T-Mobile security chief insists its defenses stood up to attacks linked to Salt Typhoon
No T-Mobile customers or services were affected after its security teams detected suspicious activity on their routers
T-Mobile was able to protect sensitive customer information and prevent disruption to its services after detecting malicious attempts to infiltrate its systems, according to its security chief.
Jeff Simon, chief security officer at T-Mobile, published an update on a string of recent cyber attacks targeting wireless companies, believed to be orchestrated by the Salt Typhoon group.
The update states that the attacks originated from the network one of T-Mobile’s wireline providers it was connected to, but Simon said connectivity to the provider’s network, which may still be compromised, was quickly severed.
Simon noted that unlike other providers, and despite media reporting, T-Mobile’s customer information was not impacted.
“Many reports claim these bad actors have gained access to some providers’ customer information over an extended period of time – phone calls, text messages, and other sensitive information, particularly from government officials. This is not the case at T-Mobile,” he wrote.
“Our defenses protected our sensitive customer information, prevented any disruption of our services, and stopped the attack from advancing. Bad actors had no access to sensitive customer data (including calls, voicemails or texts).”
Speaking to Bloomberg, Simon said T-Mobile’s network engineers discovered the attack after noticing suspicious behavior on some of the company’s network devices.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
The behavior wasn’t “inherently malicious” but may have been used to gain a clearer understanding of the company's corporate network, with threat actors probing for potential lateral movement opportunities.
Simon stated that T-Mobile’s layered network design, featuring network segmentation and robust monitoring, partnerships with third-party cyber experts, and its swift response all helped to prevent the attackers from causing further damage.
Salt Typhoon is on a rampage
Although T-Mobile were unable to “definitively identify” the attacker’s identity, the behavior is consistent with previous attacks leveraged by the Salt Typhoon group.
Trend Micro published a report on 25 November detailing previous activity of Salt Typhoon, also known as Earth Estries, Ghost Emperor, or UNC2286).
The report stated the group has primarily targeted critical sectors such as telecommunications and government entities across the US, Asia, Middle East, and South Africa since 2023 and potentially even earlier.
“The group employs advanced attack techniques and multiple backdoors, such as GHOSTSPIDER, SNAPPYBEE, and MASOL RAT, affecting several Southeast Asian telecommunications companies and government entities,” Trend Micro outlined.
RELATED WHITEPAPER
“Earth Estries exploits public-facing server vulnerabilities to establish initial access and uses living-off-the-land binaries for lateral movement within networks to deploy malware and conduct long-term espionage.”
According to the report, the group has compromised over 20 organizations in the telecommunications, technology, consulting, chemical, and transportation industries, as well as government agencies.
Reports of Salt Typhoon infiltrating internet service providers (ISPs) in the US came out in September 2024, with the Wall Street Journal confirming in October that major players Verizon Communications, AT&T, and Lumen Technologies were among a list of companies whose networks were breached.
Unnamed sources familiar with the matter told theWSJ that the access may have allowed the group to access information from systems the federal government uses for court-authorized wiretapping, describing the compromise as "potentially catastrophic”.
T-Mobile appears to have avoided the worst impacts of Salt Typhoon’s campaign, according to Simon, who added that he had recently attended a meeting of leaders at the White House to discuss how the industry can work together to mitigate the threats the group pose and avoid further damage.

Solomon Klappholz is a former staff writer for ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing, which led to him developing a particular interest in cybersecurity, IT regulation, industrial infrastructure applications, and machine learning.
-
The EU is charting a course to digital independence with the technological sovereignty packageNews New legislation looks to shore up digital sovereignty and reduce reliance on foreign tech
-
Anthropic warns AI is helping lower the bar for up-and-coming hackersNews AI is making it harder to differentiate between high and low-skilled actors
-
Hackers are turning up at law firms to gain physical access to machinesNews The FBI is warning companies to look out for fake IT staff
-
UK wants an AI-powered anti-hacking systemNews GCHQ is building a national cyber defence capability powered by AI – though it may take five years
-
GitHub internal repositories exfiltrated via malicious VS Code extensionNews The breach has been claimed by the TeamPCP hacking group, which said it is offering the data for sale
-
UK government calls on firms to sign Cyber Resilience Pledge as security sector boomsNews With new figures showing a boom in the country's cybersecurity sector, the government calling on businesses to make the most of the industry’s expertise
-
‘We’re not investing as much as we should in their skills and development’: Skills shortages remain a key factor in security breaches — and things could get worse with AI in the equationNews Skills capabilities remain a key factor in security breaches, according to a new study
-
Pay up or expect attrition: 77% of cyber professionals missed out on pay rises last year – and almost half now plan to switch rolesNews Organizations are overlooking cyber pros when it comes to pay increases, and it could cost them dearly
-
The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in lifeNews With family responsibilities and mortgages to pay, it's not teenagers dishing out malware or carrying out cyber extortion