Skip to main content
Telecom SecurityInvestigationAug 12, 2026, 2:24 PM· 3 min read· #2 of 2 in defense security

Probe Finds Chinese Telecoms Retained Footholds in US Critical Infrastructure Despite Crackdowns

A bipartisan congressional investigation reveals that three Chinese state-owned telecommunications companies maintained equipment and network ties in the U.S. years after federal regulators revoked their operating licenses.

By Anastasia Kuznetsova

Congressional Oversight 40%Cybersecurity & Defense 40%State & Local Infrastructure 20%
Congressional Oversight
Focuses on closing regulatory loopholes and removing foreign state-controlled infrastructure from U.S. networks.
Cybersecurity & Defense
Analyzes the technical risks of BGP hijacking and the overlap between telecom infrastructure and state-sponsored hacking campaigns.
State & Local Infrastructure
Highlights the downstream impact of compromised core networks on regional utilities and enterprise systems.

Why it matters

The continued presence of Chinese state-owned telecom equipment in U.S. data centers creates a regulatory blind spot that could allow foreign intelligence to monitor sensitive domestic internet traffic and sustain cyberespionage campaigns against American critical infrastructure.

For American businesses and consumers relying on secure domestic internet traffic, the assumption has long been that federal bans effectively removed Chinese state-owned telecommunications companies from U.S. infrastructure. A new bipartisan congressional investigation, however, reveals that this regulatory firewall was largely administrative, leaving physical hardware and network connections deeply embedded within the U.S. internet ecosystem.[1][6]

The House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party released a 49-page report detailing how China Mobile, China Telecom, and China Unicom retained significant footholds in American data centers. Titled "Stranger Pings," the investigation found that despite having their operating authorities revoked by the Federal Communications Commission (FCC) between 2019 and 2022, the companies maintained installed routers, server racks, power adapters, and cross-connecting equipment inside U.S. facilities.[2][4][6]

The investigation exposes a critical gap in federal enforcement mechanisms. While the FCC's revocation of Section 214 licenses successfully barred the firms from providing specific commercial telecommunications services, the agency lacked the statutory authority to mandate the physical extraction of existing hardware or the termination of private network leasing agreements.[1][4]

The FCC's revocation of operating licenses barred commercial service sales but did not mandate the removal of physical hardware.
The FCC's revocation of operating licenses barred commercial service sales but did not mandate the removal of physical hardware.

Consequently, the banned carriers pivoted toward less-regulated private networks, continuing to offer enterprise networking and internet transit services. By renting physical space within secure U.S. data centers, these companies preserved direct access to core network infrastructure, allowing them to route data between the United States, China, and Hong Kong.[1][2]

Consequently, the banned carriers pivoted toward less-regulated private networks, continuing to offer enterprise networking and internet transit services.

This persistent physical presence presents tangible security vulnerabilities. The committee's analysis of internet routing data found that China Mobile International's network appeared in routes to servers utilized by "Salt Typhoon"—a Chinese state-sponsored cyberespionage group—at least 192 times over a three-day period in late 2024.[1][3]

While investigators did not allege that telecom employees actively facilitated the Salt Typhoon campaign, the network overlap illustrates how residual infrastructure can inadvertently sustain malicious cyber operations. The retained connections provide potential vectors for foreign intelligence services to monitor sensitive traffic, hijack Border Gateway Protocol (BGP) routes, and maintain dormant access to U.S. systems. The report identified over 108,000 incidents of alleged BGP hijacks involving Chinese or Hong Kong-linked networks between 2018 and 2025.[2][3][5]

Investigators identified over 108,000 incidents of anomalous internet routing activity involving Chinese or Hong Kong-linked networks.
Investigators identified over 108,000 incidents of anomalous internet routing activity involving Chinese or Hong Kong-linked networks.

Furthermore, the investigation highlighted that the U.S. subsidiaries of these telecom giants are not genuinely independent from their parent companies in mainland China and Hong Kong. This lack of independence raises concerns that the companies could be compelled to assist in state intelligence work under China's 2017 National Intelligence Law.[1][4][6]

Addressing this vulnerability requires a shift from administrative licensing bans to physical infrastructure audits. The committee is recommending that Congress grant federal agencies expanded statutory authority to identify, constrain, and physically remove foreign state-controlled network equipment from domestic data centers, closing the loophole that allowed these firms to operate in the shadows of the U.S. communications backbone.[3][6]

What to know

  • A House investigation found that China Mobile, China Telecom, and China Unicom retained physical equipment in U.S. data centers despite FCC bans.
  • The FCC's revocation of operating licenses blocked commercial service sales but did not require the removal of hardware or private network links.
  • China Mobile International's network appeared in routing data to servers used by the 'Salt Typhoon' cyberespionage group 192 times over three days.
  • Investigators identified over 108,000 incidents of anomalous internet routing activity involving Chinese or Hong Kong-linked networks since 2018.
  • Lawmakers are recommending new statutory authority to force the physical removal of foreign state-controlled network equipment.

Where opinion splits

Congressional Investigators

Lawmakers argue that the retained infrastructure poses an unacceptable national security risk.

The House Select Committee emphasizes that administrative bans are insufficient if foreign state-owned entities maintain physical access to the U.S. communications backbone. They argue that these dormant footholds create a regulatory blind spot, allowing companies beholden to the Chinese Communist Party to potentially reroute domestic traffic, monitor sensitive data, and sustain malicious cyber infrastructure like the servers used in the Salt Typhoon campaign. The committee is pushing for new legislation to force the physical removal of this equipment.

Cybersecurity Analysts

Security experts highlight the technical mechanisms of how dormant infrastructure can be exploited.

Threat intelligence researchers point out that physical presence in a data center, combined with active peering agreements, allows for sophisticated attacks such as Border Gateway Protocol (BGP) hijacking. By manipulating routing tables, adversaries can silently divert U.S. internet traffic through foreign servers before it reaches its destination. Analysts warn that even if the telecom companies are not actively participating in espionage, their infrastructure provides a convenient, pre-established pathway for state-sponsored hacking groups to blend into normal network traffic.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

Congressional Oversight 40%Cybersecurity & Defense 40%State & Local Infrastructure 20%
  1. [1]Nextgov/FCWCongressional Oversight

    Banned Chinese Telecoms Retained US Network Ties, House Probe Finds

    Read on Nextgov/FCW
  2. [2]Foundation for Defense of DemocraciesCybersecurity & Defense

    New Congressional Investigation Alleges Banned Chinese Firms Never Left Domestic Networks

    Read on Foundation for Defense of Democracies
  3. [3]SC MediaCybersecurity & Defense

    Chinese telecom companies retain US network ties despite security concerns

    Read on SC Media
  4. [4]Industrial CyberCybersecurity & Defense

    Congressional report warns Chinese telecoms remain embedded in US networks despite FCC restrictions

    Read on Industrial Cyber
  5. [5]Route FiftyState & Local Infrastructure

    Banned Chinese telecoms retained US network ties, House probe finds

    Read on Route Fifty
  6. [6]House Select Committee on the CCPCongressional Oversight

    Stranger Pings: The Threat of CCP-Controlled Infrastructure in the U.S. Communications Backbone

    Read on House Select Committee on the CCP

Comments

Stay informed

Every angle. Every day.

Get defense security stories with full source coverage and perspective breakdowns delivered to your inbox.