Stranger Pings: How Chinese Telecom Giants Embedded Themselves in America’s Communications Backbone
A bipartisan House investigation released Tuesday found that three Chinese state-owned telecommunications companies retained deep footholds inside U.S. internet infrastructure for years after federal regulators moved to expel them — and that their residual access may have helped enable the most significant Chinese cyber espionage campaign in history.
The report, titled “Stranger Pings: The Threat of CCP-Controlled Infrastructure in the U.S. Communications Backbone,” was released by the House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party. It draws on subpoenaed documents, eight transcribed interviews conducted under oath and a multi-year technical dataset spanning 108,891 confirmed internet routing anomalies.
“U.S.-based subsidiaries of Chinese telecommunications companies are beholden to the CCP, and they are a threat to all of us,” said Select Committee Chairman John Moolenaar, R-Mich. “They make American customers promise to censor information according to the CCP’s laws, and they poison the domestic cyber infrastructure we rely on.”
The Regulatory Gap That Wasn’t Closed
Between 2019 and 2022, the Federal Communications Commission denied China Mobile USA’s application for international service authority and revoked the operating licenses of China Telecom Americas and China Unicom Americas. The FCC cited each company’s vulnerability to exploitation, influence and control by the Chinese Communist Party.
But those administrative actions were licensing tools, not eviction orders. Under current law, revoking a Section 214 telecommunications license terminates a carrier’s right to sell regulated services — it does not require the company to remove hardware, vacate data centers or sever private network relationships.
The carriers exploited that gap. China Telecom Americas maintained 10 active points of presence across seven U.S. metro areas including Ashburn, Va., Chicago, Los Angeles, Miami and New York. China Unicom Americas documented roughly 10 data centers and active colocation cages across 11 cities. China Mobile USA retained 39 U.S. points of presence across 27 distinct data center and interconnection facilities, commanding a total network capacity of up to 1,380 gigabits per second.
“Chinese state-owned carriers remained deeply embedded in the U.S. internet ecosystem long after federal regulators had already found them vulnerable to CCP exploitation, influence, and control,” the report states.
Not Independent: The CCP Control Structure
All three companies sit at the bottom of ownership chains that run through Hong Kong and offshore holding companies to Chinese state-owned enterprises supervised by the State-owned Assets Supervision and Administration Commission (SASAC), the PRC government body that exercises ownership rights over central state enterprises on behalf of Beijing.
The Department of Defense lists all three parent companies as “Chinese military companies” under the National Defense Authorization Act. The Department of the Treasury lists them on its Non-SDN Chinese Military-Industrial Complex Companies list under Executive Order 14032, which restricts U.S. investment in firms tied to China’s military-civil fusion strategy.
Critically, China’s National Intelligence Law requires all three parent carriers to hand over data upon state demand. Because the U.S. subsidiaries rely on parent-controlled routing and systems, any traffic traveling over their infrastructure remains potentially visible to Chinese intelligence services.
The governance evidence is stark. China Unicom Americas disclosed that seven of its board’s eight directors are CCP members and two of its three senior management members are CCP members. The company’s U.S.-based employees used Chinese email addresses and accessed internal records through a VPN into parent-controlled systems. When a senior compliance officer was asked whether the parent company was state-owned, he said he did not know — despite that fact appearing in the company’s own regulatory filings.
China Mobile USA operated as what one witness described as “basically a sales team,” with no independent network engineering function. When investigators asked about U.S.-based network staff, witnesses could not identify a single network operating team outside Hong Kong. Troubleshooting ran through Shanghai and Hong Kong. Customer trouble tickets were first logged by a call center in Shanghai.
China Telecom Americas received “freeze notifications” — administrative pauses on network changes — from its parent entity in Shanghai whenever there was a major event or holiday in China. Those freezes applied across the entire customer base, meaning U.S. customers’ network operations were governed by Beijing’s calendar.
BGP: The Internet’s Exploitable Trust System
The technical core of the threat is the Border Gateway Protocol, or BGP — the system that decides how data travels across the global internet. Every network identifies itself with a unique Autonomous System Number and advertises the range of internet addresses it can reach. The system runs almost entirely on trust: networks accept one another’s route announcements without independent verification.
A BGP hijack occurs when a network broadcasts false announcements claiming it is the fastest route to a specific destination. Surrounding routers believe the false announcement and update their internal maps. Traffic is pulled away from its legitimate path and funneled into the hijacker’s infrastructure, where it can be copied, monitored or stored before being silently forwarded — often without the user ever knowing they were intercepted.
The earliest well-documented episode occurred April 8, 2010, when erroneous routes propagated by China Telecom redirected traffic for roughly 15 percent of the internet’s destinations through servers in China for about 18 minutes. Affected networks included the U.S. Senate, the armed services, the Office of the Secretary of Defense, NASA, the Department of Commerce and NOAA.
When it ultimately revoked China Telecom’s operating authority, the FCC found the carrier had exploited BGP vulnerabilities “to misroute United States internet traffic on at least six occasions.” The commission determined that China Unicom was “the likely source of more surveillance attacks against U.S. mobile users than any other provider in the world” between May 2018 and December 2019, according to independent analysis cited in the FCC’s revocation order.
A 2020 investigation by The Guardian found China had used mobile phone networks in the Caribbean to conduct surveillance on tens of thousands of U.S. mobile subscribers, routing signaling attacks through state-controlled operators to track, monitor and intercept communications. Security researcher Gary Miller, a former mobile network security executive, found that in 2018 China Unicom conducted the highest number of apparent surveillance attacks against U.S. mobile phone subscribers over 3G and 4G networks. “Once you get into the tens of thousands, the attacks qualify as mass surveillance,” Miller said.
The Select Committee’s multi-year analysis of global internet routing tables from January 2018 through May 2025 identified 108,891 BGP hijack events in which PRC- or Hong Kong-associated carrier networks announced American internet address space without authorization. The anomalies affected at least 477 distinct U.S. networks, including premier telecommunications providers, Fortune 500 corporations and critical infrastructure operators.
The Salt Typhoon Connection
The routing data takes on acute significance in the context of Salt Typhoon, the CCP-sponsored cyber espionage campaign that FBI Director Christopher Wray described as potentially “the PRC’s broadest, most significant cyber espionage campaign in history.”
In the fall of 2024, Salt Typhoon infiltrated the core of America’s telecommunications backbone, breaching multiple major carriers and internet service providers. The attackers stole call-records data, compromised private communications of targeted individuals and copied information subject to U.S. law enforcement court orders — including systems used to comply with wiretap requests.
The committee’s technical analysis found that during the critical exposure window of Sept. 22-25, 2024 — the four days before The Wall Street Journal publicly disclosed the intrusion — China Mobile International’s network appeared in active routing paths to CISA-confirmed Salt Typhoon attacker servers at least 192 times. As U.S. defenders worked to sever the hackers’ access, China Mobile’s infrastructure provided path continuity, keeping the attackers’ operational backend accessible to the internet.
During that same month, PRC and Hong Kong-linked infrastructure initiated 1,305 separate high-confidence BGP hijacks against U.S. entities. China Mobile assets actively participated in the surge, executing 49 verified incidents including 8 high-severity hijacks directly originated by AS58453 — the exact same network providing routing continuity to the attacker servers.
Carriers as Intelligence Conduits: Four Case Studies
The report identifies four specific relationships between the Chinese state carriers and entities tied to the PRC’s defense and intelligence apparatus.
China Telecom Americas and Qihoo 360. Qihoo 360 Technology Co. — sanctioned by the U.S. government for its role in military-civil fusion projects and designated a Chinese military company — peers directly with China Telecom Americas’ network. During the Salt Typhoon disclosure window, BGP announcement volumes for Qihoo 360 and China Telecom moved together in a statistically significant pattern across 145 observation intervals. Shodan data shows many of Qihoo 360’s U.S.-announced IP addresses went offline in August 2024, weeks before Salt Typhoon became public — consistent with the company hardening or hiding exposed infrastructure before the intrusion was disclosed.
China Mobile USA and CloudRadium. China Mobile USA provided CloudRadium (HK) Limited — a Hong Kong IP transit and hosting provider whose infrastructure repeatedly appeared in malicious cyber activity — access inside critical U.S. internet infrastructure that ordinary domestic suppliers refused to provide directly. Between January 2024 and May 2025, CloudRadium executed at least six orders with China Mobile listed as the seller of record, acting as the trusted counterparty that domestic vendors would not accept. By May 2025, CloudRadium signed a 48-month contract valued at $480,000 with China Mobile — well after the FCC’s revocation of Chinese carrier authorizations. CloudRadium’s Wyoming corporate registration used an address near F.E. Warren Air Force Base, home to the 90th Missile Wing and its Minuteman III intercontinental ballistic missiles.
China Mobile and Salt Typhoon. During the May 2017 WannaCry ransomware outbreak, researcher Lee Neubecker found that 8.56 percent of U.S. results in a nationwide Shodan scan were associated with CloudRadium infrastructure. The FBI’s investigation identified operational infrastructure that included IP addresses registered to China Unicom Liaoning.
China Unicom and Integrity Technology Group. Integrity Technology Group, a Beijing cybersecurity firm, built a botnet that enrolled compromised Internet of Things devices to disguise malicious traffic and used China Unicom Beijing Province Network IP addresses to manage the network. As of June 2024, the botnet held more than 260,000 compromised devices and its management database recorded over 1.2 million historical compromise records, including more than 385,000 unique U.S. victim devices. The FBI assessed Integrity Tech was “responsible, at least in part, for the computer intrusion activities collectively attributed to Flax Typhoon.” The Treasury Department sanctioned Integrity Tech on Jan. 3, 2025. Despite U.S. sanctions, China Unicom continued awarding cybersecurity work to Integrity Tech and moved to integrate the firm into its core security operations.
Hardware and Censorship: The Physical Layer
The carriers also kept Chinese-manufactured equipment running inside U.S. networks. China Telecom Americas acknowledged that roughly 25 percent of its transmission hardware on the U.S. network remained Huawei equipment — gear that sits below many software-based traffic-monitoring tools, potentially enabling interception or disruption without triggering standard intrusion alarms.
A Select Committee network scan in June 2025 using Shodan identified approximately 6,000 Ruijie Networks devices discoverable in U.S. networks. Ruijie, a Fuzhou-based maker of routers and switches, is a “level 2” technical support unit for China’s National Vulnerability Database of Information Security, which is operated by an entity identified as subordinate to the Ministry of State Security. In December 2024, CISA issued an advisory documenting critical vulnerabilities in Ruijie’s cloud platform, including a flaw permitting arbitrary command execution on affected devices. Ruijie is not currently on the FCC Covered List.
China Unicom Americas embedded an “Acceptable Use Policy” in IP Transit Agreements with U.S. companies requiring compliance with regulatory requirements issued by China’s Ministry of Industry and Information Technology and Ministry of Public Security. The policy prohibited broadcasting political news against PRC state laws, information in violation of PRC state security laws and information violating “social order and social stability.” The committee found this constituted an attempt to export Beijing’s internal censorship and surveillance regime into the U.S. market on an extraterritorial basis.
The SS7 Dimension
The routing manipulation documented in the report operates alongside a parallel vulnerability in mobile signaling protocols. Signaling System 7, or SS7, is a decades-old protocol used by telecom companies worldwide to coordinate calls, texts and roaming. Because it was designed without modern security in mind, SS7 can be exploited to track device locations in real time, intercept SMS messages and voice communications, and silently push malicious commands onto target devices.
A 2025 report by mobile security firm iVerify found that at least 60 mobile operators in 35 countries, including U.S. allies Japan, South Korea and New Zealand, route sensitive mobile traffic through Chinese-owned networks including China Mobile International, China Telecom Global, China Unicom Global, CITIC Telecom International and PCCW Global Hong Kong. Because mobile signaling protocols are unencrypted, those networks have direct, man-in-the-middle access to authentication data, SMS messages, location updates and internet traffic for millions of users worldwide.
Policy Response and Countermeasures
The FCC on April 30, 2026, voted 3-0 to advance a Notice of Proposed Rulemaking that would bar China Mobile, China Telecom and China Unicom from operating under the blanket domestic Section 214 authority that most carriers have held automatically since 1999. The proposed rule also seeks to prohibit domestic carriers from interconnecting with these entities.
But the committee argues the NPRM is insufficient. Section 214 is a licensing tool. It does not require a foreign state-controlled carrier to remove retained points of presence, colocation equipment, cross-connects, peering relationships, IP transit arrangements or parent-controlled routing identities.
The committee’s six legislative recommendations call on Congress to codify the FCC’s authority to deny blanket authorizations and restrict domestic interconnection; establish statutory authority to identify, restrict and remove retained foreign-adversary infrastructure; broaden Team Telecom and Commerce Department ICTS jurisdiction over private commercial arrangements; mandate entity-specific FCC Covered List determinations and fund targeted “rip-and-replace”; fund internet routing-security enforcement; and require interim logging and monitoring of anomalous behavior until covered infrastructure is removed.
Ranking Member Ro Khanna, D-Calif., said the report “shows the importance of continued oversight of PRC-linked telecommunications companies operating in the U.S.” and called on Congress to ensure agencies responsible for securing communications networks have the resources they need.
Closing the routing-layer dimension of this threat requires more than domestic rulemaking. The FCC cannot compel a foreign autonomous system to withdraw an unauthorized route announcement made to networks abroad. Addressing the full scope of the problem requires allied network operators to enforce common route origin validation standards, share rapid route-leak notifications and refuse to propagate unauthorized announcements from high-risk carriers.
The committee noted a classified annex accompanies the report, suggesting the public version represents a floor, not a ceiling, of the documented threat.
Sources: House Select Committee on China, “Stranger Pings” report, Aug. 4, 2026 | Nextgov/FCW, Aug. 4, 2026 | Reuters, April 23, 2025 | The Guardian, Dec. 15, 2020 | iVerify, April 17, 2025 | CISA Advisory AA25-239A, Sept. 3, 2025
AI generated