Published On: October 7, 2026Categories: Holding Businesses Accountable, Press Release

HELENA – Montana Attorney General Austin Knudsen joined a coalition of 21 state attorneys general in asking the Federal Communications Commission (FCC) to scrutinize the China-founded technology company TP-Link Systems Inc. (TP-Link), as they seek conditional approval to sell new router models in the United States. The company’s routers may pose national security risks due to the company’s close ties to the Chinese Communist Party.

In the letter sent Wednesday to FCC Chairman Brendan Carr and Commissioners Anna Gomez and Olivia Trusty, Attorney General Knudsen raises concerns with TP-Link’s routers, as the company has close connections to China and made false statements to consumers about the privacy and security of their products. Attorney General Knudsen also filed a lawsuit against TP-Link, which controls at least 60 percent of the United States retail market for Wi-Fi systems and small-office and home-office routers, for violating the Montana Consumer Protection act Tuesday.

“TP-Link routers should be considered a Trojan horse planted by the Chinese Communist Party to spy on Americans. I hope the FCC seriously considers TP-Link’s concerning practices and declines to grant the conditional approval they are seeking for the sake of our national security,” Attorney General Knudsen said.

While TP-Link Systems Inc., founded in Shenzhen, China in 1996 and now headquartered in California, claims a May 2024 corporate split from China’s TP-Link Technologies Co., Ltd., Bloomberg reports roughly 11,000 employees remain in China, along with the company’s research, development, and manufacturing. Meanwhile, the company only employs roughly 300 people in the United States.

Further, TP-Link claims to manufacture its U.S.-market products in Vietnam, but less than one percent of the components by value are sourced in Vietnam and the rest are imported from or through China.

TP-Link also promises consumers their routers are secure. However, their routers have contained critical, actively exploited firmware vulnerabilities, which were exploited by Chinese state hackers to weaponize consumers’ routers in the Volt and Flax Typhoon attacks, according to congressional testimony. Russia’s GRU foreign military intelligence agency has also exploited TP-Link’s insecure routers. The company also advertises that HomeShield covers “all security scenarios” and formerly promised a “100% safeguard,” and made other model-specific claims, despite known, actively exploited flaws in the products.

Additionally, TP-Link’s apps collect consumers’ email addresses, location, and device identifiers while reserving the right to share data with affiliates or “to comply with applicable laws” without disclosing that its Chinese affiliates are subject to the 2017 National Intelligence Law and the 2021 Regulations on the Management of Security Vulnerabilities, which require reporting new vulnerabilities to the Chinese government within two days.

“We stand ready to work with the FCC to protect American consumers. Our consumer-protection concerns are focused on ensuring that 1) previously harmed consumers are protected from further depredation and 2) going forward, consumers are protected from exploitation by the Chinese Communist Party,” the letter states.