US states sue popular kitmaker TP-Link over China risks

US states sue popular kitmaker TP-Link over China risks

The attorneys general of Florida, Iowa, Montana, and Nebraska have sued ubiquitous networking and smart home tech maker TP-Link, alleging its security claims were misleading and it hadn’t properly disclosed ties to China. The company has a large presence in US retail and the tech channel, especially in consumer routers, with stats from Circana asserting it had around 36.6 percent US market share by units and 31 percent by dollars in 2024. The complaint [PDF] accuses California-based TP-Link Systems, whose brand originated in Shenzhen, of deceptive and unfair marketing practices concerning its routers’ security and its connections to China. It cites exploitation of TP-Link devices by Chinese and Russian state-backed hackers. The suit also claims TP-Link allegedly concealed facts about its “past and ongoing ties to the People’s Republic of China,” accuses it of having a supply chain that’s reliant on PRC players, repeated firmware vulnerabilities, and being subject to Chinese laws that force companies to cooperate with state intelligence. According to the states’ attorneys general, the hardware vendor still relies on Chinese companies for research and development and manufacturing operations, despite previously claiming to have moved into Vietnam after severing ties with China. The complaint alleges that only 0.5 percent of components used at TP-Link’s Vietnamese plant, measured by value, are bought in Vietnam, with “all other inputs” imported “from or through China.” The complaint also claims that a US-designated Chinese military company carried out construction work at the Vietnamese factory, challenging TP-Link’s assurances about its supply chain’s security. The complaint cites 2025 testimony [PDF] from former NSA cybersecurity director Rob Joyce that TP-Link’s share of the US retail market for Wi-Fi systems and small-office/home-office (SoHo) routers at at least 60 percent. Lawyers pointed to various snippets from TP-Link’s marketing materials. These included claims that its HomeShield product “covers all security scenarios” and, on a version of its website available in November 2025, provides a “100 percent safeguard” for network security. The complaint argues that TP-Link’s security assurances were misleading because its routers contained critical vulnerabilities. It further cites Joyce’s that TP-Link routers were among the brands exploited in the China-linked Volt Typhoon and Flax Typhoon campaigns. The complaint also alleges that TP-Link’s privacy policies permit it to collect customer data and share it with affiliates without disclosing how its Chinese connections and China’s intelligence laws could expose that information to Chinese intelligence agencies. “Iowans’ sensitive data and our national security is at risk because of TP-Link and their connection to the communist Chinese government,” said Iowa Attorney General Brenna Bird. “TP-Link tells Iowans its routers are safe, our personal data is secure, and that they have no ties to China. They are not telling the truth. It’s time to hold China and China-backed companies accountable.” “TP-Link’s false statements and deceptive advertising are a violation of Montana law,” said Attorney General Austin Knudsen. “As a result of their nefarious practices, millions of Americans have unknowingly invited a foreign adversary into their living rooms and put their personal information at risk. “I will do everything I can as Attorney General to hold TP-Link accountable and protect our privacy and security.” Steve Kovsky, corporate affairs officer for TP-Link Systems Inc., said the lawsuits were based on false premises, did nothing to advance national security, and unfairly penalized a US company. Kovsky added that the company has spent months providing officials with clear documentation showing that it is not owned or controlled by any foreign government and that its devices sold in the US are manufactured in Vietnam. “Any claims that our products present a threat to user security or grant unauthorized network access to foreign governments are baseless,” he said. “TP-Link Systems is a US company that complies with US privacy and data protection laws. We perform comprehensive security testing and rely on trusted third-party security labs for additional scrutiny to ensure our products meet the highest security standards and are recognized as among the most secure on the market. “We meet or exceed all industry best practices for monitoring and preventing vulnerabilities and actively support our customers to mitigate any issues that occur as they are identified. We do not, and will not, share customer network data with foreign governments or unauthorized third parties. “We stand fully behind the security of our products, the integrity of our company and our people, and our commitment to serving the best interests of our customers in the United States and globally. We look forward to refuting these baseless allegations in court.” The allegations echo those made by Texas Attorney General Ken Paxton, whose office sued TP-Link earlier this year over its Chinese connections and router security. US officials began weighing restrictions on TP-Link router sales in 2024. In March 2026, the FCC imposed broader restrictions [PDF] on new foreign-produced router models, barring new equipment authorizations unless an exemption is granted. Previously authorized models were not automatically banned. ®

By jawad