The Federal Communications Commission voted 2-1 along party lines on Thursday to scrap rules that required U.S. phone and internet giants to meet certain minimum cybersecurity requirements.
The FCCโs two Trump-appointed commissioners, chairman Brendan Carr and his Republican colleague Olivia Trusty, voted to withdraw the rules that require telecommunications carriers to โsecure their networks from unlawful access or interception of communications.โ The Biden administration had adopted these rules prior to leaving office earlier this year.
The FCCโs sole Democratic commissioner, Anna Gomez, dissented. In a statement following the vote, Gomez called the now-overturned rules the โonly meaningful effort this agency has advancedโ since the discovery of a sweeping campaign by a China-backed hacking group called Salt Typhoon that involved hacking into a raft of U.S. phone and internet companies.
The hackers broke into more than 200 telcos, including AT&T, Verizon and Lumen, during the years-long campaign to conduct broad-scale surveillance of American officials. In some cases, the hackers targeted wiretap systems that the U.S. government previously required telcos to install for law enforcement access.
The FCCโs move to change the rules sparked rebuke from senior lawmakers, including Sen. Gary Peters (D-MI), the ranking member of the Senate Homeland Security Committee. Peters said he was โdisturbedโ by the FCCโs effort to roll back โbasic cybersecurity safeguardsโ and warned that doing so will โleave the American people exposed.โ
Sen. Mark Warner (D-VA), the ranking member of the Senate Intelligence Committee, said in a statement that the rule change โleaves us without a credible planโ to address the basic security gaps exploited by Salt Typhoon and others.
For its part, the NCTA, which represents the telecommunications industry, praised the scrapping of the rules, calling them โprescriptive and counterproductive regulations.โ
But Gomez warned that while collaboration with the telecommunications industry is valuable for cybersecurity, it is insufficient without enforcement.
โHandshake agreements without teeth will not stop state-sponsored hackers in their quest to infiltrate our networks,โ said Gomez. โThey wonโt prevent the next breach. They do not ensure that the weakest link in the chain is strengthened. If voluntary cooperation were enough, we would not be sitting here today in the wake of Salt Typhoon.โ


