On 19 August 2026, Bloomberg published an account from Jeff Simon, T-Mobile US’s chief information officer, of how the company evicted Salt Typhoon from its network in November 2024. Simon and three colleagues drove to a data centre in the Seattle area, located the infected hardware, and physically cut the cable connecting it. A frayed length of yellow cable is now framed at T-Mobile’s Bellevue headquarters as, in Simon’s words, a small trophy.
The story travels well because it is vivid: four people, a drive, a pair of cutters, and a state-sponsored intrusion ended in an afternoon. It has been picked up widely on that basis.
It deserves attention for a different reason. Underneath the anecdote is the decision that incident response teams find hardest and that incident response plans most often fail to address: at the moment you find the adversary, do you cut them off, or do you watch them? T-Mobile chose to cut, and chose the most irreversible form of cutting available.
That was, on the reported facts, defensible. What matters for everyone else is that the choice is a governance decision with regulatory consequences, and the time to make it is not while standing in a data centre.
The context that makes the choice hard
Salt Typhoon is the designation for a Chinese state-linked group whose campaign against telecommunications infrastructure became public in late 2024. The FBI now says it has breached at least 200 companies across 80 countries. Named victims in the telecommunications sector have included AT&T, Verizon, Lumen, Charter Communications and Windstream.
The campaign’s objective was not disruption or extortion. It was collection — phone records and communications metadata associated with senior US government officials, including individuals who were presidential candidates at the time. The technique centred on compromising routers and network infrastructure to siphon traffic.
This site has covered the legislative response to Salt Typhoon and the FCC’s subsequent rescission of its telecom cybersecurity ruling. The regulatory picture for US telecoms remains unsettled. The operational picture does not: a patient, well-resourced collection actor sitting inside network infrastructure is a category of adversary that most incident response playbooks were not written for.
Three features of that adversary shape the containment decision.
They are already deep. By the time a collection actor is detected in network hardware, they have typically established multiple footholds. Cutting one is not eviction unless you know it is the only one.
They watch your response. Sophisticated actors monitor defender activity — including through the same telemetry the defenders use. A visible remediation action can trigger the adversary to burn a foothold you had not found and re-establish elsewhere, or to destroy evidence.
The intelligence value of observation is real. Watching a collection actor operate reveals their tooling, their infrastructure, their targeting and their other footholds. That information may be the only way to achieve actual eviction rather than apparent eviction.
Against those, the case for cutting immediately is equally real: every additional hour of observation is an additional hour of collection against your customers, and for a carrier holding communications metadata on government officials, the harm accrues continuously.
Why cutting a physical cable, specifically
The detail that makes this account instructive is not that T-Mobile isolated the device. It is how.
A network-layer isolation — an ACL, a VLAN change, a firewall rule, a port shutdown pushed from a management console — has three properties that a pair of cable cutters does not:
It is mediated by the control plane. If the adversary has compromised network management infrastructure, a control-plane action may be visible to them, may be reverted by them, or may not take effect at all. When the trustworthiness of your management plane is in question, actions that depend on it are not reliable.
It is reversible. Which is usually a virtue and occasionally a liability.
It is logged. Which is a virtue in both directions — it produces an audit trail, and it produces a signal the adversary may see.
Physically severing the link removes all three considerations. It cannot be reverted remotely, cannot fail silently, and does not depend on any system whose integrity is in doubt. When the question is “can I be certain, right now, that this device is off my network”, the cable cutter is the only tool that answers it definitively.
That is a legitimate engineering judgment under conditions of control-plane uncertainty. It is also maximally destructive to the live-state evidence that a forensic investigation would want, and that is the part that carries regulatory weight.
What you lose, and who cares that you lost it
Cutting a link — or pulling power, which is the more common version of the same decision — destroys or degrades:
- Volatile memory, including in-memory implants, decryption keys, injected code and process state. Router and network-appliance implants frequently exist only in memory specifically to defeat disk forensics.
- Live network state — established sessions, ARP and routing state, and the adversary’s active connections, which reveal command-and-control infrastructure.
- Attribution and scoping evidence that would establish whether other devices are compromised.
The organisations that care about that loss are not only your own investigators.
Under the SEC cybersecurity disclosure rules, an Item 1.05 Form 8-K requires a description of the material aspects of the nature, scope and timing of the incident and its material impact or reasonably likely material impact. A registrant that destroyed the evidence needed to determine scope will find those determinations harder to make and harder to defend. This site has tracked two years of 8-K cyber disclosures; the recurring weakness in those filings is scope uncertainty, and containment choices are one of its causes.
Under NIS2 Article 23, essential and important entities owe an early warning within 24 hours, an incident notification within 72 hours including an initial assessment of severity and impact and, where available, indicators of compromise, and a final report within one month including a detailed description, the type of threat or root cause, and applied mitigations. Indicators of compromise and root cause are precisely what live-state evidence produces.
Under DORA Articles 17 to 19, financial entities face a comparable classification and reporting cascade, with root cause analysis expected in the final report.
Under HIPAA, for covered entities and business associates, the breach risk assessment at 45 CFR § 164.402 turns on the nature and extent of the PHI involved, the unauthorised person who accessed it, whether it was actually acquired or viewed, and the extent to which risk has been mitigated. Every one of those determinations is evidence-dependent. Destroy the evidence and the presumption of breach — which the rule establishes unless a low probability of compromise is demonstrated — becomes very hard to rebut.
Under CIRCIA, once the final rule’s reporting obligations are operative for covered entities, the reported content will likewise depend on investigative findings.
None of these regimes prohibit aggressive containment. All of them expect you to be able to explain the incident afterwards. The tension is structural, and it is not resolvable by choosing one side permanently.
What the plan should say
The failure mode here is not choosing wrongly in the moment. It is arriving at the moment with no framework, so that the decision defaults to whoever is most senior and most alarmed.
Name the decision and name the decision-maker. Your IR plan should contain an explicit “containment versus continued observation” decision point, with a named role — typically the incident commander, in consultation with legal and the executive sponsor — holding the call. Not a committee, and not “the CISO will decide”, which in practice means the decision is made by whoever answers the phone.
Write pre-authorised triggers for immediate containment. These are the conditions under which observation is not an option and no one needs to seek approval:
- Evidence of ongoing exfiltration of regulated data
- Evidence of active lateral movement toward crown-jewel systems
- Evidence of destructive preparation — backup deletion, shadow copy removal, encryption staging
- Safety-of-life or safety-of-service implications in OT, medical or critical-infrastructure environments
- Loss of confidence in the integrity of the management plane — the T-Mobile condition
Pre-authorising these removes the worst failure mode, which is hesitation while a decision is escalated.
Write the evidence floor that applies even to emergency containment. Before the cable is cut or the power is pulled, capture what can be captured in the time available:
- Memory image of the affected device where technically feasible, and record explicitly if it is not
- Network capture at the upstream device — which does not require touching the compromised host and is often the highest-value artefact obtainable under time pressure
- Configuration and running state exported from the device
- Photographs of physical state, cabling and device identifiers
- Contemporaneous written log of the decision: who decided, when, on what information, what alternatives were considered, and why the chosen action was necessary
That last item is the one organisations skip and regulators ask for. A contemporaneous record showing that containment was chosen deliberately, for stated reasons, with evidence-preservation measures taken to the extent time allowed, converts “you destroyed the evidence” into “you made a documented risk decision under uncertainty”. Those are very different conversations.
Prefer upstream containment where it is available. Isolating at the upstream device — the switch or router one hop toward the core — often achieves the same containment while leaving the compromised host’s volatile state intact for imaging. This is the option that is frequently forgotten because the instinct is to act on the affected device. Where the management plane is trustworthy, upstream isolation is usually the better trade.
Rehearse it. A tabletop exercise in which the injects force the team to choose between eviction and observation, under time pressure, with incomplete information, is worth more than a rewritten policy document. Most tabletops never present this choice because the facilitator assumes containment is obviously correct.
Decide who else you call. In a suspected nation-state intrusion in critical infrastructure, the calculus changes. CISA and, for telecommunications, sector-specific channels may have visibility into the campaign that materially affects whether observation is worthwhile — and may ask you to preserve access for a period. That is a decision your executives should be prepared to make, and the relationships should exist before the incident.
The part that generalises
T-Mobile’s response, on the reported facts, worked. The company detected an intrusion that many peers did not detect for longer, made a decisive call under management-plane uncertainty, and acted on it within hours. Framing the cable is a reasonable way to mark that.
The lesson generalises less neatly than the anecdote does. The right answer was not “cut the cable” — the right answer was “cut the cable given that we could not trust the control plane, given that a collection actor was actively taking customer metadata, and given that we accepted the forensic cost.” Every clause in that sentence is a judgment, and each one could reasonably come out differently in another organisation’s incident.
What every organisation can copy is the preparation: a named decision-maker, pre-authorised triggers, an evidence floor that survives even emergency action, and a contemporaneous written record of why.
The cable in the frame is a good story. The decision record that should sit beside it is the artefact regulators will ask for.
This article is provided for informational purposes only and does not constitute legal advice.



