Chinese Telecom Giants Retain US Infrastructure Footprint After Salt Typhoon Links, Prompting New Congressional Scrutiny
What Happened — A bipartisan House Select Committee on China released a 49‑page report confirming that China Mobile, China Unicom and China Telecom continue to operate hardware, interconnection agreements and data‑center footholds inside the United States. The firms were previously cited in the Salt Typhoon supply‑chain intrusion that compromised at least nine U.S. telecommunications providers, and the committee says their lingering presence creates “trusted backdoors” for state‑sponsored actors.
Why It Matters for Compliance & Audit Readiness
- The situation exemplifies a vendor‑risk scenario that SOC 2’s Vendor Management (CC6.1) and Risk Management (CC7) criteria are designed to address.
- Continuous monitoring of third‑party equipment and contracts provides the audit evidence needed to demonstrate due diligence when regulators question foreign‑origin hardware.
- Mapping this risk to a formal Vendor Risk Management program helps create a defensible trail for any future FCC or C‑suite inquiries.
Who Is Affected — U.S. telecommunications carriers, ISPs, cloud‑hosting providers, and any enterprise that routes traffic through infrastructure owned or operated by the three Chinese state‑owned carriers.
Recommended Actions
- Conduct an immediate third‑party risk assessment of all network assets that trace back to China Mobile, Unicom or Telecom.
- Update vendor‑management policies to require continuous evidence of equipment provenance and enforce contractual security clauses (e.g., right‑to‑audit, removal timelines).
- Deploy continuous‑compliance tooling to collect and retain logs, configuration baselines, and FCC licensing status as part of your SOC 2 evidence repository.
Source: The Record – Chinese telcos maintain deep US presence despite Salt Typhoon links
Technical Notes — The Salt Typhoon campaign leveraged compromised network gear and firmware to exfiltrate data from nine U.S. telecoms. No specific CVE is cited; the risk stems from supply‑chain exposure and the continued physical presence of Chinese‑owned equipment in U.S. data centers.