Editor’s Note: A bipartisan House report found three Chinese state-owned carriers, their Section 214 authorizations denied or revoked, still holding equipment, data-center space and interconnection ties inside U.S. networks; within a day, China’s embassy had objected and party-state media had recast the findings as politicized and lacking technical evidence. That collision is the durable story, because the finding and the pushback now travel together: every attribution that reaches a boardroom, a breach notification or a claims file arrives pre-contested.
For cybersecurity teams, the report maps exposure living in the interconnection layer rather than the perimeter. For privacy and compliance professionals, its six recommendations sketch codified FCC and interagency authorities, funded removal mandates and interim logging duties would begin generating new record sets if enacted and implemented. For eDiscovery professionals, the committee’s own method, subpoenaed records, sworn interviews and routing telemetry, previews the evidence stack downstream litigation could demand.
Watch whether the FCC’s proposed optical-transceiver measure advances, whether appropriators fund an expanded rip-and-replace and whether enterprise customers start asking, in writing, which facilities their traffic transits.
Content Assessment: Beijing contests House Salt Typhoon report as Congress weighs a wider cleanup
Information - 92%
Insight - 90%
Relevance - 90%
Objectivity - 92%
Authority - 91%
91%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Beijing contests House Salt Typhoon report as Congress weighs a wider cleanup."
Industry News – Cybersecurity Beat
Beijing contests House Salt Typhoon report as Congress weighs a wider cleanup
ComplexDiscovery Staff
Beijing’s answer to the House’s Salt Typhoon investigation arrived within a day, and it was to put the report itself on trial.
The Communist Party-affiliated Global Times and two analysts it quoted dismissed the bipartisan findings Aug. 5 as politicized and technically unsupported. The report, released Aug. 4, found that three Chinese state-owned carriers whose Section 214 service authorizations were denied or revoked years ago never fully left U.S. networks. It asks Congress to move in the opposite direction: codify Federal Communications Commission authority over Chinese carrier infrastructure, fund an expanded rip-and-replace effort and require logging of whatever stays behind.
Salt Typhoon is the espionage campaign that reached at least nine U.S. telecommunications companies and that U.S. agencies attribute to Chinese state-linked actors. The report it prompted frames two questions practitioners will live with long after this news cycle closes. Who gets believed when an accused state’s officials and media contest the findings? And what records get created, kept and eventually produced if Congress orders foreign equipment out of American networks?
What the committee says never left
The House Select Committee on the Chinese Communist Party released its report Aug. 4, the product of an investigation launched after a March 2025 hearing on Beijing’s Typhoon campaigns. The findings rest on subpoenaed corporate records, eight sworn interviews, federal records, routing data and network infrastructure scans. Subpoenas went out in April 2025 after China Telecom, China Mobile and China Unicom declined to answer a bipartisan information request.
The FCC denied or revoked the three state-owned carriers’ Section 214 authorizations to provide U.S. telecommunications services between 2019 and 2022. The committee found the FCC actions reached services, not presence. China Telecom’s U.S. subsidiary kept 10 active points of presence in seven metropolitan areas, with about 25 percent of its U.S. transmission hardware made by Huawei, according to the report. China Mobile’s U.S. arm held 39 point-of-presence entries in 27 facilities and at least 143 active network assets. China Unicom kept equipment and connections in roughly 10 U.S. data centers.
Routing data supplied the report’s most specific technical evidence: time-bounded route observations tied to identified server infrastructure. The report’s routing analysis ran checks every eight hours from Sept. 22 through 25, 2024, across 58 internet prefixes linked to Salt Typhoon attacker servers confirmed by the Cybersecurity and Infrastructure Security Agency, and it found China Mobile International’s network in active routing paths to those servers at least 192 times across a window that overlapped the campaign’s first public reporting. AT&T, Verizon and Lumen have acknowledged being hit by the campaign, and T-Mobile has said suspicious behavior on its network devices tipped it off to an attempted breach, Bloomberg reported. The committee said the routing overlap shows how residual network ties could help sustain malicious infrastructure. It did not allege that employees of the Chinese carriers knew of or participated in the campaign, and Bloomberg reported the committee concluded the U.S. operators were unaware of the cybersecurity risks from these connections. Using what it described as a high-confidence methodology, the report counted 108,891 Border Gateway Protocol hijack events between January 2018 and May 2025 in which carrier networks associated with China or Hong Kong announced U.S. internet address space without authorization. It identified 4,213 high-confidence anomalies or hijacks involving four China Mobile-controlled networks, while acknowledging that some anomalies may reflect aggressive routing, configuration errors or poor management.
Chairman John Moolenaar, R-Mich., said the U.S. subsidiaries answer to the Chinese Communist Party and called for removing them from domestic infrastructure. Ranking Member Ro Khanna, D-Calif., said Congress should keep addressing risks to Americans’ data and ensure the agencies that secure U.S. communications networks have the resources to respond.
Beijing’s rebuttal follows a familiar script
The pushback came through two channels. A spokesperson for China’s embassy in Washington said Beijing firmly opposes what it considers an overstretched concept of national security and would defend Chinese companies’ rights and interests, according to Nextgov/FCW, which first reported the footprint findings. The three carriers did not respond to the outlet’s requests for comment. The Global Times commentary, published Aug. 5, described the report as politicizing cybersecurity while lacking technical evidence.
Li Yan, who directs the technology and cybersecurity institute at the China Institutes of Contemporary International Relations, a state-run research organization in Beijing, argued the report ties the carriers’ remaining connections to Salt Typhoon without demonstrating a causal relationship. He pointed to published analyses from Cisco Talos, Microsoft and Singapore’s Infocomm Media Development Authority that he said found no technical evidence Chinese carrier infrastructure served as a stepping stone for the attacks, and he faulted the report for resting on hedged words such as may, could and potential. Ma Jihua, a telecommunications industry analyst, told the outlet that full separation of the U.S. and Chinese telecom sectors remains unrealistic on commercial grounds.
The hedges Li attacked are common phrasing in infrastructure forensics. Congressional investigators described network proximity and routing behavior, not proven operational control, and the committee itself said it does not allege employee participation. That restraint is what careful analysis looks like. It is also precisely the seam that state-level pushback exploits.
Contested attribution reaches the claims file
For practitioners the dispute is anything but abstract. Chinese officials and state media have contested U.S. cyber attribution before; the Foreign Ministry dismissed allied Salt Typhoon findings as disinformation in September 2025. Nor is this the only live attribution fight: the same week the report landed, the FBI was investigating a multistate intrusion campaign against water utilities that researchers link to Iranian-backed hackers. When an accused state contests a finding, every downstream document that assumes the attribution, from board briefings to breach notifications to insurance submissions, inherits an adversarial audience.
Insurance is one arena where that inheritance carries a price. War and state-action exclusions turn on whether conduct is attributable to a sovereign, an issue litigated through Merck’s NotPetya coverage fight, which ended in a settlement in 2024, and embedded in the state-backed cyberattack exclusions Lloyd’s of London has required in cyber policies since 2023. Official Chinese objections do not defeat attribution, but they keep the question contested in any coverage dispute where an insurer invokes state action. The unglamorous moves follow from that: review war-exclusion and state-action language at renewal, assume incident narratives drafted today will be read against a contested attribution record in discovery tomorrow, and preserve the attribution evidence chain, from agency advisories to forensic findings, as a record set of its own.
Rip-and-replace would leave a paper trail
The report’s six recommendations read like a records-management program for the U.S. network edge. The committee asks Congress to codify the FCC’s authority to deny blanket authorizations and restrict domestic interconnection, to establish statutory authority over retained foreign-adversary infrastructure, and to widen the jurisdiction of Team Telecom and the government’s information and communications technology and services (ICTS) authorities over private commercial arrangements. It also calls for entity-specific Covered List determinations backed by targeted rip-and-replace funding, financed routing-security enforcement and mandatory interim logging, monitoring and record-preservation obligations until covered infrastructure is removed or mitigated.
Every one of those measures generates records. Procurement files, replacement schedules, extension requests, interim risk acceptances and the mandated logs themselves could become subject to discovery, where relevant and proportional to the claims and defenses, once a carrier or its enterprise customers face litigation over a downstream breach. The committee’s own method shows how such a file gets built: subpoenaed commercial records, interviews under oath and routing telemetry, assembled into findings. Depending on the claims and the facts, civil litigants pursuing a downstream breach could seek comparable categories of evidence from carriers, facility operators and their customers. The existing program shows how long the trail runs. As of the FCC’s June 15 report to Congress, recipients had filed final certifications, attesting completed removal and replacement, for 53 of 126 Priority 1 applications, about 42 percent, while only 12 applications had cleared the program’s separate closeout process; most remaining recipients received limited deadline extensions. Congress first funded the Huawei- and ZTE-focused program at $1.9 billion; after the FCC approved about $4.98 billion in cost estimates submitted through program applications, the defense bill enacted in December 2024 authorized the commission to borrow up to $3.08 billion to cover the balance. That fix took years to arrive, and it came only when Congress attached it to the annual defense measure. An expansion reaching carrier-grade equipment from three state-owned operators would multiply the money, the paperwork and the wait.
Not everyone accepts the premise. Marc Rogers, a veteran telecommunications security expert, called expanded replacement mandates economically unrealistic, compared the undertaking to demolishing a city to rebuild it, and warned that unilateral action invites Chinese operators to route around any single country’s rules. James Mulvenon, vice president of intelligence at Pamir Consulting, said Salt Typhoon’s seriousness gives the FCC ample justification to restrict or expel the carriers.
Where enterprise exposure hides in the interconnection layer
Coverage so far has treated this as a carrier and FCC story. For corporate counsel and security teams, the architectural implications may be more directly actionable than the licensing fight. The report does not identify enterprise customers among the exposed parties; the exposure it documents runs through colocation facilities and data-center interconnection, and that is infrastructure corporations, law firms and legal service providers also buy. The report describes Chinese carrier equipment sitting in commercial facilities, cross-connected into the fabric of the American internet, years after regulators acted.
The question the report leaves with corporate customers is uncomfortable in its simplicity: which facilities does their traffic transit, and who else holds cross-connects there? Security and sourcing teams can start by mapping their own colocation and transit dependencies, asking carriers and facility operators directly about interconnection with covered entities, adding transparency and notice obligations at contract renewal, and treating BGP route monitoring as seriously as endpoint telemetry. Information governance teams should treat vendor-transition records, the risk acceptances, waivers and interim mitigations an expanded mandate would generate, as potentially litigation-relevant from the day they are created.
The FCC is already moving on adjacent fronts. Reuters reported Aug. 4 that the commission is developing a measure to bar imports of new models of Chinese optical transceivers used in data centers, a proposal officials hope to publish in 2026 and one that could still be modified or abandoned; a Chinese Embassy spokesperson called the plan protectionist, China Daily reported. The commission had also teed up a preliminary rulemaking in April that Bloomberg reported could further restrict data-center access for companies already barred from U.S. operations. The near-term signals to track are whether that proceeding hardens into rules reaching retained infrastructure rather than new sales, whether appropriators fund the expanded removal mandate and whether any enterprise customer starts asking its providers the interconnection question in writing.
If your organization had to certify today which data centers its traffic transits, and who else holds cross-connects inside them, could it?

News sources
- Chinese telecom firms kept footholds in US networks despite federal crackdowns, House probe finds (Nextgov/FCW)
- Stranger Pings: Chinese Telecom Companies Infiltrate U.S. Infrastructure (Select Committee on the CCP)
- Data Centers Exposed Carriers to China Hack, House Panel Says (Bloomberg via Insurance Journal)
- US Congress ‘Salt Typhoon’ report politicizes cybersecurity, lacks technical evidence, Chinese experts say (Global Times via GlobalSecurity.org)
- Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says (The Record)
- House probe finds gaps in U.S. effort to remove Chinese telecom risks (Government Executive)
- FCC Rip-and-Replace: 42 Percent of Huawei and ZTE Projects Done as Supply Chain Delays Double (TechTimes)
- Secure and Trusted Communications Networks Reimbursement Program (Federal Communications Commission)
- Eighth Report of the FCC on the Secure and Trusted Communications Networks Reimbursement Program (Federal Communications Commission)
- China opposes US abuse of national security to target Chinese firms (China Daily)
- Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict (The Register)
- Foreign Ministry Spokesperson’s Remarks on Salt Typhoon Hacking Operations (Ministry of Foreign Affairs of the PRC)
- Stranger Pings: The Threat of CCP-Controlled Infrastructure in the U.S. Communications Backbone (United States Congress)
Assisted by GAI and LLM technologies
Additional reading
- Restore the controller, risk losing evidence: federal water guidance leaves the sequence open
- Policy without control: the AI governance gap in IBM’s 2026 Cost of a Data Breach Report
- ShinyHunters’ July 31 deadline for EY arrives after third-party tax-data breach
- The new negligence baseline: how voluntary CI Fortify guidance becomes Exhibit A in post-breach litigation
- Stadler rejects $12.3 million ransom after supplier-linked platform breach
- SharePoint attackers are stealing the keys, and patching alone will not evict them
- UK and EU impose first simultaneous cyber sanctions as Poland attack is attributed to the FSB
- The negotiator was the leak: insider who betrayed ransomware victims gets 70 months
- Why a single Signal recovery key is a preservation problem
- Europe’s critical sectors are maturing, but seven still sit in ENISA’s risk zone
- When the worm targets the assistant: Miasma turns AI coding agents into the trigger
- Glasswing widens: Anthropic puts Mythos inside power, water and hospital operators across more than 15 countries
- Canvas breach moves from disclosure to demand as ShinyHunters sets May 12 deadline
- CISA’s CI Fortify rewrites the disconnection playbook for critical infrastructure
- A 48-month federal benchmark resets the incident-response insider question
- Data collection in occupied territory: A closer read of Cyber Law Toolkit scenario 35
- Cyber Law Toolkit tests surveillance and data collection under occupation
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.



























