According to a House report, Chinese carriers have never exited US networks.
The Salt Typhoon breach, which affected the largest phone carriers in America, had a back door that was obvious yet overlooked. A bipartisan House report presents a straightforward conclusion. Three state-owned Chinese telecom companies, which had been expelled from the U.S. years ago, have not completely exited the market. According to the report, their lingering presence may have contributed to the persistence of the hackers' infrastructure.
Between 2019 and 2022, U.S. regulators denied or revoked the licenses of China Telecom, China Mobile, and China Unicom. However, the House Select Committee on China identified a loophole: the companies were not compelled to dismantle their equipment, vacate data centers, or sever private network connections. As a result, these carriers maintained enterprise networking, transit, and hardware within American facilities.
The Salt Typhoon incident
Discovered in 2024, Salt Typhoon was a significant Chinese espionage initiative that penetrated AT&T, Verizon, and Lumen, even gaining access to court-sanctioned wiretap systems. It targeted high-ranking officials, including then-presidential candidate Donald Trump and Vice President JD Vance.
The committee analyzed routing data from the time the breach became known. Reports indicated that China Mobile International's network was present in routing paths to those servers at least 192 times.
The committee is cautious about drawing conclusions from this evidence; it does not claim that China Mobile's U.S. personnel were aware of or participated in the breach. They state that the routing evidence is not conclusive but suggest that the existing connections could facilitate continued access to the malicious infrastructure.
Cloudflare and external experts have corroborated parts of this analysis.
The regulatory gap
The vulnerability stemmed from data centers and secondary connections that lie beyond the regulators' authority. The Federal Communications Commission (FCC) can prohibit a carrier's services but cannot terminate its hardware, leases, or private connections. One witness described China Mobile USA as “essentially a sales team.” Nevertheless, the panel identified 143 active network assets in U.S. facilities, and approximately a quarter of the hardware from China Telecom Americas was still manufactured by Huawei.
In response, the FCC is in the process of drafting an order to prohibit Chinese-made data center components, a measure we highlighted last week. This effort builds on an existing list of entities already banned from U.S. networks. The U.S. government has already invested billions in removing Huawei equipment. The committee urges Congress to take more stringent action regarding the equipment and private agreements that remain post-revocation.
The challenge ahead
Not everyone is convinced that this solution is viable. China’s embassy criticized the U.S. for "overstating" national security concerns. Marc Rogers, an expert in telecom security, expressed agreement with many points in the report but deemed the expanded rip-and-replace approach unrealistic, likening it to “bulldozing an entire city to create a new one.” He cautioned that such measures could only succeed if allied nations act cohesively. The three carriers have not responded to requests for comment.
The deeper takeaway is structural. A telecom system reliant on private infrastructure and long-standing commercial relationships is difficult to dismantle. A ban on a service rarely extends to the underlying equipment. As U.S.-China cyber tensions escalate ahead of a leaders' summit, Beijing has reciprocated past U.S. sanctions with its own measures. The committee's conclusion is clear: the back door was never truly secured.
Other articles
According to a House report, Chinese carriers have never exited US networks.
A bipartisan report from the House indicates that three Chinese state-owned carriers maintained equipment and network connections in the United States, links it associates with the Salt Typhoon hack.
