How the CCP Is Reaching Into the Foundations of America’s Internet: A Three-Layer Threat From Home Routers to AI Data Centers


Aug. 31, 2026, 3:34 a.m.

Views: 1672


1

China’s technological security threat is often understood through familiar issues such as TikTok, Huawei, semiconductor export controls, or repeated cyber intrusions. But the questions Washington should be most concerned about may lie much deeper: Whose networks are carrying American data? Who can remotely control the routers used by American homes and businesses? And who manufactures the critical components on which the data centers powering generative AI increasingly depend?

The answer suggests that the United States is no longer confronting merely a single risky product or an isolated cyberattack. It is facing a broader combination of supply-chain and connectivity risks extending from the internet backbone to edge devices and, increasingly, AI infrastructure.

The Chinese Communist Party does not need to “shut down the entire American internet” to gain strategic leverage. If companies controlled or heavily influenced by Beijing retain enough equipment, access points, routing relationships, and positions at critical network nodes, China could gain additional options for intelligence collection, surveillance, cyber penetration, and disruption of U.S. communications during a crisis.

Layer One: Their Licenses Were Revoked, but Chinese State-Owned Telecom Companies Never Fully Disappeared

2

The Federal Communications Commission has already taken action against China Mobile, China Telecom, and China Unicom.

China Mobile was denied relevant telecommunications authorization in 2019, while China Telecom and China Unicom subsequently had their Section 214 authorizations revoked. The central rationale was not ordinary commercial competition. It was national security, including concerns that these companies could be subject to exploitation, influence, and control by the Chinese government.

The problem is that revoking a license does not amount to physically removing a company from the network.

3

In August of this year, the House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party released a bipartisan investigative report titled Stranger Pings. The report found that the U.S. subsidiaries of these three Chinese state-owned telecommunications companies had not truly separated themselves from their parent companies in China and Hong Kong.

More importantly, while the FCC can restrict the telecommunications services these companies are authorized to sell, existing law does not automatically remove their equipment, network locations, or existing interconnection relationships.

In other words, the United States may have closed the legal front door while leaving a side entrance open inside the digital infrastructure.

4

This gap is particularly significant at the level of the Border Gateway Protocol, or BGP.

BGP can be understood as the traffic-routing system of the internet. It tells networks around the world which paths data should take to reach its destination. If a network mistakenly or without authorization announces itself as a preferable route, internet traffic can be redirected.

The congressional investigation analyzed global routing data from January 2018 through May 2025 and identified 108,891 high-confidence events involving networks associated with China or Hong Kong announcing U.S. IP address space without identifiable authorization.

At least 477 American networks were affected, including telecommunications providers, Fortune 500 companies, and critical-infrastructure operators.

5

From a national-security perspective, the key question is whether state-owned telecommunications networks closely tied to the Chinese government still occupy structural positions from which they could influence the routes taken by American data.

Salt Typhoon makes that concern more tangible.

The congressional investigation found that during the four days from September 22 to September 25, 2024, China Mobile International’s network appeared at least 192 times in routing paths leading to 58 groups of network addresses associated with Salt Typhoon servers identified by the U.S. Cybersecurity and Infrastructure Security Agency.

6

What this finding reveals is a broader problem: when a high-risk, foreign state-owned network remains embedded in America’s digital infrastructure, existing connectivity can continue to provide pathways through which malicious infrastructure remains reachable even after telecommunications licenses have been revoked.

Layer Two: The Risk Has Reached Routers Inside American Homes and Businesses

If the first layer of risk seems distant from the lives of ordinary Americans, the second exists directly inside homes, offices, and even vehicles.

Also in August of this year, cybersecurity firm VulnCheck disclosed that firmware used in at least 20 models of routers manufactured by Shenzhen-based Zbtlink contained a remote-control component known as ENDLESSDOORS.

7

Researchers found that the affected devices repeatedly attempted to establish connections with external command-and-control servers. The software operated with root privileges, the highest level of control on the device, while lacking sufficient authentication safeguards.

Reuters further reported that the affected equipment attempted to connect to a designated IP address or China-registered domain approximately every 35 seconds. Zbtlink products and white-labeled versions had also been sold through platforms including Amazon.

This raises a basic question: Why should a product leave the factory with a technical capability that could allow an external party to obtain the highest level of control over the device?

8

A home router is not an insignificant plastic box.

It commonly connects personal smartphones, work laptops, security cameras, network-attached storage devices, Internet of Things equipment, and a wide range of cloud accounts. Once a router is compromised, an attacker may gain far more than control over a single device. The router can become a privileged vantage point from which to observe, intercept, or launch further attacks against the internal network.

For the United States, supply-chain security has therefore moved beyond telecommunications facilities and directly into ordinary American homes and small businesses.

Layer Three: The Next Battlefield Is the AI Data Center

9

The third layer of risk is emerging inside one of America’s most important new technological infrastructures.

The race for artificial intelligence has made NVIDIA GPUs the center of global attention. But tens of thousands of GPUs are of limited value if they cannot exchange enormous volumes of data at extremely high speeds. Without fast interconnection, even the most expensive processors cannot function efficiently as a large-scale AI cluster.

That is why optical transceivers matter.

10

These components convert high-speed electrical signals into optical signals and connect servers, switches, racks, and large data centers. They are physically small, but they function as indispensable neural connections inside modern AI computing architecture.

The Trump administration is currently considering restrictions on new Chinese-made optical transceivers entering the U.S. market. The national-security concerns under consideration by the FCC reportedly include data theft, malware installation, and service disruption.

Among the companies drawing attention is Chinese manufacturer Zhongji Innolight, which has become a major supplier of optical transceivers for global data centers. Reuters cited estimates placing its global market share for data-center optical transceivers at approximately 27 percent.

截圖 2026-08-31 下午4.00.54

This places the United States in a familiar dilemma.

AI companies want to build computing capacity more quickly and at lower cost. Yet the pursuit of speed and affordability can also introduce new supply-chain dependencies into some of America’s most sensitive digital infrastructure.

National-security policy cannot wait until a backdoor is activated, sensitive data is stolen, or a major cloud service is disrupted before Washington begins considering the security of the supply chain.

12

For AI data centers, a trusted supply chain is itself part of computing capability. It is also part of national security.

America Cannot Keep Treating “License Revoked” as “Risk Eliminated”

These three layers expose a longstanding weakness in U.S. policy: modern networks do not operate on the basis of a business license alone.

The real risks exist inside data-center racks, BGP routing tables, firmware, remote-management accounts, private interconnection agreements, vendor relationships, and millions of seemingly insignificant components.

13

A legal order can take effect in a single day. Physical and digital infrastructure can remain unchanged for years.

The next phase of U.S. policy must therefore move beyond simply preventing new risks from entering the country. Washington must also identify the exposure that is already embedded inside American infrastructure.

Congress should strengthen the FCC’s statutory authority to address residual infrastructure associated with foreign adversaries and expand the ability of Team Telecom and the Information and Communications Technology and Services framework to review data-center arrangements, network interconnections, and remote-management agreements.

494849593_560681097075455_7854491471312955382_n

For equipment already determined to pose serious national-security risks, the United States needs genuinely funded and time-bound “rip-and-replace” programs.

Critical networks should also accelerate the adoption of routing-security mechanisms such as Resource Public Key Infrastructure, or RPKI, which can reduce the likelihood that unauthorized route announcements will be accepted across the global internet. Until high-risk foreign-controlled equipment is fully removed, operators should also be required to maintain comprehensive logs of routing changes and anomalous network activity.

For AI data centers, trusted-supply-chain policy cannot focus exclusively on GPUs. High-speed optical networking, switching equipment, firmware, and remote-management components must also be treated as integral parts of critical infrastructure.

16

The real battlefield in the technological competition between the United States and the Chinese Communist Party is not always found in the most visible semiconductor fabrication plants or social-media platforms.

It also exists in every route taken by a packet of American data, in the Wi-Fi router sitting in the corner of a living room, and in the inconspicuous optical module behind a rack of AI servers. The greatest danger the Chinese Communist Party poses to the United States may not be its ability to suddenly “turn off the American internet” one day.

The more realistic risk is that companies controlled or heavily influenced by Beijing may remain for years inside the least visible layers of America’s digital infrastructure. Once enough of these positions accumulate, they can provide intelligence and surveillance advantages during peacetime and potentially become tools for network disruption and strategic coercion during a major crisis.

The United States has already spent years trying to keep Huawei out of the core of its 5G networks.

The next question is more difficult: Does Washington actually know how much China-linked technology, equipment, and connectivity has already entered the United States and remains operational today?

If the answer is no, America’s greatest cybersecurity vulnerability may not be the absence of another firewall.

It may be that the United States still does not know who is already standing on the other side of it.


Return to blog