The Federal Communications Commission (FCC) is reversing a previous ruling that required U.S. telecommunications providers to implement stricter cybersecurity measures following a massive attack by the Chinese threat group known as Salt Typhoon. The ruling was issued in January 2025 and took effect immediately under the Communications Assistance for Law Enforcement Act (CALEA), in response to Salt Typhoon’s breaches of multiple providers to spy on private communications.
See also: FCC: Tighter restrictions on Chinese telecom equipment

Along with Section 105 of CALEA, the decision included a Notice of Proposed Rulemaking (NPRM) for telecommunications companies to:
– Create and implement cybersecurity risk management plans
– They submit annual certifications to the FCC proving that they do so
– Treat general network cybersecurity as a legal obligation
After pressure from telecommunications companies, who found the new framework too burdensome and burdensome for their operations, the FCC has now deemed the previous rule inflexible and repealed it.
See also: FCC: Robocalls "targeted" staff and their families

The FCC, now under new leadership, noted that communications service providers have taken significant steps to strengthen their cybersecurity posture following the Salt Typhoon incidents and have agreed to continue on this path in a coordinated manner, reducing national security risks. It was revealed in October 2024 that the Salt Typhoon attacks were linked to a Chinese espionage campaign that affected multiple companies, including Verizon, AT&T, Lumen Technologies, T-Mobile, Charter Communications, Consolidated Communications, and Windstream.
Hackers gained access to key systems that the US federal government was using for court-ordered network surveillance requests and likely stole highly sensitive information, down to the level of government officials. Given that the risk of similar hacking operations remains unchanged, the FCC's latest decision has been met with criticism.
See also: Ron Wyden: Proposes telecommunications security bill

Commissioner Anna M. Gomez, the only one to vote against the current ruling, expressed frustration with the reliance on telecommunications providers to self-assess their cybersecurity posture and the effectiveness of protective measures. Senators Maria Candwell and Gary Peters also sent letters to the FCC before the vote urging the agency to maintain cybersecurity safeguards.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
