US telecommunications companies connected their networks to data centers and related infrastructure in ways that exposed them to cybersecurity risk, according to a House committee report. Those links may have helped create the conditions for the Salt Typhoon hacking campaign, which breached several mobile carriers in 2024.
The House Select Committee on China said telecom networks had routine pathways to equipment and data centers that may have tied back to three Chinese telecommunications firms barred from operating directly in the US.
Those connections created exposure between US carriers and infrastructure targeted by Salt Typhoon, the Chinese hacking group linked to the campaign, according to Bloomberg.
The Federal Communications Commission had barred China Telecom Corp., China Mobile International and China Unicom from direct connections to US networks. The committee said the companies still used regulatory gaps to keep a physical presence in the American market.
That gap left Chinese state-owned carriers embedded in the US internet system after regulators had already identified their exposure to Chinese Communist Party influence, according to the committee.
US intelligence officials in 2024 accused Salt Typhoon of a wide cyberespionage campaign against several US telecom companies. The group targeted call records and communications linked to a limited number of people in government and politics, including then-presidential candidate Donald Trump.
AT&T, Verizon and Lumen Technologies have acknowledged Salt Typhoon breaches. T-Mobile said suspicious behavior on network devices alerted the company to an attempted breach, according to Beinsure.
The House panel described Salt Typhoon as an attempt to turn the basic architecture of carrier networks into an attack surface.
The report focuses on secondary telecom connections. These links sit outside the primary carrier network but still connect telecom operators to the wider internet infrastructure.
According to the committee, US operators were not aware of the cybersecurity risks created by those connections.
Representative John Moolenaar, the committee’s Republican chairman, said the situation leaves the US exposed to state-sponsored cyberattacks from China. He said Chinese subsidiaries should be cut out of domestic infrastructure to protect Americans.
The findings matter because the government does not directly regulate telecom carriers’ commercial relationships with data centers. US rules instead restrict carriers from using networking equipment made by certain Chinese companies inside US telecom networks.
Washington has already spent bn through rip-and-replace programs to remove components from Chinese manufacturers such as Huawei Technologies.
The committee’s report suggests the next risk area sits deeper in the carrier-data center relationship, where equipment, services and network access do not always fall under the same rules, according to Reuters.
The FCC is drafting an order to ban Chinese-made data center components, according to a person familiar with the matter. The agency is also reviewing other steps to stop blacklisted China-based companies from connecting to US networks, the committee said.
The FCC had already opened a preliminary rulemaking in April that points toward tighter restrictions on foreign access to data centers.
The rulemaking focuses on companies already barred from US operations and sales under the FCC’s covered list, including China Mobile, China Unicom, Huawei and ZTE.









