The United States spent years restricting three Chinese state-owned telecom carriers from its regulated communications market. A bipartisan congressional investigation says they nevertheless retained significant positions inside American internet infrastructure.
Between 2019 and 2022, the Federal Communications Commission denied China Mobile USA’s application for international Section 214 authority and revoked or terminated Section 214 authorisations held by China Telecom Americas and China Unicom Americas. The FCC concluded that the companies presented national security and law-enforcement risks, including vulnerability to exploitation, influence and control by the Chinese government.
Those decisions restricted the carriers’ ability to provide covered telecommunications services. Current law did not create a complete infrastructure-removal remedy or compel them to remove equipment, leave data centres, terminate private network connections or abandon services falling outside the relevant licensing regime.
That regulatory gap sits at the centre of a new investigation by the House Select Committee on China. Drawing on subpoenaed company records, interviews with employees and internet routing data, the committee found that the three carriers retained extensive physical and digital footholds inside the United States.
China Telecom identified ten active points of presence across seven US metropolitan areas, including Los Angeles, New York, Chicago and Ashburn, Virginia. China Unicom retained equipment and active connections in roughly ten data centres. China Mobile USA’s records contained 39 point-of-presence entries across 27 facilities, with aggregate network capacity of up to 1,380 gigabits per second.
These facilities are important because they are places where networks meet and exchange traffic. The report says equipment and cross-connections inside them allowed China Mobile USA to connect directly with telecom backbones, data exchanges and private networks rather than relying solely on the ordinary public internet.
The investigation also found that the American subsidiaries remained closely dependent on their parent organisations in China and Hong Kong. One witness described China Mobile USA as “basically a sales team”, while another said it had no network engineers.
China Telecom’s international troubleshooting processes ran through Hong Kong and Beijing, while its American operation kept no independent traffic-flow logs. A China Unicom compliance officer said the US subsidiary relied on parent-controlled systems but could not guarantee that China Unicom Global complied with American law.
Some of the retained equipment was Chinese-made. A China Telecom witness said approximately one quarter of its US transmission equipment remained supplied by Huawei. The company’s records also listed a ZTE switch in Chicago.
One of the report’s most striking documentary findings concerns a mandatory acceptable-use policy included in China Unicom IP transit agreements with American companies. The policy prohibited the broadcasting of political news contrary to Chinese law, information deemed to violate Chinese state security, and material considered harmful to “social order and social stability”. It also required users to provide network-usage information, including IP addresses and domain names, for review.
The committee’s more consequential claims concern the Border Gateway Protocol, or BGP, the system networks use to tell one another where internet traffic should be sent. BGP relies heavily on trust. A false or mistaken route announcement can divert data through an unexpected network, creating opportunities for interception, disruption or surveillance.
The committee says it identified 108,891 events that it classified as high-confidence BGP hijacks between January 2018 and May 2025. In each case, a network associated with a carrier in China or Hong Kong announced American internet address space without an identified authorisation. At least 477 US networks were affected, according to the report.
That number requires careful handling. The report’s methodology says each counted event represents a discrete route-origin observation, rather than a unique victim, internet prefix or campaign. The dataset also extends beyond the three US subsidiaries examined in the investigation. The committee does not contend that every event was a deliberate, state-directed espionage operation and acknowledges that some anomalies could have resulted from configuration errors, aggressive routing or poor network management.
The committee says Cloudflare and outside cybersecurity experts independently confirmed the baseline total. The public report does not reproduce the underlying row-level dataset, offender-ASN watchlist, filter parameters or methodology annex, meaning the figure cannot be independently recreated from the document alone.
The report stops short of claiming that employees of the three carriers knowingly participated in Chinese cyber operations. Its examination of Salt Typhoon, the Chinese cyber-espionage campaign against US telecommunications networks disclosed in 2024, identifies a concerning correlation rather than direct proof of complicity.
During a four-day period from September 22 to 25, 2024, the committee tracked 58 internet prefixes linked to what it described as CISA-confirmed Salt Typhoon attacker servers. Route checks conducted every eight hours found that China Mobile International’s AS58453 network, which the report associates with relevant China Mobile USA routing, appeared in active paths to those servers at least 192 times.
Investigators argue that this provided path continuity while American defenders attempted to sever the attackers’ access. The committee says the evidence does not establish that China Mobile USA personnel knew about or participated in the operation, and does not definitively attribute the cyber campaign to the company.
The underlying policy problem remains substantial even if the routing evidence cannot establish deliberate corporate involvement. US regulators identified the carriers as national security risks and denied or revoked important operating authorisations, while parent-linked equipment and network relationships remained inside critical American infrastructure.
The FCC has already begun examining this gap. On April 30, 2026, it adopted a notice of proposed rulemaking proposing to exclude entities on its national security Covered List from blanket domestic Section 214 authority. The FCC also sought comment on restricting interconnections with excluded or revoked entities, including through points of presence and data centres.
The House committee now wants Congress to create explicit powers to identify, monitor and, where necessary, remove foreign state-controlled infrastructure. It also recommends targeted removal funding and minimum logging, monitoring and record-preservation requirements while such infrastructure remains in place.
The episode exposes a mismatch between traditional telecommunications regulation and the architecture of the modern internet. Revoking a carrier’s authorisation can end its ability to provide covered services while leaving physical equipment, private contracts and trusted network pathways in place. Washington’s next task is to decide what removing a security threat should mean at the network level.