Skip to content
Technology · Telecom Security · August 5, 2026

Three Chinese Carriers Lost Their U.S. Licenses. A House Investigation Found Their Equipment Never Left the Data Centers.

Between 2019 and 2022, the Federal Communications Commission stripped three Chinese state-owned telecom carriers of their authority to sell service in the United States. A bipartisan House investigation released August 4, 2026 found that those orders never required the companies to unplug anything.

The report — “Stranger Pings: Chinese Telecom Companies Infiltrate U.S. Infrastructure,” roughly 50 pages from the House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party — documents points of presence, leased colocation space, and interconnection agreements that China Telecom Americas, China Mobile USA, and China Unicom Americas kept inside third-party American commercial data centers for years after losing their licenses.

The committee also reviewed four days of routing data from September 2024, when the Salt Typhoon espionage campaign became public, and found one of those carriers’ networks appearing in routes toward addresses U.S. cyber authorities had tied to the campaign. The committee is explicit that this does not definitively link the company to Salt Typhoon. That distinction is the whole story, and it is worth holding onto through every paragraph below.

  • 10 active points of presence China Telecom Americas still maintains across 7 U.S. metro areas, years after the FCC revoked its authorization House Select Committee on the CCP
  • 143 active network assets the committee counted for China Mobile USA, spread across 27 U.S. data-center and interconnection facilities “Stranger Pings,” August 4, 2026
  • ~109,000 incidents in which Chinese or Hong Kong-linked networks improperly claimed U.S. IP address space, January 2018 through May 2025 Committee routing analysis
§ 01 / A License Can Be Revoked. Hardware Doesn't Have to Move.

The FCC’s authority here runs through Section 214 of the Communications Act, which governs who may provide regulated telecommunications service across U.S. borders. When the commission denied China Mobile’s application in 2019 and revoked China Telecom’s and China Unicom’s authorizations in 2021 and 2022, it took away exactly that: permission to sell regulated telecom service. It did not order anyone to pull servers out of a rack, terminate a colocation lease, or dissolve a peering arrangement with an American network.

That is the gap the committee spent more than a year documenting. Stripped of their retail licenses, all three companies stayed in the country doing work that sits outside the FCC’s reach — enterprise networking, internet transit, cloud-adjacent services sold to business customers. None of that requires a Section 214 authorization. The equipment that had carried licensed traffic simply kept running under a different commercial label, in the same buildings, connected to the same American networks.

What the Committee Actually Did

This was not a document review. After the three companies declined to cooperate voluntarily, the committee issued subpoenas, then conducted eight sworn interviews and cross-referenced the subpoenaed records against FCC filings, publicly observable routing data, and independent verification from Cloudflare and outside cybersecurity firms.

It is a bipartisan product. Rep. John Moolenaar (R-MI) chairs the committee; Rep. Ro Khanna (D-CA) is its ranking member. Both signed on to the findings.

§ 02 / What Is Still Inside American Data Centers

The specifics are what make the report land. China Telecom Americas still runs ten active points of presence across seven U.S. metropolitan areas, and roughly a quarter of its American transmission hardware is Huawei-made — equipment from a manufacturer Washington has spent the better part of a decade trying to remove from domestic networks. China Unicom Americas maintains equipment and connections inside about ten U.S. data centers, and the committee reports that seven of its eight directors and two of its three senior managers are members of the Chinese Communist Party.

The access point looked ordinary. That was the whole design. — Civic Intelligence illustration
What Each Carrier Still Has Inside U.S. Facilities
Source: “Stranger Pings,” House Select Committee on the CCP, August 4, 2026
China Telecom Americas
FCC revoked its Section 214 authority in October 2021
  • 10 active points of presence across 7 U.S. metro areas
  • Roughly 25% of its U.S. transmission hardware is Huawei-made
China Mobile USA / China Mobile International
FCC denied its U.S. entry application in May 2019
  • 39 point-of-presence entries across 27 U.S. data-center and interconnection facilities
  • At least 143 active network assets; the report describes the U.S. entity as “basically a sales team” with no network engineers on U.S. soil
China Unicom Americas
FCC revoked its authority in January 2022
  • Equipment and connections inside roughly 10 U.S. data centers
  • 7 of 8 directors and 2 of 3 senior managers are CCP members, per the report
Note: the FCC actions above removed each company’s authority to sell regulated telecom service. None of them required removing hardware or vacating leased space.

China Mobile is the strangest entry. The committee counted 39 point-of-presence entries across 27 U.S. data-center and interconnection facilities and at least 143 active network assets — and then found that the American entity operating all of it is, in the report’s phrase, “basically a sales team,” with no network engineers on U.S. soil at all. Whoever is configuring that hardware is doing it from somewhere else.

Fox Business · Chinese state carriers and the funneling of U.S. network traffic
§ 03 / The Salt Typhoon Question, Stated Precisely

Salt Typhoon is not new and is not this report’s discovery. The Chinese state-linked espionage campaign, attributed by U.S. authorities to actors tied to China’s Ministry of State Security, became public in the fall of 2024 after breaching AT&T, Verizon, Lumen, and T-Mobile, reaching into the lawful-intercept systems American carriers maintain under CALEA, and — according to reporting at the time — accessing communications metadata tied to senior political figures, including then-candidate Donald Trump and running mate JD Vance during the 2024 campaign, well before the inauguration.

BBC News · Inside China's most ambitious cyber hack

What the House committee adds is narrower and more technical. Reviewing routing data from September 22 through 25, 2024 — the days the campaign surfaced publicly — investigators found China Mobile International’s network appearing in routes toward 58 groups of IP addresses that CISA had linked to Salt Typhoon command-and-control servers. It appeared at least 192 times across those four days.

Read This Part Carefully

The committee’s own language is the ceiling on what anyone can claim from this finding: the routing analysis “does not definitively link” China Mobile to Salt Typhoon. The report does not allege that China Mobile USA employees knew about the campaign or participated in it.

What the report argues is a pathway, not an act: that retained footholds inside U.S. data centers gave Beijing-linked infrastructure routine, largely unmonitored routes through American networks — the kind of access that could help sustain an operation like Salt Typhoon, whether or not it did.

No U.S. data center was reported hacked in this document. That is a different claim, and the committee did not make it.

X
House Select Committee on the CCP
@ChinaSelect · August 4, 2026· paraphrase

New Select Committee report — “Stranger Pings: Chinese Telecom Companies Infiltrate U.S. Infrastructure” — details how Chinese state-owned telecom firms retained access to U.S. networks and data centers even after federal regulators moved against them.

U.S.-based subsidiaries of Chinese telecommunications companies are beholden to the CCP, and they are a threat to all of us.

Rep. John Moolenaar (R-MI) · Chairman, House Select Committee on the CCP

Rep. Ro Khanna (D-CA), the committee’s ranking member, framed the finding in oversight terms rather than alarm: “This report shows the importance of continued oversight of PRC-linked telecommunications companies operating in the U.S.” The FBI, CISA, and other intelligence agencies declined to comment on the report.

§ 04 / 109,000 Claims on Address Space That Wasn't Theirs

The report’s broadest finding has nothing to do with any single company’s data-center lease. The internet routes traffic using the Border Gateway Protocol, a system built on the assumption that networks tell the truth about which addresses they control. There is no enforcement layer. If a network announces that it owns a block of addresses, its neighbors generally believe it and send traffic that way.

Analyzing announcements from January 2018 through May 2025, the committee counted roughly 109,000 incidents in which Chinese or Hong Kong-linked networks improperly claimed U.S. IP address space. More than 4,200 of those involved networks controlled by China Mobile specifically. Most BGP errors are exactly that — fat-fingered configurations that get corrected in minutes. At that volume, over that span, the committee treats the pattern as a systemic exposure regardless of intent behind any individual announcement.

§ 05 / What the Committee Wants, and Why It Is Hard

The recommendations follow directly from the gap. The committee wants federal agencies given explicit authority to compel physical removal of equipment after a license is revoked, and dedicated federal funding to pay for that removal. It wants BGP routing protections strengthened, logging and monitoring requirements imposed on foreign-controlled network operators, and tighter rules on foreign-made transmission equipment of the kind that still makes up a quarter of one carrier’s U.S. hardware.

China's state telecommunications carriers for too long have enjoyed non-reciprocal access to U.S. domestic networks, but the seriousness of Salt Typhoon gives the FCC and other agencies more than enough justification to restrict or expel them.

James Mulvenon · VP of Intelligence, Pamir Consulting

The counterargument is cost. Telecom security consultant Marc Rogers calls a full rip-and-replace of foreign-made gear from American networks “economically unrealistic,” comparing it to “bulldozing an entire city and building a new one.” That tension is the practical shape of the problem: the committee has documented a hole that everyone can now see, and the cheapest fix — writing removal authority into the next revocation order — only helps going forward. The equipment already in the racks is a harder bill.

Bottom Line

A bipartisan House investigation found that three Chinese state-owned carriers kept equipment, leased space, and network connections inside U.S. data centers years after federal regulators revoked their licenses — because the revocation orders never required them to leave. The committee found routing evidence suggesting those footholds could have offered a pathway that helped sustain the Salt Typhoon espionage campaign, and said plainly that the evidence does not definitively link any of the three companies to it. The proven finding is the regulatory gap. The Salt Typhoon link is a documented possibility, not a documented fact, and this page will not report it as one.

Sources & Methodology · 10 Sources
08
Congressional Research Service (primary, background)·CRS In Focus product on Salt Typhoon and the telecommunications intrusions
Methodology and a deliberate limit on this story: the House Select Committee’s routing findings are circumstantial. The committee itself writes that its September 2024 routing analysis “does not definitively link” China Mobile to the Salt Typhoon campaign, and the report does not allege that China Mobile USA employees knew about or participated in it. Civic Intelligence reports that finding exactly as the committee framed it — as a documented pathway, not a proven act. Nothing in this report establishes that U.S. data centers were themselves hacked, and no headline on this page should be read that way. The Bloomberg piece that first carried the story sits behind a subscriber paywall; the underlying facts here are drawn from the committee’s own published report and from four non-paywalled secondary accounts that independently describe the same figures. The FBI, CISA, and other intelligence agencies declined to comment on the report, so no agency reaction is quoted. This is a non-partisan national-security and technology story on the site’s AI beat; both the chairman and ranking member of the investigating committee are quoted, and Truth Social is omitted because no administration post specific to this report was found. Only one verified X post is embedded rather than the site’s usual two-or-more: a second candidate post could not be independently confirmed against the live API, so this page ships with a disclosed one-post gap rather than an unverified second citation.