China-Linked Salt Typhoon May Leverage Telecom Infrastructure for Future Attacks, Report Warns
A U.S. congressional report suggests China-controlled telecommunications infrastructure could be exploited by threat actors like Salt Typhoon for future cyber operations.

A recent report from the U.S. Congress's bipartisan Select Committee on China, titled "Stranger Pings," has raised alarms about the potential misuse of China-controlled telecommunications infrastructure within the United States. The 49-page document highlights how Chinese telecom firms operating in the U.S. may not act independently, potentially allowing threat actors, such as the China-linked Salt Typhoon campaign, to leverage residual access for future cyber operations.
The committee's findings suggest that these trusted positions within the U.S. communications backbone could be abused to preserve access and conceal malicious activity. The report specifically points to instances where "one PRC telecommunication provider included an 'Acceptable Use' Policy in contracts with U.S. companies." This policy reportedly prohibited the broadcasting of political news against PRC state laws, information violating PRC state security laws, and content disrupting "social order and social stability," indicating a level of control that could be co-opted by state-sponsored threat actors.
While the report does not detail specific ongoing exploits, it outlines a significant risk vector. The presence of Chinese telecom infrastructure, often deeply integrated into national communication networks, presents a persistent threat. The "Stranger Pings" report implies that the infrastructure itself, and the contractual agreements surrounding its operation, could serve as a foundation for future espionage or disruptive cyber campaigns.
The Salt Typhoon campaign, previously identified by cybersecurity researchers, has been associated with various cyber espionage activities. The potential for this group, or others like it, to exploit the established presence of Chinese telecom providers in the U.S. amplifies concerns about the nation's cybersecurity posture. The committee's warning underscores the need for rigorous oversight and potential divestment from foreign-controlled critical infrastructure.
This revelation comes amidst a broader global concern over the security implications of technology supply chains and the potential for state-sponsored cyber threats. The report serves as a stark reminder that geopolitical tensions can manifest in the digital realm, with critical infrastructure becoming a potential battleground.
Further investigation into the specific vulnerabilities and contractual clauses mentioned in the report is warranted. The findings suggest a proactive approach is necessary to mitigate the risks associated with foreign-controlled telecommunications infrastructure and to safeguard national security against potential cyber incursions facilitated by such means.