Dormant High impact Espionage Checked 1w ago

Salt Typhoon espionage campaign hits global telecoms

Chinese state-linked hackers known as Salt Typhoon broke into telecom and internet networks worldwide starting around 2024, and the FBI says the group has hit at least 200 companies in 80 countries. Reporting through August 2026 details how T-Mobile's security team physically cut a network cable in 2024, sending staff to a Bellevue, Washington data center to sever it by hand, to cut the attackers off before they could steal customer data.

Started
Jan 1, 2024
Latest activity
Aug 27, 2025
Attributed to
Salt Typhoon (China state-linked)Confirmed
Where
United States, United Kingdom, Canada, Worldwide
Sectors
Telecom, Government
Scale
at least 200 companies across 80 countries, including major US telecom carriers

Current status

Coverage through 2026-08-20 (TechCrunch, Cybernews, Yahoo) only re-tells the same 2024 T-Mobile cable-cutting incident, adding detail that four T-Mobile security staff physically cut a cable at a Bellevue data center to expel the intruders; no new victims or fresh Salt Typhoon activity have been reported.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

The FBI and allied government agencies (UK, Canada and others) publicly attributed the campaign to the Chinese government-linked group Salt Typhoon.

Impact

Hackers gained access to telecom and internet infrastructure, including systems tied to law-enforcement wiretap requests and call records; T-Mobile said it detected and cut off the intrusion before customer data was taken.

What to do

Watch for official notices from your phone carrier if it confirms it was one of the breached companies.

Timeline

  1. Aug 15, 2026

    Bloomberg reporting detailed how T-Mobile stopped the 2024 intrusion, with no new confirmed victims disclosed.

    Dormantcybersecuritynews.com
  2. Aug 27, 2025

    The FBI and allied agencies said the Salt Typhoon campaign had grown to at least 200 companies across 80 countries.

    Dormantsiliconangle.com
  3. Jan 1, 2024

    T-Mobile's security team detected the intrusion and physically severed a network cable at a data center to cut off attacker access.

    Containedcybersecuritynews.com
  4. Jan 1, 2024

    Salt Typhoon hackers began breaching US telecom and internet infrastructure, according to later reporting.

    Activecybersecuritynews.com

Sources

Related reports