What the report actually found
On August 5, 2026, the House Select Committee on the CCP released Stranger Pings: Chinese Telecom Companies Infiltrate U.S. Infrastructure, a 49-page bipartisan investigation into China Mobile, China Unicom, and China Telecom. The committee subpoenaed all three firms and concluded that their US subsidiaries retained equipment, data-center space, interconnection agreements, and network ties years after the FCC denied or revoked their operating licenses between 2019 and 2022. None of the three, the report says, are meaningfully independent of parent companies with deep Chinese Communist Party ties.
The headline finding links that lingering footprint to Salt Typhoon, the Chinese state-linked campaign that breached at least nine US telecom carriers. According to reporting on the report, China Mobile International's network appeared in routing paths to Salt Typhoon attack servers at least 192 times over a four-day window in September 2024, and China Unicom's Beijing-registered addresses were reportedly used to manage the botnet infrastructure. The committee separately tallied nearly 109,000 incidents between January 2018 and May 2025 in which Chinese or Hong Kong-linked networks claimed US internet address space without authorization — a Border Gateway Protocol vulnerability that has nothing to do with licensing and everything to do with how the internet's routing layer trusts its participants.
The case for acting, stated fairly
The committee's ask — expanded FCC authority over equipment and arrangements that fall outside the Section 214 licensing regime, plus mandatory rip-and-replace — deserves to be taken on its merits before it's argued against. The FCC's 2021 order revoking China Telecom Americas' authority to operate as an international common carrier found the company "subject to exploitation, influence, and control by the Chinese government," with no meaningful legal recourse to resist a state directive. That finding didn't expire when the license did. If a company was too great a national-security risk to hold a 214 authorization, its physical equipment, peering arrangements, and data-center leases sitting in the same buildings are not obviously safer. Salt Typhoon proved the threat isn't theoretical: state-linked actors reached deep enough into US carrier networks to access call records and, reportedly, live communications of high-value targets. A regulator whose authority stops at the licensing paperwork, while the infrastructure itself stays put, has a real gap — and 109,000 unauthorized routing claims is the kind of number that should worry anyone who thinks BGP hijacking is a solved problem. Congress convening a bipartisan, subpoena-backed investigation and publishing its findings in the open, rather than quietly briefing classified annexes, is itself the right instinct.
Why the remedy needs more precision than the committee offered
The weak point isn't the diagnosis — it's the prescription. Congress already ran this experiment. The Secure and Trusted Communications Networks Reimbursement Program — the original "rip-and-replace," targeting Huawei and ZTE gear in smaller carriers' networks — was funded at $1.9 billion in 2021 against roughly $5.6 billion in actual carrier reimbursement requests, a gap Congress has still not closed despite bipartisan agreement that it should. Carriers have needed repeated deadline extensions, citing both the funding shortfall and supply-chain delays for replacement gear. That program targeted a comparatively simple problem: swap out named radios and switches from two blacklisted vendors. What the committee proposes is broader and fuzzier — unwinding data-center leases, interconnection deals, and "unregulated footprints" for which there is no equivalent equipment list, no existing appropriation, and no agency currently staffed to inventory it. Mandating rip-and-replace again, without first funding the last one properly, risks producing exactly what critics like telecom-security consultant Marc Rogers have warned: a program that looks decisive in a press release and drags on for years underfunded, as the current one has.
There's also a due-process dimension worth taking seriously. "Expanded FCC authority" is a request for durable power, not a one-time fix, and Congress should be precise about its scope and sunset rather than handing the agency an open-ended mandate in response to one report — however well-documented. The proportionate response is to fully fund the removal mechanisms that already exist before creating new ones, and to treat the BGP hijacking numbers as the most tractable and urgent piece of this: routing security through RPKI adoption and stricter peering verification is a technical fix carriers can implement without a new licensing fight, and it addresses the 109,000-incident figure directly rather than through a multi-year infrastructure teardown.
The bottom line
Salt Typhoon and the committee's routing evidence make a genuine case that revoked licenses did not equal removed risk. But the answer to an underfunded first rip-and-replace program is not a second, broader one launched the same way. Congress should close the reimbursement gap it already created, give the FCC narrowly scoped authority tied to specific, inventoried infrastructure, and prioritize the routing-security fixes that don't require a fight over agency power to implement.