Chinese telecoms kept footholds in US despite crackdowns, probe finds

Years after federal regulators invoked national security to push three Chinese state-owned telecommunications providers out of the American market, the companies never fully left, a new House probe has found.

China Telecom, China Mobile, and China Unicom retained equipment, data-center space and connections to other networks in the United States after the Federal Communications Commission denied or revoked their authority to provide certain telecommunications services, according to a nearly 50-page bipartisan House China Committee investigation planned for release Tuesday and first seen by Nextgov/FCW.

From 2019 to 2022, the FCC denied China Mobile USA’s application to provide international service; it revoked related authorizations held by China Telecom Americas and China Unicom Americas. But those actions did not require the companies to remove equipment, leave data centers, or sever private network links, so the carriers continued offering enterprise networking, internet transit and other services, the panel found.

The committee argues that those remaining footholds could give Beijing’s cyberspies visibility into sensitive traffic, help keep malicious infrastructure online and create opportunities to reroute data or reach U.S. targets. American officials regard China as the country’s leading cyber adversary, with a record of targeting critical infrastructure and stealing military, commercial and personal data.

The three carriers did not respond to detailed requests for comment.

Nextgov/FCW also sought comment from the FBI, the Cybersecurity and Infrastructure Security Agency, and several U.S. spy agencies. The Defense Intelligence Agency, which produces intelligence findings for the Pentagon, declined to comment.

A spokesperson for China’s embassy in Washington said Beijing “firmly opposes the U.S. overstretching the concept of national security and going after Chinese companies,” adding that China would defend its “legitimate and lawful rights and interests.”

The remaining network ties took on added significance in the committee’s review of Salt Typhoon, the sweeping Chinese espionage campaign uncovered in 2024 where hackers breached major telecom carriers in the United States and abroad. The intrusion reached systems used to comply with court-authorized wiretap requests and allowed the cyberspies to target the communications of senior U.S. officials, including President Donald Trump and Vice President JD Vance.

Reviewing routing data from Sept. 22 to 25, 2024, just as the Salt Typhoon campaign became public, the committee identified 58 groups of internet addresses that CISA had linked to Salt Typhoon servers. China Mobile International’s network appeared in routes to those servers at least 192 times, helping keep the attacker infrastructure reachable as U.S. defenders sought to shut it down, the report said.

The committee does not allege that China Mobile USA employees knew about or participated in the campaign, and it says the routing evidence does not definitively link the company to Salt Typhoon. But the panel argues that the overlap shows how China Mobile’s remaining network ties could help sustain malicious infrastructure.

That finding came from a broader analysis that identified nearly 109,000 incidents from January 2018 through May 2025 in which Chinese or Hong Kong-linked networks allegedly claimed U.S. internet addresses without authorization, potentially diverting American traffic through their systems. The committee classified them as high-confidence hijacks of the Border Gateway Protocol, a bedrock system that directs traffic across networks, but acknowledged that some may have resulted from mistakes or poor network management.

More than 4,200 of the incidents involved China Mobile-controlled networks. In September 2024, eight originated from the same network that appeared in routes to Salt Typhoon servers and diverted traffic belonging to unnamed U.S. network operators, the committee said.

Chinese telecoms kept footholds in US despite crackdowns, probe finds – Defense One

(David DiMolfetta – Defense One) 

The Global Eye is in partnership with SIOI

Latest articles

Related articles