Chinese Telecom Giants Retain U.S. Footholds Despite Security Concerns, Lawmakers Warn
Despite previous license revocations and documented ties to state-sponsored hacking campaigns, three major Chinese telecommunications companies—**China Mobile**, **China Unicom**, and **China Telecom**—maintain significant operational presence within the U.S. internet ecosystem. A new bipartisan congressional investigation highlights these enduring vulnerabilities and calls for strengthened regulatory action to protect national cyber infrastructure.
A recent **U.S. Congress Select Committee on China** investigation has revealed that three prominent Chinese telecommunications companies continue to be deeply embedded in the U.S. internet infrastructure, raising significant cybersecurity concerns.
The 49-page report, released Tuesday, specifically targets **China Mobile**, **China Unicom**, and **China Telecom**. These firms had their telecommunications licenses denied or revoked by U.S. regulators between 2019 and 2022 due to their alleged ties to the Chinese government and potential national security risks.
The investigation was prompted in part by the **Salt Typhoon** hack, which impacted at least nine U.S. telecommunications companies. The committee issued subpoenas and conducted interviews with personnel from all three Chinese firms.
### Enduring Influence Despite FCC Action
The committee concluded that none of the companies operate independently of their Chinese parent corporations, which maintain strong links to the Chinese government. While the **Federal Communications Commission (FCC)** actions limited their ability to provide certain services, they did not compel the companies to remove existing equipment or sever business relationships with other U.S. telecom and technology firms.
"Chinese state-owned carriers remained deeply embedded in the U.S. internet ecosystem long after federal regulators had already found them vulnerable to CCP exploitation, influence, and control and took action to terminate their provision of international telecommunication services," the report states.
**Select Committee Chairman John Moolenaar (R-MI)** emphasized the threat posed by these companies, stating they "are a threat to all of us" because they are "beholden to the [Communist Party of China]" and "poison the domestic cyber infrastructure we rely on."
"All of this leaves us vulnerable to a new wave of state-sponsored cyberattacks from our nation’s biggest adversary," Moolenaar added, advocating for a "rip-and-replace" mandate similar to China's prohibition of U.S. telecom companies within its borders.
### Loopholes in Section 214 Authorizations
The report scrutinizes the aftermath of the FCC's decision to revoke or deny **Section 214** authorizations for the three companies, which traditionally restricts their provision of certain services in the U.S. While commending the FCC's initial steps, the investigation found these measures did not force the companies to cease physical operations.
Instead, the report alleges, all three firms "quietly obtained or retained hardware, interconnection agreements, and data center footholds that served as their ‘trusted’ backdoors."

The committee outlined several avenues through which the companies could have been involved in the **Salt Typhoon** attacks and may continue to facilitate access for the Chinese government. The study revealed that each company is part of an ownership structure extending through Hong Kong and offshore holding companies, ultimately controlled by a Chinese state-owned enterprise under the **State-owned Assets Supervision and Administration Commission of the State Council**.
Initial outreach by the committee was met with non-cooperation, and the Chinese government condemned the subsequent subpoenas. Interviews conducted in September 2025 with company officials yielded mixed results, with some refusing to acknowledge even basic facts or news reports concerning the **Salt Typhoon** incidents.
Following the FCC's actions, the companies reportedly pivoted to less regulated network services.
"By rebuilding their U.S. businesses around network services outside the core **Section 214** licensing framework, they preserved their operational footing at critical nodes of U.S. internet infrastructure," the study noted. They also maintained Chinese-manufactured equipment within U.S. networks, including hardware from firms subject to Chinese legal obligations that can compel cooperation with state security and intelligence services.
These activities included routing customer data globally, renting physical space at U.S. facilities, managing VPNs, and brokering third-party network equipment.
### Links to Salt Typhoon and Sanctioned Entities
The report explicitly links the three companies to various cybersecurity incidents over the past decade and to multiple sanctioned Chinese cybersecurity firms.
**China Telecom**, along with other state-backed carriers, was tied to several large-scale internet routing incidents where U.S. government, private-sector, and domestic traffic was reportedly misrouted to PRC-controlled networks. While some incidents might be accidental, the **Justice Department** and other agencies have concluded that multiple incidents were designed to expose data to interception or alteration.
Though the committee did not directly implicate **China Mobile** in the **Salt Typhoon** campaign, technical data reportedly connected the hacking incidents to the company’s infrastructure.
**China Unicom** also has verified ties to **Integrity Tech**, a company sanctioned by the U.S. and accused of direct involvement in China's state-sponsored hacking. Furthermore, **China Unicom** is a corporate partner of **i-SOON**, another Chinese cybersecurity company accused by the U.S. government of participating in several hacking campaigns.
The study concludes with recommendations to Congress, urging further limitations on the operational capabilities of **China Mobile**, **China Unicom**, **China Telecom**, and similar entities in the U.S. It also calls for increased funding for federal agencies to recruit experts with deep technical understanding of cyber threats.
**Rep. Ro Khanna (D-CA)**, ranking member of the committee, stated that the report underscores the need for Congress to "address risks to Americans’ data and ensure that the agencies responsible for securing our communications networks have the resources they need to respond to potential threats."