Editor’s Note: A bipartisan House report found three Chinese state-owned carriers, their Section 214 authorizations denied or revoked, still holding equipment, data-center space and interconnection ties inside U.S. networks; within a day, China’s embassy had objected and party-state media had recast the findings as politicized and lacking technical evidence. That collision is the durable story, because the finding and the pushback now travel together: every attribution that reaches a boardroom, a breach notification or a claims file arrives pre-contested.

For cybersecurity teams, the report maps exposure living in the interconnection layer rather than the perimeter. For privacy and compliance professionals, its six recommendations sketch codified FCC and interagency authorities, funded removal mandates and interim logging duties would begin generating new record sets if enacted and implemented. For eDiscovery professionals, the committee’s own method, subpoenaed records, sworn interviews and routing telemetry, previews the evidence stack downstream litigation could demand.

Watch whether the FCC’s proposed optical-transceiver measure advances, whether appropriators fund an expanded rip-and-replace and whether enterprise customers start asking, in writing, which facilities their traffic transits.


Content Assessment: Beijing contests House Salt Typhoon report as Congress weighs a wider cleanup

Information - 92%
Insight - 90%
Relevance - 90%
Objectivity - 92%
Authority - 91%

91%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Beijing contests House Salt Typhoon report as Congress weighs a wider cleanup."


Industry News – Cybersecurity Beat

Beijing contests House Salt Typhoon report as Congress weighs a wider cleanup

ComplexDiscovery Staff

Beijing’s answer to the House’s Salt Typhoon investigation arrived within a day, and it was to put the report itself on trial.

The Communist Party-affiliated Global Times and two analysts it quoted dismissed the bipartisan findings Aug. 5 as politicized and technically unsupported. The report, released Aug. 4, found that three Chinese state-owned carriers whose Section 214 service authorizations were denied or revoked years ago never fully left U.S. networks. It asks Congress to move in the opposite direction: codify Federal Communications Commission authority over Chinese carrier infrastructure, fund an expanded rip-and-replace effort and require logging of whatever stays behind.

Salt Typhoon is the espionage campaign that reached at least nine U.S. telecommunications companies and that U.S. agencies attribute to Chinese state-linked actors. The report it prompted frames two questions practitioners will live with long after this news cycle closes. Who gets believed when an accused state’s officials and media contest the findings? And what records get created, kept and eventually produced if Congress orders foreign equipment out of American networks?



What the committee says never left

The House Select Committee on the Chinese Communist Party released its report Aug. 4, the product of an investigation launched after a March 2025 hearing on Beijing’s Typhoon campaigns. The findings rest on subpoenaed corporate records, eight sworn interviews, federal records, routing data and network infrastructure scans. Subpoenas went out in April 2025 after China Telecom, China Mobile and China Unicom declined to answer a bipartisan information request.

The FCC denied or revoked the three state-owned carriers’ Section 214 authorizations to provide U.S. telecommunications services between 2019 and 2022. The committee found the FCC actions reached services, not presence. China Telecom’s U.S. subsidiary kept 10 active points of presence in seven metropolitan areas, with about 25 percent of its U.S. transmission hardware made by Huawei, according to the report. China Mobile’s U.S. arm held 39 point-of-presence entries in 27 facilities and at least 143 active network assets. China Unicom kept equipment and connections in roughly 10 U.S. data centers.

Routing data supplied the report’s most specific technical evidence: time-bounded route observations tied to identified server infrastructure. The report’s routing analysis ran checks every eight hours from Sept. 22 through 25, 2024, across 58 internet prefixes linked to Salt Typhoon attacker servers confirmed by the Cybersecurity and Infrastructure Security Agency, and it found China Mobile International’s network in active routing paths to those servers at least 192 times across a window that overlapped the campaign’s first public reporting. AT&T, Verizon and Lumen have acknowledged being hit by the campaign, and T-Mobile has said suspicious behavior on its network devices tipped it off to an attempted breach, Bloomberg reported. The committee said the routing overlap shows how residual network ties could help sustain malicious infrastructure. It did not allege that employees of the Chinese carriers knew of or participated in the campaign, and Bloomberg reported the committee concluded the U.S. operators were unaware of the cybersecurity risks from these connections. Using what it described as a high-confidence methodology, the report counted 108,891 Border Gateway Protocol hijack events between January 2018 and May 2025 in which carrier networks associated with China or Hong Kong announced U.S. internet address space without authorization. It identified 4,213 high-confidence anomalies or hijacks involving four China Mobile-controlled networks, while acknowledging that some anomalies may reflect aggressive routing, configuration errors or poor management.

Chairman John Moolenaar, R-Mich., said the U.S. subsidiaries answer to the Chinese Communist Party and called for removing them from domestic infrastructure. Ranking Member Ro Khanna, D-Calif., said Congress should keep addressing risks to Americans’ data and ensure the agencies that secure U.S. communications networks have the resources to respond.

Beijing’s rebuttal follows a familiar script

The pushback came through two channels. A spokesperson for China’s embassy in Washington said Beijing firmly opposes what it considers an overstretched concept of national security and would defend Chinese companies’ rights and interests, according to Nextgov/FCW, which first reported the footprint findings. The three carriers did not respond to the outlet’s requests for comment. The Global Times commentary, published Aug. 5, described the report as politicizing cybersecurity while lacking technical evidence.

Li Yan, who directs the technology and cybersecurity institute at the China Institutes of Contemporary International Relations, a state-run research organization in Beijing, argued the report ties the carriers’ remaining connections to Salt Typhoon without demonstrating a causal relationship. He pointed to published analyses from Cisco Talos, Microsoft and Singapore’s Infocomm Media Development Authority that he said found no technical evidence Chinese carrier infrastructure served as a stepping stone for the attacks, and he faulted the report for resting on hedged words such as may, could and potential. Ma Jihua, a telecommunications industry analyst, told the outlet that full separation of the U.S. and Chinese telecom sectors remains unrealistic on commercial grounds.

The hedges Li attacked are common phrasing in infrastructure forensics. Congressional investigators described network proximity and routing behavior, not proven operational control, and the committee itself said it does not allege employee participation. That restraint is what careful analysis looks like. It is also precisely the seam that state-level pushback exploits.

Contested attribution reaches the claims file

For practitioners the dispute is anything but abstract. Chinese officials and state media have contested U.S. cyber attribution before; the Foreign Ministry dismissed allied Salt Typhoon findings as disinformation in September 2025. Nor is this the only live attribution fight: the same week the report landed, the FBI was investigating a multistate intrusion campaign against water utilities that researchers link to Iranian-backed hackers. When an accused state contests a finding, every downstream document that assumes the attribution, from board briefings to breach notifications to insurance submissions, inherits an adversarial audience.

Insurance is one arena where that inheritance carries a price. War and state-action exclusions turn on whether conduct is attributable to a sovereign, an issue litigated through Merck’s NotPetya coverage fight, which ended in a settlement in 2024, and embedded in the state-backed cyberattack exclusions Lloyd’s of London has required in cyber policies since 2023. Official Chinese objections do not defeat attribution, but they keep the question contested in any coverage dispute where an insurer invokes state action. The unglamorous moves follow from that: review war-exclusion and state-action language at renewal, assume incident narratives drafted today will be read against a contested attribution record in discovery tomorrow, and preserve the attribution evidence chain, from agency advisories to forensic findings, as a record set of its own.

Rip-and-replace would leave a paper trail

The report’s six recommendations read like a records-management program for the U.S. network edge. The committee asks Congress to codify the FCC’s authority to deny blanket authorizations and restrict domestic interconnection, to establish statutory authority over retained foreign-adversary infrastructure, and to widen the jurisdiction of Team Telecom and the government’s information and communications technology and services (ICTS) authorities over private commercial arrangements. It also calls for entity-specific Covered List determinations backed by targeted rip-and-replace funding, financed routing-security enforcement and mandatory interim logging, monitoring and record-preservation obligations until covered infrastructure is removed or mitigated.

Every one of those measures generates records. Procurement files, replacement schedules, extension requests, interim risk acceptances and the mandated logs themselves could become subject to discovery, where relevant and proportional to the claims and defenses, once a carrier or its enterprise customers face litigation over a downstream breach. The committee’s own method shows how such a file gets built: subpoenaed commercial records, interviews under oath and routing telemetry, assembled into findings. Depending on the claims and the facts, civil litigants pursuing a downstream breach could seek comparable categories of evidence from carriers, facility operators and their customers. The existing program shows how long the trail runs. As of the FCC’s June 15 report to Congress, recipients had filed final certifications, attesting completed removal and replacement, for 53 of 126 Priority 1 applications, about 42 percent, while only 12 applications had cleared the program’s separate closeout process; most remaining recipients received limited deadline extensions. Congress first funded the Huawei- and ZTE-focused program at $1.9 billion; after the FCC approved about $4.98 billion in cost estimates submitted through program applications, the defense bill enacted in December 2024 authorized the commission to borrow up to $3.08 billion to cover the balance. That fix took years to arrive, and it came only when Congress attached it to the annual defense measure. An expansion reaching carrier-grade equipment from three state-owned operators would multiply the money, the paperwork and the wait.

Not everyone accepts the premise. Marc Rogers, a veteran telecommunications security expert, called expanded replacement mandates economically unrealistic, compared the undertaking to demolishing a city to rebuild it, and warned that unilateral action invites Chinese operators to route around any single country’s rules. James Mulvenon, vice president of intelligence at Pamir Consulting, said Salt Typhoon’s seriousness gives the FCC ample justification to restrict or expel the carriers.

Where enterprise exposure hides in the interconnection layer

Coverage so far has treated this as a carrier and FCC story. For corporate counsel and security teams, the architectural implications may be more directly actionable than the licensing fight. The report does not identify enterprise customers among the exposed parties; the exposure it documents runs through colocation facilities and data-center interconnection, and that is infrastructure corporations, law firms and legal service providers also buy. The report describes Chinese carrier equipment sitting in commercial facilities, cross-connected into the fabric of the American internet, years after regulators acted.

The question the report leaves with corporate customers is uncomfortable in its simplicity: which facilities does their traffic transit, and who else holds cross-connects there? Security and sourcing teams can start by mapping their own colocation and transit dependencies, asking carriers and facility operators directly about interconnection with covered entities, adding transparency and notice obligations at contract renewal, and treating BGP route monitoring as seriously as endpoint telemetry. Information governance teams should treat vendor-transition records, the risk acceptances, waivers and interim mitigations an expanded mandate would generate, as potentially litigation-relevant from the day they are created.

The FCC is already moving on adjacent fronts. Reuters reported Aug. 4 that the commission is developing a measure to bar imports of new models of Chinese optical transceivers used in data centers, a proposal officials hope to publish in 2026 and one that could still be modified or abandoned; a Chinese Embassy spokesperson called the plan protectionist, China Daily reported. The commission had also teed up a preliminary rulemaking in April that Bloomberg reported could further restrict data-center access for companies already barred from U.S. operations. The near-term signals to track are whether that proceeding hardens into rules reaching retained infrastructure rather than new sales, whether appropriators fund the expanded removal mandate and whether any enterprise customer starts asking its providers the interconnection question in writing.

If your organization had to certify today which data centers its traffic transits, and who else holds cross-connects inside them, could it?



News sources



Assisted by GAI and LLM technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).