A 49-page report, a subpoena fight, and a stubborn question
Three Chinese state-owned telecom giants still have a quiet but real presence inside America’s internet backbone, years after federal regulators pulled their licenses over cybersecurity fears. That’s the blunt conclusion of a new bipartisan investigation from the House Select Committee on China, released Tuesday.
The 49-page report focuses on China Mobile, China Unicom, and China Telecom — companies that lost or were denied Section 214 authorization by the FCC between 2019 and 2022. That authority is what lets foreign carriers provide international telecommunications services in the U.S. Losing it was supposed to be a near-fatal blow.
It wasn’t.
Committee investigators subpoenaed all three firms, conducted eight interviews with company officials in September 2025, and pored over technical data tied to the Salt Typhoon hacking campaign, which breached at least nine U.S. telecom companies. Their finding: the license revocations limited what these carriers could do, but never forced them to pull equipment out of American networks or sever business ties with U.S. partners.
What the FCC actions actually accomplished
The report gives the FCC credit for moving against the carriers. But it argues the agency’s actions left a glaring loophole: nothing required the companies to shut down physical operations or dismantle hardware already sitting inside U.S. infrastructure.
Instead, all three “quietly obtained or retained hardware, interconnection agreements, and data center footholds that served as their ‘trusted’ backdoors,” the report states. They pivoted into less-regulated network services — managing VPNs, brokering third-party equipment, renting space at U.S. facilities, and routing customer data across the globe.
In other words, they rebuilt their U.S. businesses around services that sit outside the core Section 214 framework. The committee says that preserved their operational footing at critical nodes of the U.S. internet.
Ownership chains that lead straight to Beijing
The investigation traces each company’s corporate structure upward. Every one of them sits at the bottom of an ownership chain running through Hong Kong and offshore holding companies to a Chinese state-owned enterprise, all overseen by China’s State-owned Assets Supervision and Administration Commission (SASAC).
The committee’s conclusion is blunt: none of these firms are independent from their parent companies, and those parents have deep ties to the Chinese government. The report also notes that Chinese-manufactured equipment from firms subject to PRC legal obligations — which can compel cooperation with state security services — is still running inside U.S. networks.
Chairman John Moolenaar (R-MI) put it in stark terms. “These companies are a threat to all of us,” he said in a statement. “They poison the domestic cyber infrastructure we rely on.”
Salt Typhoon links and a decade of routing incidents
The report doesn’t stop at structural analysis. It connects the three carriers to a string of cybersecurity incidents stretching back years.
China Telecom and other state-backed carriers were tied to several large-scale internet routing incidents where U.S. government and private-sector traffic was misrouted to PRC-controlled networks. Some may have been accidents. But the Justice Department and other agencies concluded that multiple incidents were intended to expose data to interception or alteration, according to the study.
On Salt Typhoon specifically, the committee stopped short of saying China Mobile directly participated. But it found technical data tying the hacking incidents to the company’s infrastructure.
China Unicom’s links are more concrete. The report says the company has verified connections to Integrity Tech, a firm sanctioned by the U.S. and accused of direct involvement in state-sponsored hacking. China Unicom is also a corporate partner of i-SOON, another Chinese cybersecurity company the U.S. government has accused of running hacking campaigns.
Interviews that went nowhere
The committee’s outreach to the companies themselves didn’t exactly yield candor. Officials initially didn’t respond to voluntary requests, and the Chinese government condemned the subpoenas outright.
When interviews finally happened in September 2025, results were mixed. Some officials answered questions. Others refused to acknowledge even basic facts about their employers. None of those interviewed would admit to reading news reports about the Salt Typhoon incidents.
That’s a remarkable detail, and the committee clearly intends it as one.
What Congress should do next
The report lands with a set of recommendations aimed at closing the gaps the FCC couldn’t. It urges Congress to expand the FCC’s authority to limit these companies’ operations, and to force a “rip-and-replace” of technology from China Mobile, China Unicom, and China Telecom wherever it remains in U.S. networks.
It also calls for more funding for federal agencies to hire technical experts who actually understand cyber threats at the network level — a recurring weakness in government cybersecurity hiring.
Rep. Ro Khanna (D-CA), the committee’s ranking member, framed the stakes in terms of data protection. The report, he said, highlights the need for Congress to “address risks to Americans’ data and ensure that the agencies responsible for securing our communications networks have the resources they need to respond to potential threats.”
The question now is whether the FCC’s next move will be stronger — or whether the carriers will find yet another way to stay embedded. For more on how these threats evolve, see our analysis of state-sponsored cyberattack trends and telecom network security best practices.