The Salt Typhoon hack that breached America’s biggest phone carriers had a back door hiding in plain sight. A bipartisan House report has a blunt finding. Three Chinese state-owned carriers, pushed out of the US years ago, never fully left. Their leftover footholds, it says, may have helped keep the hackers’ infrastructure alive.
US regulators denied or revoked the licences of China Telecom, China Mobile and China Unicom between 2019 and 2022. But those orders had a gap, the House Select Committee on China found. They never forced the firms to remove equipment, leave data centres or cut private network links. So the carriers kept enterprise networking, transit and hardware inside American facilities.
The Salt Typhoon thread
Salt Typhoon, uncovered in 2024, was a sweeping Chinese espionage campaign. It breached AT&T, Verizon and Lumen, and reached court-authorised wiretap systems. It targeted senior officials, including then-candidate Donald Trump and Vice President JD Vance.
The committee reviewed routing data from the days the campaign became public. China Mobile International’s network appeared in routes to those servers at least 192 times, Nextgov reported.
The committee is careful about what that proves. It does not allege China Mobile’s US staff knew of or joined the campaign. The routing evidence, it says, is not definitive. But it argues the overlap shows how residual ties could keep malicious infrastructure reachable.
Cloudflare and outside experts verified parts of the analysis.
The gap regulators can’t reach
The exposure ran through data centres and secondary links that fall outside regulators’ reach. The FCC can ban a carrier’s services, but not its hardware, leases or private links. One witness called China Mobile USA “basically a sales team.” Yet the panel counted 143 active network assets in US facilities. About a quarter of China Telecom Americas’ US gear was still made by Huawei.
The response is now taking shape. The FCC is drafting an order to ban Chinese-made data-centre components, an effort we covered last week. It builds on the covered list of firms already barred from US networks. Washington has spent billions ripping out Huawei gear. The committee wants Congress to go further, over the equipment and private deals that survive a revocation.
The hard part
Not everyone buys the fix. China’s embassy said the US “overstretches” national security. Marc Rogers, a telecom-security veteran, agreed with much of the report. But he called expanded rip-and-replace unrealistic, like “bulldozing an entire city and building a new one.” It works only if allies move together, he warned. The three carriers did not respond to requests for comment.
The deeper lesson is structural. A telecom system built on private infrastructure and decades of commercial ties is hard to purge. A ban on a service rarely reaches the equipment behind it. US-China cyber tension is sharpening before a leaders’ summit, and Beijing has answered past US bans in kind. The committee’s message is blunt: the back door was never really closed.
Get the TNW newsletter
Get the most important tech news in your inbox each week.