Data Centers Exposed Carriers to China Hack, House Panel Says

By | August 5, 2026

US telecommunications companies connected their systems to data centers and related infrastructure in a way that exposed them to cybersecurity vulnerabilities, potentially opening the door to the massive Salt Typhoon hacking campaign that breached several mobile carriers two years ago, according to a House committee.

The companies’ networks had routine pathways to equipment and data centers that may have been connected to three Chinese telecommunications firms that are otherwise prohibited from operating in the US, according to a report released Tuesday by the House Select Committee on China. Those connections created links between US telecom companies and the infrastructure breached by a Chinese hacking group known as Salt Typhoon.

While the Federal Communications Commission barred China Telecom Corp., China Mobile International and China Unicom from directly connecting to US networks, the firms have exploited regulatory gaps to maintain a physical presence in the American market, the panel found. For example, the companies weren’t required by the FCC to pull their hardware from third-party data centers, nor were they obligated to end internet management services at those facilities.

“As a result, Chinese state-owned carriers remained deeply embedded in the US internet ecosystem long after federal regulators had already found them vulnerable” to Chinese Communist Party influence and moved to end their ability to provide telecommunication services in the US, the committee wrote.

US intelligence officials in 2024 accused the Chinese hacking group of a “broad and significant cyberespionage campaign” that breached the systems of several US telecommunications companies and targeted the phones of prominent politicians, including then-presidential candidate Donald Trump. The hackers infiltrated telecom networks in an effort to steal call records and compromise the communications belonging to a “limited number” of people in government and politics, US officials have said.

AT&T Inc., Verizon Communications Inc. and Lumen Technologies Inc. have all acknowledged that they’d been hit by Salt Typhoon’s hacking operation. T-Mobile US Inc. has said suspicious behavior on its network devices tipped off the company to an attempted breach. In its report, the panel called Salt Typhoon an attempt to “weaponize the fundamental architecture of carrier networks.”

At issue are the US telecommunications companies’ secondary connections, ones that tangentially link them to the broader information ecosystem and fall outside of federal regulators’ purview. The bipartisan report, which is the result of a more than yearlong investigation by the panel, concludes that US operators were not aware of cybersecurity risks posed by these connections.

“All of this leaves us vulnerable to a new wave of state-sponsored cyberattacks from our nation’s biggest adversary,” Representative John Moolenaar, the committee’s Republican chairman, said in a statement. “We must cut these subsidiaries out of our domestic infrastructure to protect the American people.”

The committee’s findings are especially notable because telecom carriers’ relationships with data centers aren’t directly regulated by the government. The companies are instead barred by the US from using networking equipment manufactured by certain Chinese companies within their own US telecom networks. The US government has spent billions of dollars on “rip and replace” efforts to extract those components from Chinese manufacturers such as Huawei Technologies Co.

In response to that issue, the FCC is drafting an order to ban Chinese-made data center components, according to a person familiar with the matter. The agency is also considering other steps to keep blacklisted China-based companies from connecting to US networks, the committee said in its report.

An FCC spokesperson didn’t respond to a request for comment. Reuters reported earlier that the agency was exploring a ban on Chinese networking equipment.

The FCC had already teed up a preliminary rulemaking in April that suggests it may further restrict foreign access to data centers, specifically for companies that are already barred from US operations and sales on the FCC’s so-called covered list. Those firms include China Mobile and China Unicom, as well as Huawei and ZTE Corp.

In their report, lawmakers called for further steps to close any loopholes in the FCC’s ability to bar companies from foreign adversaries from operating in the US. They also recommended a targeted effort to ensure that equipment owned by entities on the FCC’s blacklist is removed.

“Congress should continue to address risks to Americans’ data and ensure that the agencies responsible for securing our communications networks have the resources they need to respond to potential threats,” said Representative Ro Khanna, the committee’s top Democrat.

Photo: Photographer: Brent Lewin/Bloomberg

Topics Carriers Cyber China

Was this article valuable?

Here are more articles you may enjoy.