READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Congress, Federal Agencies Warn China-Linked Hackers and Telecoms Have Deep Access to U.S. Infrastructure

Congress, Federal Agencies Warn China-Linked Hackers and Telecoms Have Deep Access to U.S. Infrastructure
A House Select Committee investigation found Chinese state-owned telecom firms still operate largely unregulated inside U.S. networks years after their federal licenses were revoked. Separately, federal cybersecurity agencies warned this week that hackers are using AI-generated scripts to probe industrial control systems running U.S. water, energy, and manufacturing operations. Neither report claims an attack has caused damage yet, but both describe a threat surface that keeps growing while oversight lags behind.

The House Select Committee on the Chinese Communist Party released a bipartisan report Tuesday concluding that Chinese state-owned telecom carriers remain, in the committee's words, "deeply embedded in the U.S. internet ecosystem" years after federal regulators flagged them as security risks.

The report, titled "Stranger Pings: Chinese Telecom Companies Infiltrate U.S. Infrastructure," found that China Mobile, China Unicom, and China Telecom kept extensive footprints in American networks even after the FCC denied or revoked their Section 214 telecom licenses. Those licenses are what let carriers legally operate U.S. telecommunications services.

According to the committee, the companies' American subsidiaries are not actually independent from their Beijing-based parent firms, despite public claims otherwise. China Unicom's U.S. arm, CUA, disclosed to Congress under subpoena that seven of its eight board members and two of three senior executives are Chinese Communist Party members, the committee said.

The report also cites Chinese national security law, which requires companies to hand data to Chinese military intelligence on request, a mandate the committee says "follows the network infrastructure globally." That means any data crossing U.S.-based equipment tied to these firms could, in theory, be visible to Chinese intelligence services, per the report.

One finding stands out: subsidiaries told the committee that their Chinese parent companies can provision servers and connectivity for undisclosed third parties, and staff at the U.S. entities don't ask who those clients are. "Hypothetically, a PRC intelligence agency itself could contract for services in the U.S. with the parent company, and the U.S. subsidiary would remain ignorant of this reality. This is an unacceptable blind spot," the committee wrote.

Committee Chairman John Moolenaar (R-MI) said the subsidiaries are "beholden to the CCP" and called for cutting them out of domestic infrastructure entirely. Ranking Member Ro Khanna (D-CA) framed it as a resourcing issue, saying Congress should ensure agencies "have the resources they need to respond to potential threats." The bipartisan tone matters: this isn't a partisan gotcha report. Both parties signed off on the findings and the concern.

The investigation traces back to a March 2025 hearing on Salt Typhoon, the Chinese hack that compromised U.S. telecom infrastructure, which prompted subpoenas after the three companies allegedly declined to cooperate voluntarily.

A Second, Related Warning on Industrial Systems

Separately, the NSA, CISA, FBI, Department of Energy, and EPA issued a joint advisory this week describing what they called an "active threat" targeting Siemens S7 Series programmable logic controllers, the industrial computers that run physical processes at water utilities, power plants, chemical facilities, and manufacturers, according to The Hacker News.

The agencies said attackers are using internet scanning tools like Censys and ZoomEye to find exposed, poorly secured PLCs, then deploying AI-generated exploit scripts disguised as legitimate monitoring software. A custom Python script built on open-source industrial libraries lets attackers read and write PLC memory and control logic.

The advisory does not attribute this activity to a specific named group or nation. It's a broader warning about a technique, not a confirmed China link, even though it lands the same week as the telecom report. The sources don't establish a connection between the two.

The Volt Typhoon Backdrop

Wired's Uncanny Valley podcast walked through a related but distinct threat: Volt Typhoon, a Chinese state-sponsored hacking group that, according to Wired senior correspondent Andy Greenberg, has spent three years pre-positioning itself inside American infrastructure. Greenberg attended a closed-door insurance industry war game in Manhattan that simulated a scenario where hackers knock out 5,000 U.S. water utilities simultaneously, an exercise designed to model potential fallout including burst water mains, hospital evacuations, and insulin shortages.

The exercise was a simulation, not an actual attack. No such attack has occurred. The value is in stress-testing response plans, not predicting an imminent event.

What's Actually Proven, What's Alleged

The committee's findings on board composition and licensing history are documented and confirmed by subpoenaed testimony. That's solid ground. The claim that Chinese intelligence could access U.S. network traffic through these subsidiaries is a plausible extrapolation from Chinese law, but it's not proof any specific data has been exfiltrated this way. The committee itself frames it as risk, not a confirmed breach.

Skeptics might reasonably ask why publicly traded companies with U.S. operations and disclosed CCP-affiliated boards were allowed to keep unregulated footprints for years after licenses were pulled. That's a fair question the report doesn't fully answer, beyond noting regulatory and enforcement gaps.

The committee's policy recommendations call for identifying and, where warranted, removing foreign state-controlled infrastructure from U.S. networks entirely. Whether Congress acts on that, or whether it becomes another shelved report, is the open question. The Siemens PLC advisory, meanwhile, puts a concrete to-do list in front of utility operators now: patch software, isolate systems from the internet, and monitor for the AI-generated scripts already circulating.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredChina Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?
right
BreitbartCongress Warns China ‘Deeply Embedded in the U.S. Internet Ecosystem’
unknown
The Hacker NewsAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
unknown
democrats-selectcommitteeontheccp.houseStranger Pings: Chinese Telecom Companies Infiltrate U.S. Infrastructure