The Salt Typhoon hack that breached America’s biggest phone carriers had a back door hiding in plain sight. A bipartisan House report has a blunt finding. Three Chinese state-owned carriers, pushed out of the US years ago, never fully left. Their leftover footholds, it says, may have helped keep the hackers’ infrastructure alive.

US regulators denied or revoked the licences of China Telecom, China Mobile and China Unicom between 2019 and 2022. But those orders had a gap, the House Select Committee on China found. They never forced the firms to remove equipment, leave data centres or cut private network links. So the carriers kept enterprise networking, transit and hardware inside American facilities.

The Salt Typhoon thread

Salt Typhoon, uncovered in 2024, was a sweeping Chinese espionage campaign. It breached AT&T, Verizon and Lumen, and reached court-authorised wiretap systems. It targeted senior officials, including then-candidate Donald Trump and Vice President JD Vance.

The committee reviewed routing data from the days the campaign became public. China Mobile International’s network appeared in routes to those servers at least 192 times, Nextgov reported.