The Threat of CCP-Controlled Infrastructure in the U.S. Communications Backbone

In the fall of 2024, the “Salt Typhoon” campaign—a cyber-espionage operation directed by the People’s Republic of China (PRC)—infiltrated the core of America’s telecommunications backbone, breaching the networks of multiple major American telecommunications companies and internet service providers. The attackers bypassed traditional perimeter defenses to access systems enabling them to steal call-records data, compromise sensitive private communications of some individuals, and exploit sensitive law enforcement information. This operation proved that Beijing’s hackers no longer rely on malware alone. Instead, they weaponize the fundamental architecture of carrier networks—routing, reachability, and trusted pathways—to maintain deep, persistent access and evade detection. The U.S. government recognized this threat years earlier, when the Federal Communications Commission (FCC or Commission) took the critical step of revoking or denying the Section 214 authorizations2 of China Telecom (Americas) Corporation, China Mobile International (USA) Inc., and China Unicom (Americas) Operations Limited to block them from providing retail telecommunication services. However, those administrative actions did not require these Chinese telecommunication providers to shut down all physical operations in the United States. The carriers quietly obtained or retained hardware, interconnection agreements, and data center footholds that served as their “trusted” backdoors.


Stranger Pings