FCC revocations left Chinese carriers in US networks, House probe finds
The agency had authority to order physical departure but never invoked it, and China Mobile's retained routing appeared 192 times in paths to Salt Typhoon infrastructure during the 2024 breach response.
TL;DR
A bipartisan House China Committee investigation found that FCC revocations of China Telecom, China Mobile, and China Unicom authorizations from 2019, 2022 did not require equipment removal, data-center exit, or private network severance. The carriers kept operational US footholds. Routing data from September 2024, analyzed during the Salt Typhoon campaign, showed China Mobile International's network appearing in paths to CISA-linked attacker servers at least 192 times, sustaining infrastructure as defenders tried to isolate it. The committee identified nearly 109,000 BGP hijack incidents from China-linked networks between 2018 and mid-2025, over 4,200 involving China Mobile-controlled networks.
The headline finding from the House China Committee's nearly 50-page report isn't that Chinese telecom carriers posed a threat. That part was settled by 2019. The finding is that the regulatory mechanism used to address the threat stopped at the paperwork.
From 2019 to 2022, the FCC denied China Mobile USA's application to provide international service and revoked the Section 214 authorizations held by China Telecom Americas and China Unicom Americas. None of those actions required the companies to pull equipment from US data centers, terminate private peering arrangements, or stop offering enterprise networking and internet transit services to American customers. So they didn't. The committee, relying on subpoenaed records, sworn testimony, and independent routing analysis verified by Cloudflare, found that all three carriers retained operational US network footprints years after their authorizations were revoked.
The gap isn't obscure. Section 214 authority governs whether a carrier can provide telecommunications services. Revoking it doesn't touch equipment leases, colocation agreements, or private interconnections. The FCC could have pursued physical removal through other authorities but never did. The carriers, state-owned and subject to China's 2017 National Intelligence Law (which requires companies to assist state intelligence work) kept operating on an unregulated basis.
What Salt Typhoon revealed about the gap
The committee examined Border Gateway Protocol routing data from September 22 to 25, 2024, the window when the Salt Typhoon espionage campaign became public. It identified 58 groups of IP addresses that CISA had linked to Salt Typhoon command-and-control servers. China Mobile International's network appeared in routes to those servers at least 192 times during that period.
The committee does not allege that China Mobile USA employees knew about or participated in the campaign, and it states the routing evidence does not definitively link the company to Salt Typhoon. But the overlap demonstrates the operational consequence of leaving a carrier's network interconnections intact after revocation: attacker infrastructure remained reachable through that carrier's routing as US defenders worked to isolate it.
The committee's broader BGP analysis identified nearly 109,000 incidents from January 2018 through May 2025 in which Chinese or Hong Kong-linked networks claimed US internet addresses without authorization, classified as high-confidence route hijacks, though the panel acknowledged some may reflect misconfiguration rather than malice. More than 4,200 involved China Mobile-controlled networks. In September 2024, eight hijack incidents originated from the same China Mobile network that appeared in Salt Typhoon routing paths and diverted traffic belonging to unnamed US network operators.
The subsidiaries never operated independently
The committee's subpoenaed testimony also revealed structural dependence on parent entities. At China Telecom Americas, requests involving connections between US and overseas networks were handled by personnel in Shanghai, Hong Kong, or Beijing. Service orders could flow through a parent-controlled system to Shanghai Telecom without a separate contract. The US subsidiary didn't maintain independent traffic-flow records, leaving employees unable to determine whether a parent or affiliate had changed routes.
These aren't arms-length commercial relationships. They're integrated operations where the US subsidiary is dependent on the same parent entities that China's National Intelligence Law compels to cooperate with state security apparatus.
What comes next
The committee recommends giving federal agencies explicit authority over equipment and network arrangements that survive license revocation, along with targeted removal funding and mandatory logging and routing-protection requirements for foreign-controlled operators. The FCC has already proposed barring Covered List entities from automatic Section 214 authorization and is considering whether to revoke existing approvals, a rulemaking that gained procedural momentum in April 2026, but one that addresses prospective access, not the equipment already sitting in US data centers.
For state CISOs, defense contractors, and anyone whose traffic traverses networks where these carriers maintain interconnection, the report surfaces a risk that most compliance frameworks don't address. CMMC and NIST SP 800-171 don't ask whether your ISP's upstream provider is a state-owned entity whose parent company reports to Beijing. The committee's recommendation to treat core telecom systems as high-risk targets requiring closer oversight suggests that gap may finally get regulatory attention, but Monday morning, the equipment stays.
Published ·Deep Fathom