BTC$63,057+0.34% LTC$44.05+1.12% XMR$412.08+4.33%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Aug 5, 2026 · 5 min read · Original story

Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says

Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says
Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says

Three Chinese telecommunications giants continue to have footholds in the U.S. internet ecosystem despite their alleged role in previous Chinese hacking campaigns, lawmakers said Tuesday.

Congress’s bipartisan Select Committee on China published a 49-page investigation into China Mobile, China Unicom, and China Telecom — three companies that had their telecommunications licenses denied or revoked by regulators between 2019 and 2022 due to cybersecurity concerns.

The investigation was conducted in the wake of the Salt Typhoon hack of at least nine U.S. telecommunications companies. In addition to technical investigations, the committee subpoenaed all three companies and interviewed people working at each firm.

The committee concluded that none of the firms are independent from their Chinese parent companies who have deep ties to the government. License denials and revocations by the Federal Communications Commission (FCC) limited the companies but did not force them to remove their equipment or hamper their business ties to other telecoms and technology firms.

Despite the FCC action, Chinese state-owned carriers “remained deeply embedded in the U.S. internet ecosystem long after federal regulators had already found them vulnerable to CCP exploitation, influence, and control and took action to terminate their provision of international telecommunication services.”

The study urges Congress to beef up the FCC’s authority to limit the companies’ ability to operate in the U.S. and take other actions to force companies to “rip-and-replace” technology from China Mobile, China Unicom and China Telecom.

Select Committee Chairman John Moolenaar (R-MI) said the companies “are a threat to all of us” because they are “beholden to the [Communist Party of China].” He added that the companies “poison the domestic cyber infrastructure we rely on.”

“All of this leaves us vulnerable to a new wave of state-sponsored cyberattacks from our nation’s biggest adversary,” Moolenaar said.

“The CCP does not allow U.S. telecom companies into China. We must cut these subsidiaries out of our domestic infrastructure to protect the American people.”

Section 214

The report reviews the aftermath of the FCC decision to revoke or Section 214 authorization for the three companies, which blocks them from providing some services in the U.S.

While the report lauds the FCC for these actions, it found that they did not force the companies to shut down their physical operations in the U.S. All three “quietly obtained or retained hardware, interconnection agreements, and data center footholds that served as their ‘trusted’ backdoors.”

The committee outlines several ways the companies were potentially involved in the Salt Typhoon attacks and could continue to provide pathways for Chinese government access.

The study found that each company sits “at the bottom of an ownership chain that runs through Hong Kong and offshore holding companies to a Chinese state-owned enterprise.” All of the parent companies are governed by China’s State-owned Assets Supervision and Administration Commission of the State Council.

The committee noted the companies initially did not respond to voluntary outreach and the Chinese government condemned the subpoenas that were issued.

Eight interviews with company officials were conducted in September 2025, with some willing to answer questions and others refusing to acknowledge even basic facts about their employers. None of those interviewed would acknowledge reading news reports about the Salt Typhoon incidents.

After the FCC action, all three companies pivoted into less regulated network services.

“By rebuilding their U.S. businesses around network services outside the core Section 214 licensing framework, they preserved their operational footing at critical nodes of U.S. internet infrastructure,” the study said.

“The carriers also kept Chinese-manufactured equipment running inside U.S. networks, including hardware built by firms subject to PRC legal obligations that can compel cooperation with state security and intelligence services.”

The companies continued to route customer data across the globe, rent physical space at U.S. facilities, manage VPNs, broker third-party network equipment and more.

Links to Salt Typhoon

The report linked the three companies to a variety of cybersecurity incidents over the last decade and multiple sanctioned Chinese cybersecurity companies.

According to the study, China Telecom and other state-backed carriers were tied to several large-scale internet routing incidents where U.S. government, private-sector, and domestic traffic was misrouted to PRC-controlled networks.

While many of these incidents may have been accidents, the Justice Department and other agencies concluded that multiple incidents intended to expose data to interception or alteration, the study said.

The committee declined to say that China Mobile participated directly in the Salt Typhoon cyber campaign but found technical data that tied the hacking incidents to the company’s infrastructure.

China Unicom also has verified links to Integrity Tech – a company sanctioned by the U.S. and accused of being directly involved in China’s state-sponsored hacking activities. China Unicom is also a corporate partner of i-SOON, another Chinese cybersecurity company accused by the U.S. government of involvement in several hacking campaigns.

The study includes recommendations to Congress on ways to further limit the ability of China Mobile, China Unicom, China Telecom and other companies to operate in the U.S.

It also calls for more funding for federal agencies to hire experts who understand cyber threats on a technical level.

Rep. Ro Khanna (D-CA), ranking member of the committee, said the report highlights the need for Congress to “address risks to Americans’ data and ensure that the agencies responsible for securing our communications networks have the resources they need to respond to potential threats.”

References in this story

  1. At least 8 US telcos, dozens of countries impacted by Salt Typhoon breaches, White House says therecord.media Senators briefed on the wide-ranging breaches by Chinese hackers called for action on Wednesday to protect the country's telecommunications networks.
  2. US lawmakers' subpoena of Chinese telecom firms over security concerns a clear case of political manipulation: expert -… www.globaltimes.cn The leaders of a US congressional committee on Wednesday issued subpoenas to China
  3. US sanctions prominent Chinese cyber company for role in Flax Typhoon attacks therecord.media The Treasury Department said Integrity Technology provided Flax Typhoon actors with infrastructure between the summer of 2022 and fall of 2023 — with the state-backed groups sharing and receiving information from the…
  4. Company listed on Shanghai stock exchange accused of aiding Chinese cyberattacks therecord.media The cybersecurity company Integrity Technology Group (Integrity Tech), also known as Yongxin Zhicheng, is connected with a hacking operation tracked as Flax Typhoon, the U.S. said after announcing it had taken down an…
  5. US charges Chinese nationals in cyberattacks on Treasury, dissidents and more therecord.media U.S. prosecutors accused a dozen Chinese nationals with hacking into the Treasury Department and other entities as part of a web extending from private companies into China's state security agencies.
  6. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  7. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  8. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

Guides related to this story

← Back to all news