T-Mobile named in Salt Typhoon espionage campaign against US telecoms

Organization
T-Mobile US
Exploit
Hacking
Industry
Telecommunications

On November 15, 2024, The Wall Street Journal reported that T-Mobile was among the carriers caught up in a long-running cyber-espionage campaign attributed to Salt Typhoon, a group linked to the Chinese state and also tracked under names including Earth Estries and UNC2286. AT&T, Verizon and Lumen Technologies were identified as targets in the same campaign, alongside telecom operators outside the United States.

At other carriers the operation reached call detail records, unencrypted text messages and, for a small set of high-value targets, audio from calls, as well as systems used to service US law enforcement wiretap requests. Reporting described an intrusion that had run for months and involved compromise of network infrastructure, including Cisco routers. Among those reportedly targeted were senior US political figures and officials working on national security.

T-Mobile disputed the scope of the intrusion from the outset, saying it had identified no significant impact to its systems and no evidence that customer information had been affected. In a follow-up on November 27, the carrier said its engineers had spotted unauthorized commands being run on network devices, traced the activity to a compromised wireline provider it connected to, severed that connectivity and used network segmentation to eject the intruders before they moved deeper or reached customer data.

T-Mobile said it had shared its findings with the US government. According to The Record, federal law enforcement agencies had been warning for months about how deeply Salt Typhoon had penetrated telecom networks, and investigations into the campaign continued.

Sources