Hearings to examine America's communications networks

Commerce, Space, and Science NominationsSenate Commerce, Science, and Transportation Subcommittee on Telecommunications and Media · 2025-12-02 · 119th Congress
The Senate Commerce Subcommittee on Telecommunications and Media convened this hearing to examine escalating cyber, espionage, and sabotage threats to America's communications networks — including telecom carriers, undersea cables, and satellite systems — and how government and industry should coordinate to defend them. Begins at 0:17:03
Transcript
Highlights

Title

Securing U.S. communications networks from foreign cyber threats

Purpose

The Senate Commerce Subcommittee on Telecommunications and Media convened this hearing to examine escalating cyber, espionage, and sabotage threats to America's communications networks — including telecom carriers, undersea cables, and satellite systems — and how government and industry should coordinate to defend them. Witnesses Robert Mayer (USTelecom), Daniel Gizinski (Comtech), Jamil Jaffer (National Security Institute), and Deborah Jordan (former FCC Public Safety and Homeland Security Bureau chief) testified amid disagreement over the FCC's recent decision to rescind post-Salt Typhoon cybersecurity certification rules. Begins at0:17:03

Who spoke

Chair Marsha Blackburn (R-TN)0:17:03: Opened by describing China as the most active cyber threat to U.S. institutions and cited the Salt Typhoon hacking campaign0:17:34; highlighted her FACT Act on foreign-owned FCC licenses0:19:03 and recent Nebraska school and 911 outages0:19:32; later pressed witnesses on the FACT Act's scope0:52:50 and domestic manufacturing policy0:53:41.

Sen. Ben Ray Luján (D-NM), Ranking Member0:21:39: Said Salt Typhoon compromised Verizon, AT&T, and T-Mobile and is likely the largest telecom hack in U.S. history0:22:28; criticized the FCC for dismantling verification requirements in favor of "voluntary pledges"0:23:20 and noted President Trump fired the board investigating the attack0:24:06; later pressed witnesses on whether the U.S. can win the AI race while leaking IP through hacks1:00:01 and on the Cyber Safety Review Board's effectiveness2:01:38.

Chair Deb Fischer (R-NE)0:24:41: Chaired the panel, introduced witnesses0:24:41, and questioned Jaffer on what distinguishes Salt Typhoon from prior operations0:49:58 and detection capability gaps0:50:56; closed the hearing2:03:27.

Robert Mayer, USTelecom SVP of Cybersecurity and Innovation0:26:05: Argued cybersecurity frameworks must stay flexible rather than becoming rigid checklists that "shift attention... to managing paperwork"0:27:49; cited an Anthropic-linked incident where AI executed 80% of a cyberattack without human involvement1:12:00; disclosed the federal government spent $30 billion on telecom contracts and $14.3 billion on IT services from FY14-18, with $3.2 billion in FY241:59:15.

Daniel Gizinski, Comtech President of Satellite and Space Communications0:30:24: Said satellites' global reach increases their attack surface, citing a UC San Diego/University of Maryland study showing sensitive traffic could be intercepted0:31:13; recommended enabling encryption on satellite modems as a low-cost fix still not widely adopted0:31:411:19:52.

Jamil Jaffer, National Security Institute, George Mason University0:34:13: Said the U.S. is effectively "at war" in the cyber domain with China, Russia, Iran, and North Korea0:34:13; said the government identified Salt Typhoon actors in systems before realizing they were hackers, comparing it to intelligence failures before 9/110:36:52; said 93% of world internet traffic travels on undersea cables and urged treating deliberate cable cuts as attacks on critical infrastructure1:03:281:49:11.

Deborah Jordan, former FCC Public Safety and Homeland Security Bureau Chief0:39:10: Said Salt Typhoon infiltrated nine major communications providers and 200 other U.S. organizations, including officials' metadata0:40:02; said the FCC's November 20, 2025 reversal of its cyber risk management rules left no accountability process for providers' promised protections0:42:16; recommended Congress push the FCC to require the NIST Cybersecurity Framework for all telecom providers0:43:07.

Sen. Ted Cruz (R-TX), Commerce Committee Chairman0:44:35: Praised the FCC's rescission of the "misguided" January 2025 declaratory ruling as consistent with sound policy0:46:27; argued compliance checklists divert resources from real threat response0:47:21; cited the Rip and Replace program and GPS backup systems as successes0:48:34.

Sen. Marsha Blackburn (R-TN)1:02:38: Pressed Jaffer on subsea cable landing-station vulnerabilities1:03:12 and Mayer on data centers as critical infrastructure1:30:15.

Sen. Jacky Rosen (D-NV)1:08:26: Raised an August cyberattack on Nevada state systems requiring FBI response1:09:20 and asked about risks of a reactive versus proactive federal cybersecurity posture1:09:38.

Sen. Eric Schmitt (R-MO)1:15:50: Asked about minimum cybersecurity standards for federal contracts, proposing third-party security audits1:16:21; questioned satellite hardware/encryption gaps1:19:13.

Sen. John Hickenlooper (D-CO)1:20:47: Asked about federal-state information sharing gaps1:21:36 and how the FCC should incorporate post-quantum cryptography planning1:22:38.

Sen. Shelley Moore Capito (R-WV)1:26:51: Noted West Virginia's BEAD allocation dropped from $1.2 billion to $600 million after rebidding and asked how remaining funds could support cybersecurity1:26:51; raised designating data centers as critical infrastructure1:29:50.

Sen. Maria Cantwell (D-WA)1:32:59: Said Salt Typhoon let China track Americans' locations and read texts, and that AT&T and Verizon refused her request for remediation documentation1:34:39; noted the FBI took the "unprecedented step" of urging Americans to use encrypted messaging1:35:36.

Sen. Gary Peters (D-MI)1:40:51: Pressed for a 10-year extension of the 2015 Cybersecurity Information Sharing Act, set to lapse in January1:41:13; questioned why USTelecom pushed to roll back the FCC's post-Salt Typhoon cyber rules1:44:38.

Sen. Todd Young (R-IN)1:47:14: Asked about countermeasures for undersea cable cutting given his work on the Intelligence Committee1:47:29; discussed who should bear the cost of cable redundancy1:51:51.

Key moments

Jordan testified Salt Typhoon infiltrated nine major U.S. communications providers and 200 other organizations, capturing metadata on then-candidates Trump, Vance, and Harris and members of Congress, and compromising law enforcement wiretap request logs0:40:020:40:30.

Jordan said the FCC's November 20, 2025 reversal of proposed cyber risk management certification rules left "no process by which providers will be held accountable"0:42:160:42:43.

Cruz praised the FCC's rescission of the Biden-era 2025 declaratory ruling as sound policy that avoids "chilling" compliance-driven regulation0:46:270:47:38, directly contrasting with Jordan's and Lujan's criticism of the same rollback.

Jaffer said the government had identified Chinese hackers in U.S. systems before the Salt Typhoon breach was recognized, comparing the failure to intelligence gaps before 9/11, and that hackers may still be embedded in networks0:36:520:51:06.

Mayer disclosed that in a recent incident, an AI platform (Anthropic) executed 80% of a cyberattack without human intervention, a share he said will keep rising1:12:00.

Lujan pressed Mayer with a yes/no question on whether America can win the AI race while leaking IP through telecom hacks; Mayer declined to answer yes or no, prompting Lujan to answer "no" himself1:00:011:00:26.

Cantwell said AT&T and Verizon refused her request for documentation on Salt Typhoon remediation, and that the FBI and CISA took the "unprecedented step" of urging Americans to use encrypted messaging because telecom networks could not be trusted1:34:391:35:36.

Jaffer proposed treating deliberate undersea cable cuts by adversaries as attacks on critical infrastructure, noting Russian surveillance of cables and Chinese cable-cutting incidents near Taiwan and the Baltics1:49:111:49:33.

Capito noted West Virginia's broadband deployment allocation fell from $1.2 billion to $600 million after rebidding, and pressed whether remaining funds could be redirected to cybersecurity1:26:51.

Peters noted the Cybersecurity Information Sharing Act of 2015 lapses at the end of January without reauthorization; Mayer said a 10-year extension is needed so information-sharing isn't renegotiated "every few years or every few months"1:41:131:43:15.

Metadata

CommitteeSenate Commerce, Science, and Transportation Subcommittee on Telecommunications and Media
Chamber / CongressSenate · 119th Congress
Date2025-12-02
TypeMeeting
Witnesses
(none listed in event metadata)
Videosenate-isvp
Transcript302 caption blocks · 14,182 words · 2:03:39 runtime
EventCongress.gov 337700