T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network
T-Mobile “剪断电缆”以清除网络中的中国黑客
New reporting from Bloomberg revealed how cybersecurity staff at U.S. phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide intrusions by Beijing aimed at stealing customer data. 彭博社的最新报道揭露了美国电信运营商 T-Mobile 的网络安全团队如何在 2024 年识别并清除了潜入其网络的中国黑客。当时,北京方面正针对整个行业发起一系列入侵行动,旨在窃取客户数据。
The hacks were carried out by a Chinese government-backed hacking group called Salt Typhoon. The campaign compromised hundreds of phone companies, internet giants, and data center providers with the goal of collecting phone records and information about senior U.S. government officials, including then-presidential candidates. 这些黑客攻击是由一个名为“盐台风”(Salt Typhoon)的中国政府支持的黑客组织实施的。该行动波及了数百家电信公司、互联网巨头和数据中心提供商,其目标是收集通话记录以及美国政府高级官员(包括当时的总统候选人)的相关信息。
Hacked companies included AT&T, Verizon, satellite phone network Viasat, and network infrastructure giants Charter and Windstream. 受攻击的公司包括 AT&T、Verizon、卫星电话网络 Viasat,以及网络基础设施巨头 Charter 和 Windstream。
By and large, T-Mobile escaped a widescale breach of its network by catching the activity early — and resorted to physically cutting the cable to a compromised system, per Bloomberg. 据彭博社报道,T-Mobile 通过及早发现异常活动,在很大程度上避免了网络遭受大规模入侵,并采取了物理切断受感染系统电缆的极端手段。
The publication said T-Mobile’s cyber staff spent months looking for suspected hackers in its network without success. Eventually, the company found unusual behavior on one of its systems coming from another router belonging to a different telecom company, which T-Mobile did not name. 该报道称,T-Mobile 的网络安全人员曾花费数月时间在网络中搜寻疑似黑客,但一无所获。最终,公司发现其某个系统出现了异常行为,而这些流量来自另一家电信公司(T-Mobile 未透露具体名称)的路由器。
After identifying the breach, T-Mobile’s cybersecurity chief, Jeff Simon, told Bloomberg that he and three others drove to the data center nearby to its Bellevue, Washington headquarters, found the compromised system, pulled out a set of scissors, and snipped the cable connecting the box to the outside world. 在确认入侵后,T-Mobile 网络安全主管 Jeff Simon 向彭博社透露,他与另外三名同事驱车前往位于华盛顿州贝尔维尤总部附近的数据中心,找到了受感染的系统,随后掏出一把剪刀,剪断了连接该设备与外部网络的电缆。
When reached by TechCrunch, T-Mobile did not provide comment. 当 TechCrunch 联系 T-Mobile 时,该公司未予置评。