind each of these decisions. If this story is relevant to your estate, these are the blueprints to read next:

-   **[CP-02: Contain Active Breaches](/control-blueprints/cp-02)** — severing the hostile route during a live incident, without relying on the compromised network.
-   **[CP-03: Control Third-Party Access](/control-blueprints/cp-03)** — vendor and partner paths that exist only on demand, which is precisely the gap Salt Typhoon exploited between carriers.
-   **[CP-04: Enforce Physical Segmentation](/control-blueprints/cp-04)** — zones and conduits that hold under pressure, so disconnection is a governed action rather than a rack visit.
-   **[CP-05: Protect Critical Infrastructure](/control-blueprints/cp-05)** — national-grade path governance for operators carrying essential services.

## How Firevault applies these principles

At Firevault, we have developed a control blueprint that is designed to physically sever power, taking physical control of the network in under six milliseconds. This is why we talk about network evolution and rapid protection. Rather than leaving systems and data permanently reachable, Control maps an estate into zones and conduits and makes connection a decision instead of a default. Firebreak® opens and closes those paths on demand, so ending hostile access is an authorised, logged action taken out of band, designed to complete in under six milliseconds rather than a drive across town. Critical data sits in [Offline Secure Storage](/offline-secure-storage)®, reachable only through verified, logged retrieval, so a successful network intrusion finds nothing connected worth taking.

When the security team of a national carrier ends up killing a machine by pulling its power supply by hand, the argument for engineering disconnection into the architecture from the start writes itself.

### Sources

-   Bloomberg, _T-Mobile Cyber Staff Chopped Cable After Finding Chinese Hack_, 19 August 2026
-   NSA, CISA, FBI and international partners, joint advisory [AA25-239A](https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a), 27 August 2025
-   Wall Street Journal reporting on T-Mobile and the telecom intrusions, November 2024

_Mark Fermor, Firevault_

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Access decided by you, not assumed by the network

Control by Firevault removes standing pathways and replaces them with connection windows you approve, so stolen credentials and compromised suppliers have nothing standing to abuse.

[Get started](/get-started)[Talk to the team](/demo)

**No standing access**Paths exist only when you open them 

**Verification**Identity confirmed before any connection is made 

**Containment**A compromised account cannot reach what is disconnected 

**Control**Every window and closure is under your command 

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg)

Insight 

### Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen

People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

26 Aug 2026 3 min 







](/news/beacon-charity-database-breach-hiv-charity-health-data-2026)[

![Iran-linked hackers shut down a UK power plant for four days](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-uk-power-plant-cyber-attack-2026.jpg)

Insight 

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min 







](/news/iran-linked-hackers-uk-power-plant-shutdown-2026)[

![GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gta6-leaks-rockstar-2026.jpg)

Insight 

### GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?

Unreleased Grand Theft Auto 6 footage has appeared online ahead of Rockstar's official preview, and Take-Two is now in court seeking the identities behind the accounts sharing it. The game will still sell. The material that leaked can never be unseen.

22 Aug 2026 3 min 







](/news/gta-6-leaks-rockstar-development-footage-2026)[

![Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/nine-pbs-archives-cloud-vendor-shutdown-2026.jpg)

Insight 

### Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed

A public broadcaster lost access to fifty terabytes of archival footage, spanning seventy years of regional history, when its cloud storage supplier suddenly went out of business. The files are still trapped in a Denver data centre.

18 Aug 2026 4 min 







](/news/nine-pbs-archives-cloud-vendor-shutdown-2026)[

![French tax authority breach exposes 678,000 taxpayers and the land registry behind them](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/french-tax-authority-dgfip-data-breach-2026.jpg)

Insight 

### French tax authority breach exposes 678,000 taxpayers and the land registry behind them

France's Directorate General of Public Finances has confirmed that attackers used compromised access points to extract tax and cadastral data on 678,000 individuals and businesses. The same seller claims to have held a live session on the central land registry platform covering roughly 20 million people.

17 Aug 2026 3 min 







](/news/french-tax-authority-dgfip-data-breach-678000-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)