Texas sues TP-Link, alleging it allows China to hack into routers

Texas is suing networking equipment company TP-Link Systems for allegedly allowing the Chinese Communist Party (CCP) to hack into consumers’ devices even as it promised consumers strong security and privacy protections.

Attorney General Ken Paxton announced the lawsuit on Monday and said it is the first of several that will be filed this week against companies affiliated with the CCP.

In December, Paxton sued the Chinese television manufacturers Hisense and TCL, alleging that they capture what consumers watch in real time and could be allowing the data to be harvested by China.

Paxton alleges that TP-Link deceptively markets its products as protective of privacy and security when in reality they have been used by Chinese state-sponsored hacking groups to mount cyberattacks against the U.S.

His office cited a May 2023 report from Check Point Research, which alleged that Camaro Dragon hacking campaigns were enabled by TP-Link firmware vulnerabilities. Camaro Dragon is a Chinese state-sponsored hacking entity.

Because many of TP-Link’s parts are imported from China, the manufacturer is bound by that government’s national data laws, which require Chinese companies to support the country’s intelligence services by “divulging Americans’ data,” a Paxton press release said.

“With nearly all of its products’ parts imported from China, TP Link’s deliberate deception towards Texans regarding the nationality, privacy, and security capabilities of its networking devices is not just illegal — it is also a national security threat that enables the secret surveillance and exploitation of Texas consumers,” the press release said.

A spokesperson for TP-Link said in a statement that the lawsuit is “without merit and will be proven false.” 

TP-Link Systems Inc. is an independent American company, the statement noted, and its core operations and infrastructure are located entirely within the U.S. All U.S. users’ networking data is stored securely on Amazon Web Services servers, the statement said, and the company’s founder and CEO lives in California.

“We will continue to vigorously defend our reputation as a trusted provider of secure connectivity for American families,” the statement said.

The U.S. intelligence community has expressed similar concerns about the potential of TP-Link devices to enable Chinese government espionage, security consultant John Bambenek told Recorded Future News. 

However, the lawsuit will likely have little effect, he said.

“Using deceptive business practices seems to be a clever way of tackling this problem, but I am hard-pressed to see any scenario [where] any order by a Texas court would be respected in China,” he said. 

The lawsuit is an example of a significant evolution in cybersecurity enforcement and a broader regulatory trend, said Nakul Goenka, risk officer at security company ColorTokens.

“Security representations are increasingly being evaluated as consumer protection and disclosure issues, not merely technical ones — a shift already visible in FTC enforcement actions and SEC disclosure mandates, and now extending into state-level litigation,” he said. 

“The key legal question is not whether a vulnerability exists, but whether a company’s public statements about privacy, security, and product origin accurately reflect the underlying risk.”

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Suzanne Smalley

Suzanne Smalley

is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

 

Total
0
Shares
Previous Post

Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist’s Phone in Police Custody

Related Posts

Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts

Cloudflare on Wednesday said it detected and mitigated the largest ever distributed denial-of-service (DDoS) attack that measured at 29.7 terabits per second (Tbps). The activity, the web infrastructure and security company said, originated from a DDoS botnet-for-hire known as AISURU, which has been linked to a number of hyper-volumetric DDoS attacks over the past year. The attack lasted for 69
Read More

Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions

Trend Micro has released security updates to address multiple security vulnerabilities impacting on-premise versions of Apex Central for Windows, including a critical bug that could result in arbitrary code execution. The vulnerability, tracked as CVE-2025-69258, carries a CVSS score of 9.8 out of a maximum of 10.0. The vulnerability has been described as a case of remote code execution
Read More