A bipartisan House panel delivered a stark conclusion this week: three giant Chinese state-owned telecoms have not left the American internet, even after they were officially kicked out.

Chinese Telcos Still Run U.S. Network Backdoors, Report Warns
XOOMAR Intelligence
Analyst Take
On August 4, the House Select Committee on China published a 49-page investigation detailing the deep, persistent presence of China Mobile, China Unicom, and China Telecom within U.S. critical infrastructure. This comes in the direct wake of the Salt Typhoon hacking campaign, which according to The Record compromised at least nine major U.S. telecom firms. The report argues that despite decisive regulatory action years ago, these companies operate "trusted backdoors" into domestic networks that Beijing could weaponize for espionage or disruption.
The Aftermath of the FCC Crackdown That Wasn't
Between 2019 and 2022, the Federal Communications Commission moved decisively. It revoked or denied the Section 214 telecommunications licenses for the U.S. subsidiaries of China Telecom, China Mobile, and China Unicom, barring them from providing international voice and data services. U.S. officials cited profound national security risks, pointing to China's 2017 National Intelligence Law that compels companies to assist state security work.
The committee's new report confirms a critical loophole, however. The FCC's actions only limited what the companies could sell, not what they could own or operate. The carriers were not forced to remove installed hardware, vacate rented data center space, or sever their private interconnection agreements with major U.S. network operators. As a result, China's state-owned carriers, in the committee's words, "remained deeply embedded in the U.S. internet ecosystem long after federal regulators had already found them vulnerable to CCP exploitation."
The result was a strategic pivot by the telcos. They rebuilt their U.S. businesses around less-regulated network services outside the Section 214 framework. This preserved their operational footing at what the report calls "critical nodes of U.S. internet infrastructure."
"They make American customers promise to censor information according to the CCP’s laws, and they poison the domestic cyber infrastructure we rely on," said Select Committee Chairman John Moolenaar (R-MI).
How a Ghost Network Connects to a Major Cyberattack
The report crystallizes its fears by linking this residual infrastructure to the Salt Typhoon espionage campaign of 2024. While the committee stops short of alleging direct participation by the telecoms' U.S. employees, it presents technical data suggesting their networks were exploited or played a supporting role.
The committee's technical analysis identified nearly 109,000 incidents from 2018-2025 where Chinese or Hong Kong-linked networks allegedly hijacked routes for U.S. internet addresses, potentially diverting traffic. More than 4,200 incidents involved China Mobile-controlled networks.
Crucially, during the initial exposure of Salt Typhoon in September 2024, the committee identified 58 groups of internet addresses linked by CISA to Salt Typhoon servers. China Mobile International’s network appeared in routes to those servers at least 192 times across a three-day period, helping keep the malicious infrastructure reachable even as U.S. defenders tried to dismantle it.
Key technical links:
- China Telecom and other state-backed carriers were tied by U.S. agencies to past large-scale internet routing incidents where U.S. traffic was misrouted to PRC-controlled networks.
- China Unicom is a corporate partner of i-SOON, a cybersecurity firm the U.S. government accuses of involvement in state-sponsored hacking.
- China Unicom also has verified links to Integrity Tech, a company sanctioned by the U.S. and directly accused of state-sponsored hacking activities.
This creates an undeniable nexus: companies legally obligated to support Chinese intelligence retain physical and virtual gateways inside the U.S., while their infrastructure shows up in the technical forensics of a major attack. The cause may be exploitation, not direct complicity, but the effect is the same: a persistent vulnerability.
The Corporate Maze That Preserves Their Foothold
The operational persistence of these firms stems from a complex, layered corporate structure designed to navigate U.S. regulations.
The committee found that the U.S.-based subsidiaries are not independent. Each sits "at the bottom of an ownership chain that runs through Hong Kong and offshore holding companies to a Chinese state-owned enterprise." The ultimate parent companies are governed by China’s State-owned Assets Supervision and Administration Commission, a direct arm of the state.
This allows the U.S. entities to maintain a profile as compliant, local businesses while being legally and practically controlled from Beijing. When subpoenaed by the House committee, the companies' responses were telling. Some officials refused to acknowledge basic facts about their employers. None of those interviewed would acknowledge reading news reports about the Salt Typhoon incidents, a claim the report frames as implausible for telecom professionals.
The services they continue to offer are the mundane plumbing of the internet, which makes them both essential and dangerous:
- Renting physical space in U.S. data centers
- Managing corporate VPNs
- Providing internet transit and enterprise networking
- Brokering third-party network equipment
- Routing customer data globally through their infrastructure
This is the security gap: the FCC regulates telecommunications services, but lacks clear authority over the underlying foreign-controlled infrastructure already woven into the domestic fabric. To understand how this risk manifests, we previously explored the mechanics of How BGP Hijacking Turns Internet Traffic into an Espionage Tool.
What It Takes to Truly Cut a Digital Adversary Out
The House report is a direct indictment of the current regulatory framework as being fragmented and insufficient. The FCC’s primary tool—license revocation—proved to be a blunt instrument that left the roots of the problem in place.
The committee lays out a roadmap for Congress to close these gaps. Its recommendations move far beyond the "blacklist" approach to demanding active removal and persistent monitoring. The core philosophy is a shift from regulating services to controlling infrastructure.
- Codify FCC Authority: Give the FCC explicit statutory power to deny blanket authorizations and restrict domestic interconnection for national security.
- "Rip-and-Replace" Funding: Establish and fund a targeted program to physically remove equipment and infrastructure from designated foreign-adversary companies, similar to existing programs for Huawei gear.
- Broaden Oversight Mandates: Expand the jurisdiction of "Team Telecom" (an interagency review group) and ICTS (Information and Communications Technology and Services) authorities to cover private commercial arrangements, like data center colocation and peering agreements.
- Mandate Logging: Require foreign-controlled operators to implement interim logging and monitoring until their infrastructure can be removed or fully mitigated.
This echoes a broader call for the U.S. to better defend its digital borders. As we noted in our analysis of The U.S. Executive Order on Securing Critical Network Infrastructure, the challenge is moving from identifying risks to executing complex, disruptive removals.
The Inevitable Push Toward a Balkanized Internet
This standoff is not just a U.S.-China problem. It is a live-fire test for a foundational question: can a globally connected internet survive an era of digital sovereignty and persistent cyber conflict?
The U.S. move to forcibly remove Chinese infrastructure invites reciprocal action. China already prohibits U.S. telecom operators from its market. Beijing could escalate by targeting the vast global infrastructure of U.S. cloud providers like Amazon, Microsoft, and Google, or content delivery networks under the same national security pretexts.
The policy dilemma is acute. Aggressive "rip-and-replace" actions can cause significant disruption to legitimate global internet traffic and business operations. Inaction, however, leaves critical vulnerabilities in place that a geopolitical adversary has both the intent and legal mandate to exploit. The Salt Typhoon campaign proved those vulnerabilities are not theoretical.
The House China Committee's report makes the calculation clear. It frames the continued presence of these networks not as a regulatory oversight, but as an active national security threat enabled by legal loopholes. The next step is legislative, and the clock is ticking. Every day these "trusted backdoors" remain operational is another day they could be used, turning the foundational infrastructure of American digital life into a vector for its biggest strategic rival.
Impact Analysis
- The continued infrastructure presence creates potential backdoors for state-sponsored cyber operations like Salt Typhoon.
- Critical US telecom infrastructure remains vulnerable despite regulatory actions, exposing national security gaps.
- These findings highlight how legal loopholes can undermine national security measures against foreign state-owned enterprises.
Chinese Telecom Companies' US Presence
| Company | FCC License Status | Post-Restriction Strategy |
|---|---|---|
| China Telecom | Revoked/Denied (Section 214) | Private interconnection agreements, retained infrastructure |
| China Mobile | Revoked/Denied (Section 214) | Network service backbone operations |
| China Unicom | Revoked/Denied (Section 214) | Embedded hardware and data center presence |
Sources
- [1] The Record
- [2] Chinese telecom firms kept footholds in US networks despite federal crackdowns, House probe finds
- [3] Stranger Pings: Chinese Telecom Companies Infiltrate U.S. Infrastructure
- [4] US data centers may still have a China problem: House panel warns Chinese telecom firms embedded despite FCC action
Written by
XOOMAR Insights Team
Research and Editorial Desk
The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.
Explore More Topics
Related Articles
CybersecurityFCC Robot Inverter Ban Locks Foreign Tech Out of U.S.
The FCC blocked new foreign-made mobile robots and connected power inverters from U.S. approval over national security risks.
Cybersecurity42 US Attacks Pull Russian Cybercrime Hosts Into Court
DOJ says Russian bulletproof hosts enabled attacks on 42 US entities, shifting pressure from hackers to infrastructure sellers.
CybersecurityNew York Water Cybersecurity Grants Shield 153 Utilities
New York is spending $9M to harden 153 water systems, but the grants buy targeted fixes, not full cyber resilience.
CybersecurityIran-Linked Hackers Breach U.S. Water, Energy Controls
U.S. agencies say Iran-linked hackers are breaching exposed utility controls, turning water and energy networks into pressure points.
CybersecurityBanks Brace for Gold Eagle AI Cybersecurity Pressure
Gold Eagle is voluntary, but banks may feel pressure to use its federal vulnerability intelligence before examiners start asking.
TechnologyTrump AI Framework Excludes Open Models in Cybersecurity Blind Spot
The Trump administration's AI testing framework excludes open models, creating a two-tier system that favors corporate labs and leaves a critical cybersecurity
TradingSterling Stalls Short of 1.35 as Politics Go Dark
The British pound has stalled below a key level and entered a directionless pause, now completely untethered from UK politics for six weeks as Parliament is in
Global TrendsIran Seizes Control Over Strait of Hormuz Via Secret Oman Deal
Iran formalized a temporary shipping route with Oman, cementing Tehran's administrative control over the Strait of Hormuz while keeping blame for insecurity on
Global TrendsMichigan Republicans Elect Ghost Candidate Over Trump Pick
Michigan GOP primary voters rejected a Trump-backed candidate, instead electing a rival who had already withdrawn from the race, in a direct rebuke of top-down
Global TrendsInfantino Survives Revolt With Locked FIFA Consensus Vote
FIFA's executive board staged a political theater in Rabat to quell a revolt, delivering a foregone vote of support that shows Gianni Infantino's power now oper
Don't miss the signal
Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.
Free forever. No spam. Unsubscribe anytime.