Chinesische Hacker drangen in die Router von T-Mobile ein, um das Netz zu erkunden

Teilen:

T-Mobile says the Chinese “Salt Typhoon” hackers who recently compromised its systems as part of a series of telecom breaches first hacked into some of its routers to explore ways to navigate laterally through the network.

However, the company says its engineers blocked the threat actors before they could spread further on the network and access customer information.

Also tracked as Earth Estries, FamousSparrow, Ghost Emperor, and UNC2286, this Chinese state-sponsored threat group has been active since at least 2019 and typically focuses on breaching government entities and telecommunications companies in Southeast Asia.

Jeff Simon, the company’s Chief Security Officer, shared in a blog post published on Wednesday that the threat actors’ attack—originating from a connected wireline provider’s network—was stopped by T-Mobile’s cyber defenses, including proactive monitoring and network segmentation.

The company discovered the breach after detecting suspicious behavior, including commands usually used in the reconnaissance stage of cyberattacks being run on some of its routers and commands matching indicators of compromise previously linked to Salt Typhoon, as Simon told Bloomberg.

“Many reports claim these bad actors have gained access to some providers’ customer information over an extended period of time – phone calls, text messages, and other sensitive information, particularly from government officials. This is not the case at T-Mobil,” Simon said.

“Our defenses protected our sensitive customer information, prevented any disruption of our services, and stopped the attack from advancing. Bad actors had no access to sensitive customer data (including calls, voicemails, or texts).

“We quickly severed connectivity to the provider’s network as we believe it was – and may still be – compromised.”

T-Mobile’s CSO added that the company no longer sees any attackers active within its network and has shared its findings with the government and industry partners.

Breached in recent Salt Typhoon telecom attacks

T-Mobile’s statement from today follows the company’s announcement two weeks ago that its systems were compromised in a recent wave of Salt Typhoon telecom breaches.

CISA and the FBI confirmed the breaches in late October following reports that the Chinese threat group breached multiple broadband providers, including AT&T, Verizon, and Lumen Technologies.

The two federal agencies later revealed that the attackers compromised the “private communications” of a “limited number” of government officials, stole customer call records and law enforcement request data, and gained access to the U.S. government’s wiretapping platform.

Even though it’s unknown when the telecom giants’ networks were first breached, the Chinese hackers had access “for months or longer,” according to a WSJ report. This allowed them to collect and steal vast amounts of “internet traffic from internet service providers that count businesses large and small, and millions of Americans, as their customers,” according to people familiar with the matter.

Canada also revealed last month that many of the country’s agencies and departments, including federal political parties, the Senate, and the House of Commons, were targeted in broad network scans linked to unnamed Chinese state hackers.

In similar, although likely unrelated attacks, the Volt Typhoon Chinese threat group tracked and hacked multiple ISPs and MSPs in the United States and India after hacking their corporate networks using credentials stolen by in Versa Director zero-day attacks.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:32 am, Juli 11, 2025
Wetter-Symbol 17°C
L: 16° | H: 18°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 82 %
Druck: 1021 mb
Wind: 5 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 39%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 9:15 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
16° | 18°°C 0 mm 0% 8 mph 82 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
So. Juli 13 10:00 pm
Wetter-Symbol
18° | 30°°C 0 mm 0% 7 mph 71 % 1015 mb 0 mm/h
Mo. Juli 14 10:00 pm
Wetter-Symbol
18° | 28°°C 1 mm 100% 15 mph 84 % 1016 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
14° | 20°°C 1 mm 100% 14 mph 81 % 1017 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
17° | 18°°C 0 mm 0% 2 mph 82 % 1021 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
20° | 26°°C 0 mm 0% 2 mph 72 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
26° | 30°°C 0 mm 0% 3 mph 48 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 4 mph 26 % 1018 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 6 mph 29 % 1017 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 8 mph 49 % 1019 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 5 mph 57 % 1019 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 5 mph 66 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€99,635.01
4.97%
Ethereum(ETH)
€2,532.91
6.98%
Fesseln(USDT)
€0.85
-0.01%
XRP(XRP)
€2.19
5.97%
Solana(SOL)
€140.57
4.66%
USDC(USDC)
€0.85
0.01%
Dogecoin(DOGE)
€0.169162
9.98%
Shiba Inu(SHIB)
€0.000011
8.29%
Pepe(PEPE)
€0.000011
15.39%
Peanut das Eichhörnchen(PNUT)
€0.247151
22.02%
Nach oben scrollen