A 49-page investigation released by the House Select Committee on China warns that three state-owned Chinese telecommunications giants—China Mobile, China Unicom, and China Telecom—maintain extensive, unregulated access to U.S. core internet infrastructure despite years of federal regulatory bans. Released in the wake of the Salt Typhoon cyber espionage campaign that compromised at least nine U.S. telecommunications providers, the bipartisan report reveals how regulatory enforcement gaps allowed these Chinese state-owned enterprises (SOEs) to preserve physical footholds, data center presences, and cross-border routing capabilities within domestic networks.
While the Federal Communications Commission (FCC) denied or revoked these carriers’ Section 214 authorizations between 2019 and 2022 on national security grounds, those actions only revoked their legal rights to operate as common carriers offering international telecommunication services. The restrictions failed to compel the companies to remove physical hardware, vacate U.S. data center facilities, or sever commercial interconnect agreements with American technology and telecom firms.
Regulatory Gaps and Pivots to Unregulated Services
When the FCC issued Section 214 revocations, it targeted common carrier operations under the Communications Act of 1934. However, the House investigation shows that China Mobile, China Unicom, and China Telecom circumvented the spirit of these orders by restructuring their U.S. operations around unregulated network services.
By shifting from public carrier offerings to private enterprise solutions, the carriers continued operating at vital nexus points of the U.S. internet ecosystem. Their ongoing activities include:
- Managing enterprise virtual private networks (VPNs) and private transit routes.
- Leasing colocation space and equipment racks inside major U.S. data centers and Internet Exchange Points (IXPs).
- Brokering third-party network hardware and maintaining Chinese-manufactured infrastructure within U.S. facilities.
- Routing domestic and international customer data through offshore infrastructure.
All three companies remain structured under complex ownership chains running through Hong Kong and offshore holding entities, ultimately leading to direct oversight by Beijing’s State-owned Assets Supervision and Administration Commission of the State Council (SASAC). During committee outreach, the firms initially ignored voluntary requests and were subsequently subpoenaed. In eight interviews conducted with company personnel, officials repeatedly refused to acknowledge basic operational facts or reading reports regarding the Salt Typhoon attacks.
Direct Links to Salt Typhoon and Infrastructure Exploitation
The Select Committee’s report directly links these persistent infrastructure footholds to state-backed offensive operations, including technical telemetry associated with Salt Typhoon. The threat actor—known for infiltrating core telecommunications infrastructure, lawful intercept gateways, and call detail record (CDR) systems—has engaged in widespread intelligence gathering targeting U.S. communications infrastructure.
While the report stops short of directly accusing China Mobile of conducting the Salt Typhoon breaches, investigators confirmed technical data linking the campaign’s command-and-control and intrusion activity directly to China Mobile infrastructure. Furthermore, the report highlights deeper connections between the carriers and known offensive vendors:
- China Unicom maintains verified ties to Integrity Tech, a U.S.-sanctioned firm linked directly to Chinese state-sponsored cyber operations.
- China Unicom is a formal corporate partner of i-SOON, the Chinese cybersecurity contractor whose leaked internal documents previously exposed contract offensive hacking operations conducted for the Ministry of State Security (MSS) and People’s Liberation Army (PLA).
- China Telecom and allied state carriers have historically been implicated in deliberate Border Gateway Protocol (BGP) routing anomalies, where U.S. government and commercial internet traffic was diverted through PRC-controlled network nodes before reaching its intended destination.
The Architecture of Telecom-Level Espionage
From a network security perspective, allowing adversary-controlled entities to maintain physical and logical footholds in domestic IXPs and colocation centers creates severe systemic risk.
Telecom-level access allows state actors to leverage several foundational internet mechanisms:
- BGP Hijacking and Misrouting: Possessing autonomous system numbers (ASNs) and direct peering arrangements enables adversaries to broadcast malicious BGP routes, pulling domestic traffic across Chinese-controlled transit switches for passive interception, decryption analysis, or active manipulation.
- Physical and Logical Co-location Access: Renting hardware racks in carrier-neutral facilities allows technicians physical proximity to backbone routers. Unmonitored optical splitters or span ports can mirror unencrypted transit traffic across facility cross-connects without triggering host-level intrusion detection systems.
- Supply Chain and Hardware Risks: Maintaining hardware subject to Chinese state security laws—such as national intelligence laws that mandate corporate compliance with intelligence gathering—provides persistent out-of-band management channels into enterprise environments.
Select Committee Chairman John Moolenaar (R-MI) emphasized that these companies remain beholden to the Chinese Communist Party and “poison the domestic cyber infrastructure we rely on,” noting that while China bans U.S. telecom providers from operating domestically, the U.S. has allowed Chinese subsidiaries to embed themselves deep within American networks.
Recommended Legislative Actions
To close these vulnerabilities, the Select Committee—supported by Ranking Member Rep. Ro Khanna (D-CA)—is urging Congress to expand the FCC’s statutory mandate. Recommendations include:
- Broadening regulatory authority beyond Section 214 to ban state-linked carriers from providing any network services, enterprise VPNs, or data center operations within the U.S.
- Mandatory “rip-and-replace” legislation requiring domestic facilities and telecoms to purge all physical hardware associated with China Mobile, China Unicom, and China Telecom.
- Expanding federal funding for agencies like the FCC and CISA to recruit advanced technical cyber analysts capable of detecting low-level infrastructure manipulation.
Organizations managing critical infrastructure or enterprise networks should audit their transit paths, colocation facilities, and cross-connect agreements to identify and remediate any direct or indirect reliance on services or hardware connected to China Mobile, China Unicom, or China Telecom.
Related content
China-Aligned Hackers Exploit Roundcube Vulnerabilities in University Attacks
Security NewsChina-Linked APT Group Exploits Roundcube Flaws in Cyberespionage Campaign
Security NewsIll Bloom Vulnerability Compromises Crypto Wallets Through Weak Randomness
Security NewsSonicWall SMA 1000 Appliances Patched Against Actively Exploited Zero-Days
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call