US states sue TP-Link, claiming router ties to China expose millions of Americans to hackers
The lawsuit claims that the firm's China ties make it easier for both Chinese and Russian state actors to target Americans.

Four US states have sued TP-Link. By Cybernews.
- Four US states allege TP-Link misled customers about its China ties and supply chain.
- A complaint says only 0.5% of components at TP-Link’s Vietnam factory come from Vietnam.
- Officials cite alleged exploitation of TP-Link routers by Chinese and Russian state-backed hackers.
- TP-Link denies the allegations and says its products meet high security standards.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The lawsuit by the attorneys general of Florida, Iowa, Montana, and Nebraska says TP-Link, which was founded in China but is now officially based in California, concealed facts about its “past and ongoing ties to the People’s Republic of China,” and still has a supply chain that relies on Chinese firms for research, development, and manufacturing.
That’s despite previously claiming to have moved into Vietnam after breaking ties with China in 2024.
According to the complaint, only 0.5% of components used at the vendor’s Vietnamese factory are sourced in Vietnam: everything else is allegedly imported “from or through China.”
Moreover, “a US-designated Chinese military company performed recent construction at the Vietnam factory, further evidencing the deceptiveness of TP-Link’s assurances of additional security based on its Vietnam activities,” the complaint adds, quoting Bloomberg.
Has your password leaked?
Even though TP-Link claims that no government, foreign or domestic, has access to its routers and other devices, the complaint claims this is misleading.
Suspicious links and threats
“Much of TP-Link’s research, development, and manufacturing remains in China, entrenched in China’s state-sponsored technology ecosystem, with the company’s leadership acknowledging accolades and subsidies from the Chinese government,” the complaint claims.
Exploitation of TP-Link devices by Chinese and Russian state-backed hackers is also cited and contrasted with the company’s claims that its HomeShield product “covers all security scenarios.”
The complaint, quoting a 2025 testimony from former NSA cybersecurity director Rob Joyce, highlights that TP-Link routers were exploited in the China-linked Volt Typhoon and Flax Typhoon campaigns.
Additionally, according to the FBI and NSA, Russia’s GRU military intelligence agency has exploited a critical vulnerability in TP-Link’s TL-WR940N router to conduct adversary-in-the-middle attacks.
During such attacks, a consumer believes they are securely communicating with services such as Microsoft Outlook Web Access, while the GRU views the traffic unencrypted.
The United Kingdom’s National Cyber Security Centre warned recently that Fancy Bear, a group attributed to Russian military intelligence, was breaking into TP-Link routers across the country.
Microsoft has likewise reported that a covert network comprised predominantly of compromised TP-Link routers has been used by Chinese threat actors to conduct credential-theft attacks against American organizations.
TP-Link’s response to the lawsuit
According to congressional testimony, TP-Link controls at least 60% of the US retail market for WiFi systems and small-office/home-office routers.
“As a result of their nefarious practices, millions of Americans have unknowingly invited a foreign adversary into their living rooms and put their personal information at risk,” said Montana’s Attorney General Austin Knudsen.
Early in 2026, the state of Texas also took TP-Link to court and accused it of links with China, blaming the company for cyberattacks on US soil for good measure.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Just like in February, TP-Link now claims the lawsuits from 4 more US states are “without merit” and are based on false premises. The company says it’s looking forward to “refuting these baseless allegations in court.”
“TP-Link Systems is a US company that complies with US privacy and data protection laws,” said Steve Kovsky, TP-Link’s corporate affairs officer.
“We perform comprehensive security testing and rely on trusted third-party security labs for additional scrutiny to ensure our products meet the highest security standards and are recognized as among the most secure on the market.”