US House Report: Chinese Telecommunications Companies Remain Deeply Embedded in American Networks

The U.S. House Select Committee on the CCP released a bipartisan investigation report on Tuesday, August 4, exposing how despite having their telecommunications authorizations refused or revoked, China’s three major state-owned telecom companies continue to exploit regulatory loopholes to deeply penetrate critical U.S. communication infrastructure.

The 49-page report, titled “Stranger Pings: The Threat of CCP-Controlled Infrastructure in the U.S. Communications Backbone”, alludes to the popular American TV series “Stranger Things”.

After months of investigation, the committee highlighted that while the Federal Communications Commission (FCC) has denied or revoked the telecommunications authorizations of China Telecom, China Mobile, and China Unicom’s U.S. subsidiaries, current laws only prohibit these Chinese-owned telecom companies from selling regulated retail services, but do not mandate the removal of physical equipment or termination of network connections.

Committee Chair John Moolenaar emphasized, “The U.S. subsidiaries of Chinese telecom companies, controlled by the CCP, pose a threat to all of us.”

“They require U.S. customers to agree to review information in accordance with Chinese laws and undermine our reliance on domestic network infrastructure. All of this makes us vulnerable to attacks from America’s biggest adversaries, a new wave of state-sponsored cyberattacks,” he added.

The investigation found that while the FCC had previously denied or revoked the three companies’ authorizations under Section 214 of the Communications Act, which restricts them from providing regulated telecommunications services, Section 214 essentially serves as a service authorization tool and does not mandate the removal of hardware, data center exits, or network terminations.

The report likened this to a transportation company losing a public carrier license but still having full ownership of physical warehouses, trucks parked inside with engines idling, and the ability to freely use the same batch of assets to fulfill unregulated private logistics contracts.

Subsequently, the three companies shifted their operations towards less regulated fields such as IP transmission, data center hosting, enterprise networking, and system integration, continuing to operate at critical internet nodes in the U.S.

China Telecom Americas maintains 10 active Points of Presence (PoP) in seven metropolitan areas across the U.S., including Ashburn, Chicago, Los Angeles, New York, and San Jose. China Mobile International USA has records of 39 U.S. PoPs located in 27 data centers and interconnection facilities, with a total network capacity of up to 1,380 Gbps.

China Unicom Americas Operations also retains data center equipment, cabinets, power configurations, and cross-connect circuits in Ashburn, Chicago, Dallas, Los Angeles, Miami, New York, and Seattle, and maintains interconnections with major U.S. backbone network providers.

Through sworn testimonies and internal documents, the investigation found that these U.S. subsidiaries are not operating independently. Core routing, service activations, customer information, fault resolution, and compliance systems are still to varying degrees reliant on their parent and affiliated companies in mainland China or Hong Kong.

In a crucial interview, a compliance officer from a China Unicom subsidiary admitted, “We cannot guarantee that affiliated companies, especially China Unicom International (CUG), will comply with U.S. law.”

Additionally, China Unicom Americas included mandatory “Acceptable Use Policies” (AUP) in contracts signed with American companies, prohibiting the dissemination of politically sensitive news violating Chinese laws, information violating national security laws of China, or information violating “social order and stability.”

Moolenaar stated, “We must eliminate these subsidiaries from the U.S. domestic infrastructure to protect the American people.”

At a technical level, the report revealed a set of concerning data.

From January 2018 to the end of May 2025, the committee recorded over 108,000 high-confidence Border Gateway Protocol (BGP) hijacking incidents involving at least 477 U.S. networks. These anomalies could lead to U.S. traffic being diverted to networks in mainland China and Hong Kong, exposing them to monitoring, replication, or tampering risks.

The report compared BGP hijacking to setting up false road signs on a highway. Once data is directed onto abnormal paths, it could be replicated, monitored, or stored before being forwarded to the original destination, often difficult for users to detect.

The committee stressed that not all incidents were intentional attacks, with some stemming from misconfigurations or mismanagement. However, the report found that some abnormal routing activities overlapped in time with CCP-backed network attacks.

For instance, during the “Salt Typhoon” in September 2024, China Mobile International’s network appeared in valid routing paths to 58 attacking servers at least 192 times. The report suggested that such structural risks could provide Beijing with long-term, unsupervised passive surveillance opportunities.

Committee Democratic Chief Member Ro Khanna pointed out that given recent cyber activities from the CCP, this report underscores the critical importance of “ongoing oversight of telecom companies operating in the U.S. that have ties to the People’s Republic of China.”

He urged Congress to ensure that agencies responsible for protecting communication networks have sufficient resources to address potential threats.

Addressing this security gap, the committee proposed six policy recommendations, including:

1. Prohibiting high-risk enterprises from using blanket Section 214 authorizations and limiting their interconnection with U.S. telecom companies.
2. Granting the government the authority to handle residual equipment and networks after revocation.
3. Including private contracts such as data center leasing, IP transmission, and remote management in national security reviews.
4. Enhancing the FCC’s “covered list” and funding the “removal and replacement” of high-risk equipment.
5. Establishing common BGP route security standards with allies.
6. Mandating log retention, monitoring anomalies, and record preservation before equipment removal or risk mitigation.