Salt Typhoon espionage campaign hits global telecoms
Chinese state-linked hackers known as Salt Typhoon broke into telecom and internet networks worldwide starting around 2024, and the FBI says the group has hit at least 200 companies in 80 countries. Reporting through August 2026 details how T-Mobile's security team physically cut a network cable in 2024, sending staff to a Bellevue, Washington data center to sever it by hand, to cut the attackers off before they could steal customer data.
- Started
- Jan 1, 2024
- Latest activity
- Aug 27, 2025
- Attributed to
- Salt Typhoon (China state-linked)Confirmed
- Where
- United States, United Kingdom, Canada, Worldwide
- Sectors
- Telecom, Government
- Scale
- at least 200 companies across 80 countries, including major US telecom carriers
Current status
Coverage through 2026-08-20 (TechCrunch, Cybernews, Yahoo) only re-tells the same 2024 T-Mobile cable-cutting incident, adding detail that four T-Mobile security staff physically cut a cable at a Bellevue data center to expel the intruders; no new victims or fresh Salt Typhoon activity have been reported.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
The FBI and allied government agencies (UK, Canada and others) publicly attributed the campaign to the Chinese government-linked group Salt Typhoon.
Impact
Hackers gained access to telecom and internet infrastructure, including systems tied to law-enforcement wiretap requests and call records; T-Mobile said it detected and cut off the intrusion before customer data was taken.
What to do
Watch for official notices from your phone carrier if it confirms it was one of the breached companies.
Timeline
-
Aug 15, 2026
Bloomberg reporting detailed how T-Mobile stopped the 2024 intrusion, with no new confirmed victims disclosed.
Dormantcybersecuritynews.com -
Aug 27, 2025
The FBI and allied agencies said the Salt Typhoon campaign had grown to at least 200 companies across 80 countries.
Dormantsiliconangle.com -
Jan 1, 2024
T-Mobile's security team detected the intrusion and physically severed a network cable at a data center to cut off attacker access.
Containedcybersecuritynews.com -
Jan 1, 2024
Salt Typhoon hackers began breaching US telecom and internet infrastructure, according to later reporting.
Activecybersecuritynews.com
Sources
- T-Mobile physically cut network cable to stop Chinese attackers Cyber Security News Aug 15, 2026
- T-Mobile Sent Four People With Scissors to Stop Chinese Hackers - It Worked Yahoo Aug 19, 2026
- FBI and allies warn Salt Typhoon cyber campaign has targeted 200 US companies in 80 countries SiliconANGLE Aug 27, 2025
- T-Mobile security team cuts the cord in Seattle to thwart Chinese cyber intrusion Cybernews Aug 20, 2026 unverified
- Salt Typhoon Is Already Inside - Encryption Doesn't Solve the Problem Security Boulevard Aug 27, 2026 unverified
- T-Mobile 'chopped a cable' to expel Chinese hackers from its network TechCrunch Aug 19, 2026