Researchers detail how state-owned China Telecom, the third largest carrier in the country, regularly hijacks internet traffic passing through the US and Canada
Context & Ripple Effects
This report lands at the start of a six-year pattern: researchers flagging how much of the world's traffic transits equipment controlled by a single state-owned carrier. A year later, a BGP leak at a Swiss colocation company again pushed European mobile traffic through China Telecom — whether accident or not, the routing topology kept funneling foreign data into the same pipes.
The traffic story also foreshadows the intrusion stories that followed: McAfee researchers later documented a Chinese cyberespionage campaign hitting at least 23 telcos across the US, Europe, and Southeast Asia, and by 2024 the Salt Typhoon campaign had breached US ISPs like Verizon and AT&T, reportedly reaching wiretap systems. Routing-level access and network-level compromise turned out to be two faces of the same target.
First-order effects
- US and Canadian networks transiting China Telecom's routes have their traffic exposed to a state-owned carrier that researchers say redirects it on a regular basis, making every interconnection decision with the carrier a security decision.
- Network operators and large content providers must now treat China Telecom's announcements as untrusted, forcing re-evaluation of peering and transit contracts that were previously priced purely on cost.
Second-order effects
- Rival transit providers gain a selling point — route diversity away from state-owned Chinese carriers — while customers demand filtering and validation (such as route-origin checks) as contract terms rather than best-effort hygiene.
- Western governments face pressure to scrutinize foreign state-owned carriers' points of presence on domestic soil, the same lens later applied when Salt Typhoon showed what persistent access to ISP networks yields.
Third-order effects
- If the pattern holds, the internet's backbone stops being neutral plumbing: carrier selection becomes a geopolitical act, and states respond by ring-fencing domestic transit the way they already restrict foreign vendors in radio access networks.
- Telecom operators become first-class intelligence targets regardless of borders — the trajectory from routing manipulation to the telco espionage campaigns and ISP breaches in the related coverage suggests infrastructure ownership and network security are converging into one regulatory question.
The trend: Internet backbone transit is being reclassified from a commercial commodity into national-security terrain, with state-owned carriers' routing behavior serving as an early warning of the telecom intrusions that followed.