Telecom
Telecom towers in New Mexico. Image: Scott Elkins via Unsplash

Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says

Three Chinese telecommunications giants continue to have footholds in the U.S. internet ecosystem despite their alleged role in previous Chinese hacking campaigns, lawmakers said Tuesday.

Congress’s bipartisan Select Committee on China published a 49-page investigation into China Mobile, China Unicom, and China Telecom — three companies that had their telecommunications licenses denied or revoked by regulators between 2019 and 2022 due to cybersecurity concerns. 

The investigation was conducted in the wake of the Salt Typhoon hack of at least nine U.S. telecommunications companies. In addition to technical investigations, the committee subpoenaed all three companies and interviewed people working at each firm. 

The committee concluded that none of the firms are independent from their Chinese parent companies who have deep ties to the government. License denials and revocations by the Federal Communications Commission (FCC) limited the companies but did not force them to remove their equipment or hamper their business ties to other telecoms and technology firms.

Despite the FCC action, Chinese state-owned carriers “remained deeply embedded in the U.S. internet ecosystem long after federal regulators had already found them vulnerable to CCP exploitation, influence, and control and took action to terminate their provision of international telecommunication services.”

The study urges Congress to beef up the FCC’s authority to limit the companies’ ability to operate in the U.S. and take other actions to force companies to “rip-and-replace” technology from China Mobile, China Unicom and China Telecom.

Select Committee Chairman John Moolenaar (R-MI) said the companies “are a threat to all of us” because they are “beholden to the [Communist Party of China].” He added that the companies “poison the domestic cyber infrastructure we rely on.” 

“All of this leaves us vulnerable to a new wave of state-sponsored cyberattacks from our nation’s biggest adversary,” Moolenaar said. 

“The CCP does not allow U.S. telecom companies into China. We must cut these subsidiaries out of our domestic infrastructure to protect the American people.”

Section 214

The report reviews the aftermath of the FCC decision to revoke or Section 214 authorization for the three companies, which blocks them from providing some services in the U.S.

While the report lauds the FCC for these actions, it found that they did not force the companies to shut down their physical operations in the U.S. All three “quietly obtained or retained hardware, interconnection agreements, and data center footholds that served as their ‘trusted’ backdoors.”

The committee outlines several ways the companies were potentially involved in the Salt Typhoon attacks and could continue to provide pathways for Chinese government access. 

The study found that each company sits “at the bottom of an ownership chain that runs through Hong Kong and offshore holding companies to a Chinese state-owned enterprise.” All of the parent companies are governed by China’s State-owned Assets Supervision and Administration Commission of the State Council.

The committee noted the companies initially did not respond to voluntary outreach and the Chinese government condemned the subpoenas that were issued. 

Eight interviews with company officials were conducted in September 2025, with some willing to answer questions and others refusing to acknowledge even basic facts about their employers. None of those interviewed would acknowledge reading news reports about the Salt Typhoon incidents.

After the FCC action, all three companies pivoted into less regulated network services. 

“By rebuilding their U.S. businesses around network services outside the core Section 214 licensing framework, they preserved their operational footing at critical nodes of U.S. internet infrastructure,” the study said.

“The carriers also kept Chinese-manufactured equipment running inside U.S. networks, including hardware built by firms subject to PRC legal obligations that can compel cooperation with state security and intelligence services.”

The companies continued to route customer data across the globe, rent physical space at U.S. facilities, manage VPNs, broker third-party network equipment and more. 

Links to Salt Typhoon

The report linked the three companies to a variety of cybersecurity incidents over the last decade and multiple sanctioned Chinese cybersecurity companies.

According to the study, China Telecom and other state-backed carriers were tied to several large-scale internet routing incidents where U.S. government, private-sector, and domestic traffic was misrouted to PRC-controlled networks. 

While many of these incidents may have been accidents, the Justice Department and other agencies concluded that multiple incidents intended to expose data to interception or alteration, the study said.  

The committee declined to say that China Mobile participated directly in the Salt Typhoon cyber campaign but found technical data that tied the hacking incidents to the company’s infrastructure. 

China Unicom also has verified links to Integrity Tech – a company sanctioned by the U.S. and accused of being directly involved in China’s state-sponsored hacking activities. China Unicom is also a corporate partner of i-SOON, another Chinese cybersecurity company accused by the U.S. government of involvement in several hacking campaigns. 

The study includes recommendations to Congress on ways to further limit the ability of China Mobile, China Unicom, China Telecom and other companies to operate in the U.S. 

It also calls for more funding for federal agencies to hire experts who understand cyber threats on a technical level. 

Rep. Ro Khanna (D-CA), ranking member of the committee, said the report highlights the need for Congress to “address risks to Americans’ data and ensure that the agencies responsible for securing our communications networks have the resources they need to respond to potential threats.”

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.