House Probe Finds Persistent Risks from Chinese Telecoms

House Probe Finds Persistent Risks from Chinese Telecoms

Donald Gainsborough stands as a preeminent figure in the realm of national security, bringing years of seasoned expertise in legislative strategy and policy leadership to the forefront of the conversation. As the driving force behind Government Curated, he has navigated the complex corridors of power to influence how the United States defends its digital and physical borders against increasingly sophisticated adversaries. This conversation delves into the unsettling findings of a recent bipartisan House China Committee investigation, which exposes the persistent and dangerous presence of state-owned Chinese telecommunications firms within the American infrastructure. We examine the regulatory failures that allowed these companies to retain their physical footholds long after their licenses were revoked, the chilling implications of the “Salt Typhoon” espionage campaign, and the sheer technical difficulty of purging high-risk hardware from a deeply integrated global network. Through this dialogue, Gainsborough sheds light on the invisible vulnerabilities within our data centers and the urgent need for a more cohesive, international approach to securing the backbone of modern communication.

Even after regulators revoke service authorizations, physical equipment and data center leases often remain active. How does this persistent physical presence undermine the national security objectives originally intended by the FCC’s bans?

The reality uncovered by this 50-page investigation is that a regulatory ban on paper does not equate to a physical removal on the ground. When the FCC revoked the authorizations for China Telecom, China Mobile, and China Unicom between 2019 and 2022, the intent was to sever the influence of the Chinese state over our domestic traffic, yet the “plumbing” of these networks remained largely intact. These companies continued to occupy physical data center space and maintain private network links, which effectively allowed them to function as a “shadow” infrastructure within our borders. This persistence provides Beijing’s intelligence services with a front-row seat to sensitive American data traffic, creating a sensory-rich environment for cyberspies to monitor, intercept, and potentially reroute information. By maintaining equipment in at least ten active points of presence across seven major U.S. metropolitan areas, China Telecom Americas, for instance, ensures that its hardware—roughly a quarter of which is still made by Huawei—stays connected to the very heart of our digital economy. This isn’t just a technical oversight; it is a profound gap in our defensive posture that allows malicious actors to keep their infrastructure reachable even as our federal agencies attempt to shut them down.

The “Salt Typhoon” campaign has been described as a major breach of U.S. telecommunications. In what ways do the remaining network ties of companies like China Mobile International facilitate such high-level espionage?

The Salt Typhoon campaign represents a haunting escalation in cyber espionage, where hackers didn’t just steal data but actually sat inside the systems used for court-authorized wiretaps. During a critical window in September 2024, right as the campaign was coming to light, routing data showed that China Mobile International’s network appeared in routes to known Salt Typhoon servers at least 192 times. This wasn’t a mere coincidence; these network ties acted as a vital lifeline, keeping the attackers’ infrastructure reachable and operational while U.S. defenders were actively trying to sever those connections. The emotional weight of knowing that the communications of high-ranking officials, including President Donald Trump and Vice President JD Vance, were potentially compromised through the very systems meant to uphold the law is staggering. It demonstrates how these “carrier backbones” and private network arrangements can be weaponized to sustain a campaign that targets the highest levels of our government. Even if the local employees weren’t complicit, the sheer technical proximity of their parent companies’ networks created a sanctuary for state-sponsored hackers to maneuver.

Your analysis often touches on the “human element” of these subsidiaries. What does it reveal about the chain of command when U.S.-based employees are using parent-controlled systems and emails?

When you peel back the layers of these American subsidiaries, you find a structure that is almost entirely beholden to Beijing, leaving very little room for independent U.S. oversight. At China Unicom Americas, the fact that seven of the eight directors and two of the three senior managers are members of the Chinese Communist Party speaks volumes about where their true loyalties lie. Witnesses described China Mobile USA as “basically a sales team” with no actual network engineers on-site, meaning that every technical decision and every routing change is directed from headquarters in Hong Kong or Beijing. This creates a dangerous lack of transparency; for example, U.S. employees at China Telecom Americas admitted they couldn’t even keep independent traffic-flow records, leaving them blind to whether their parent company was altering data routes through U.S.-based equipment. This centralized control is reinforced by the use of parent-controlled email systems and cybersecurity policies dictated by the home office, ensuring that the subsidiary remains a mere extension of the Chinese state. When a compliance official admits they can guarantee their own adherence to U.S. law but cannot speak for their parent company, it highlights a terrifying jurisdictional vacuum.

There is a significant debate regarding the “rip-and-replace” strategy for legacy equipment. What are the operational and economic realities that make “bulldozing the city,” so to speak, such a daunting task for the industry?

The “rip-and-replace” strategy is a classic example of a policy that sounds impeccable on a whiteboard but faces a brutal reality in the field. To truly remove every piece of high-risk hardware, you are essentially talking about an industrial-scale excavation of our existing telecommunications architecture, which some experts have likened to bulldozing an entire city just to rebuild it from scratch. We are looking at a situation where China Telecom alone has identified ten points of presence, and China Mobile has 39 entries across 27 different data centers, involving at least 143 active network assets that are woven into the fabric of U.S. internet exchanges. Forcing carriers to tear out this equipment—much of it deeply integrated into the backbone of private networks used by major technology firms—could lead to massive service disruptions and eye-watering costs that the current funding simply doesn’t cover. There is a palpable tension between the urgent need for national security and the economic survival of the operators who must manage these complex transitions. Without a massive, coordinated influx of federal resources and a realistic timeline, we risk creating more instability in our infrastructure than the very threats we are trying to mitigate.

The investigation highlighted relationships with shadowy entities like CloudRadium and i-SOON. How do these “middleman” arrangements complicate the task of identifying and mitigating state-sponsored hacking?

The use of middlemen and front companies is a masterful tactic that allows state-sponsored actors to hide in plain sight, making the job of attribution nearly impossible for U.S. investigators. A perfect example is China Mobile purchasing data center space and network connections on behalf of CloudRadium, a hosting provider linked to repeated malicious activity, through a contract valued at $480,000. These layers of corporate separation allow entities like the Integrity Technology Group or i-SOON to operate under the radar, even as they provide the “control layer” for botnets that compromise thousands of American routers. The DOJ’s charges against eight i-SOON employees for working with 43 different intelligence and police bureaus show the sheer scale of this ecosystem, yet these companies often share logos, layouts, and even personnel with seemingly legitimate U.S. corporations like GlobalData Investments. This shell game turns our own commercial infrastructure against us, as Chinese carriers facilitate the presence of hackers on U.S. soil under the guise of routine business transactions. It forces our security agencies to play a perpetual game of “whack-a-mole” where the adversary is always three or four corporate layers removed from the actual intrusion.

Looking at the 109,000 incidents of unauthorized internet address claims since 2018, how concerned should we be about the Border Gateway Protocol (BGP) as a vector for state-sponsored data diversion?

The vulnerability of the Border Gateway Protocol is perhaps the most overlooked “engine room” issue in national security, yet the scale of the problem is astronomical. Between January 2018 and May 2025, investigators identified nearly 109,000 incidents where Chinese or Hong Kong-linked networks allegedly claimed U.S. internet addresses without any authorization. While some of these might be attributed to poor management, over 4,200 of these “high-confidence hijacks” involved China Mobile-controlled networks, which can effectively divert American data through foreign systems for inspection or modification. Under China’s 2017 National Intelligence Law, these companies are legally compelled to assist in state espionage, meaning every hijacked route is a potential intelligence windfall for Beijing. The sensory experience of a “hijack” is invisible to the average user, but for a national security expert, it feels like a silent redirection of a massive digital pipeline. If we do not implement stronger routing protections and logging requirements, we are essentially leaving the “master keys” to our network traffic in the hands of an adversary that has shown no hesitation in using them.

What is your forecast for the future of U.S. telecommunications security given these persistent vulnerabilities?

My forecast is that we are entering a period of “forced decoupling” that will be both painful and necessary, as the era of blind trust in globalized infrastructure comes to a definitive end. I expect to see the federal government move beyond simple license revocations and toward a much more aggressive, “entity-based” approach that targets the actual physical leases and equipment arrangements that have allowed these carriers to linger. We will likely see a significant expansion of the FCC’s authority to mandate the removal of hardware from private data centers, backed by a new wave of “targeted removal” funding that acknowledges the economic burden on domestic providers. However, this will only be effective if we coordinate with our international allies; if the U.S. is the only country to “bulldoze the city,” China will simply maneuver its traffic through other hubs in Europe or Asia. Ultimately, the battle for telecom security will move from the courtroom to the server room, where the implementation of “zero-trust” routing and mandatory traffic logging will become the new standard for anyone operating within our borders. We are finally waking up to the reality that a digital border is only as strong as the physical hardware that supports it, and the next few years will be defined by our willingness to pay the high price for true technological sovereignty.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later