Published On: October 6, 2026Categories: Holding Businesses Accountable, Press Release

HELENA – Montana Attorney General Austin Knudsen filed a lawsuit today against the China-founded technology company, TP-Link, for misleading Montanans and putting users’ personal information at risk of being shared with the Chinese government, a foreign adversary of the United States. The lawsuit names TP-Link Systems, Inc., which is a company incorporated in California. 

The lawsuit, filed in Lewis and Clark County, alleges TP-Link, which controls at least 60 percent of the Untied States retail market for Wi-Fi systems and small-office and home-office routers, has made false and misleading claims about the security of its devices and its reliance on China. Additionally, TP-Link reserves the right not only to collect Montanans’ personal data, including email addresses, location, and mobile phone identifies, but also share the data with “affiliates” while failing to disclose the legal requirements of Chinese intelligence laws.

TP-Link’s false and deceptive security representations; corporate-separation, supply-chain, and manufacturing misrepresentations; data-practices omissions; and unfair acts or practices are violations of the Montana Consumer Protection Act. Attorney General Knudsen is asking the court for a permanent injunction barring TP-Link from continuing their deceptive, unfair, and unconscionable practices and civil penalties of $10,000 per violation.

“TP-Link’s false statements and deceptive advertising are a violation of Montana law. As a result of their nefarious practices, millions of Americans have unknowingly invited a foreign adversary into their living rooms and put their personal information at risk,” Attorney General Knudsen said. “I will do everything I can as Attorney General to hold TP-Link accountable and protect our privacy and security.”

While TP-Link Systems Inc., founded in Shenzhen, China in 1996 and now headquartered in California, claims a May 2024 corporate split from China’s TP-Link Technologies Co., Ltd., Bloomberg reports roughly 11,000 employees remain in China, along with the company’s research, development, and manufacturing. Meanwhile, the company only employs roughly 300 people in the United States.

Further, TP-Link claims to manufacture its U.S.-market products in Vietnam, but less than one percent of the components by value are sourced in Vietnam and the rest are imported from or through China.

TP-Link also promises consumers their routers are secure. However, their routers have contained critical, actively exploited firmware vulnerabilities, which were exploited by Chinese state hackers to weaponize consumers’ routers in the Volt and Flax Typhoon attacks, according to congressional testimony. Russia’s GRU foreign military intelligence agency has also exploited TP-Link’s insecure routers. The company also advertises that HomeShield covers “all security scenarios” and formerly promised a “100% safeguard,” and made other model-specific claims, despite known, actively exploited flaws in the products.

Additionally, TP-Link’s apps collect consumers’ email addresses, location, and device identifiers while reserving the right to share data with affiliates or “to comply with applicable laws” without disclosing that its Chinese affiliates are subject to the 2017 National Intelligence Law and the 2021 Regulations on the Management of Security Vulnerabilities, which require reporting new vulnerabilities to the Chinese government within two days.

“TP-Link’s conduct has placed Montana consumers at risk of harm by making their home and small-office networks vulnerable to exploitation and intrusion by foreign actors with a proven track record of nefarious conduct. That risk is ongoing: many consumers keep their routers for years, and many of the compromised TP-Link models in Montana homes do not support automatic firmware updates and no longer receive security support at all,” the lawsuit states.

Federal agencies have also raised concerns over TP-Link routers and connections with China. In 2024, the Departments of Commerce, Defense, and Justice opened investigations into TP-Link concerning the national security risks posed by its routers. Last year, federal officials reportedly concluded that the company’s ties to China posed an “unacceptable risk” and were weighing a proposed plan to ban the sale of TP-Link routers in the United States. And this summer, the Department of Defense identified TP-Link Technologies as a Chinese military company.