NatSec Noir

Tech and geopolitics out of the shadows

Newsletter·RSS·About
Record · Congress

Stranger Pings: Chinese Telecom Companies Infiltrate US Infrastructure

The report concludes that FCC denials and revocations of the three PRC state-controlled carriers’ Section 214 authority did not remove their U.S. infrastructure, network relationships, or parent-controlled routing access, leaving a distinct national-security risk.

Docket
NA
Issuing body
Congress
Document date
2026-08-04
Entered
2026-09-12
Lists
Covered ListTeam Telecom1260HICTS

What it does It presents findings from congressional document requests, subpoenas, sworn interviews, routing records, federal records, and network scans concerning China Telecom (Americas), China Mobile International (USA), and China Unicom (Americas). It describes parent direction of U.S. subsidiaries; retained points of presence, colocation, equipment, interconnection, and IP-transit arrangements; Chinese-manufactured hardware; trusted routing identities; and China Unicom’s acceptable-use terms. It also examines BGP incidents and case studies involving Qihoo 360, CloudRadium, and Integrity Technology Group. The report recommends legislation expanding FCC, Team Telecom, and Commerce ICTS authority, entity-specific Covered List determinations, targeted removal or mitigation, routing-security measures, and interim logging.

Who it affects The findings concern the three carriers and their PRC or Hong Kong parents, U.S. telecommunications and internet-infrastructure operators, enterprise customers, and federal agencies responsible for communications and national security.

Why it matters The report identifies a gap between licensing remedies and control of physical and logical internet infrastructure. It argues that retained U.S. assets and parent-linked routing can preserve access, obscure activity, and expose American traffic even after Section 214 action.

Key dates and numbers

  • FCC Section 214 actions occurred from 2019 through 2022.
  • The investigation began March 5, 2025; subpoenas issued April 23, 2025.
  • The report identifies 108,891 high-confidence BGP hijack events affecting at least 477 U.S. networks from January 2018 through May 2025.
  • It documents 10 CTA points of presence, 39 CMI USA entries across 27 facilities, and up to 1,380 Gbps of CMI USA capacity.
Approved 2026-09-15 · published 2026-09-12