Full Breakdown
FCC Reverses Cybersecurity Standards for Internet Providers
11/22/2025, 12:05:55 AM
FCC Vote and New Regulations
On a recent Thursday, the Federal Communications Commission (FCC) voted 2-1 along party lines to eliminate minimum cybersecurity standards for internet service providers (ISPs) and cellular carriers. This decision reverses a ruling made just days before President Donald Trump's inauguration, which mandated that providers submit annual certifications demonstrating their cybersecurity risk management plans. The previous regulations were largely a response to the Salt Typhoon cyberattack in September 2022, where hackers linked to the Chinese government infiltrated the networks of major U.S. providers, including AT&T, Verizon, and Lumen Technologies. The breach reportedly allowed attackers to access millions of customers' metadata and audio recordings from individuals associated with both the Trump and Harris campaigns.
Implications of the Decision
FCC Chair Brendan Carr defended the rollback, asserting that ISPs have shown a strengthened cybersecurity posture since the Salt Typhoon incident, making the regulations unnecessary. Critics, however, argue that this move could leave significant vulnerabilities unaddressed. Mark Warner, vice chairman of the Senate Select Committee on Intelligence, expressed concern that the elimination of these requirements undermines efforts to address the security gaps exposed by the cyberattack, including issues like credential reuse and the lack of multi-factor authentication for sensitive accounts.
Industry Response and Lobbying
The ruling has been hailed as a victory for telecommunications companies, which have actively lobbied for the removal of these cybersecurity requirements. Industry groups contended that the long-standing collaboration between the government and the private sector has rendered such regulations redundant and potentially harmful. Blair Levin, a former FCC chief of staff, criticized this perspective, suggesting that a lack of oversight could lead to diminished cybersecurity standards.
Criticism and Concerns
The decision has drawn sharp criticism from cybersecurity experts and lawmakers. Cooper Quintin, a senior staff technologist at the Electronic Frontier Foundation, described the rollback as "rolling out the red carpet for another attack," emphasizing the potential risks to everyday Americans. Quintin noted that while the Salt Typhoon incident targeted government officials, the implications for the general public could be severe, with increased risks of scams and cybercrime.
Official Statements & Responses
In response to the FCC's decision, Senator Maria Cantwell highlighted the dangers posed by the Salt Typhoon attack, stating that it allowed the Chinese government to "geolocate millions of individuals" and "record phone calls at will." Carr dismissed these concerns, arguing that merely implementing regulations for the sake of action is not a viable solution.
Verbatim Quotes
- “This is such a terrible idea. This is rolling out the red carpet for another attack,” — Cooper Quintin, Senior Staff Technologist, Electronic Frontier Foundation
- “You have now proposed to reverse this requirement after heavy lobbying from the very telecommunications carriers whose networks were breached by Chinese hackers,” — Maria Cantwell, U.S. Senator
- “Doing anything just so we can say we did something is not the answer.” — Brendan Carr, FCC Chair
What's Next
As the FCC steps back from monitoring cybersecurity standards, experts stress the importance of individual cybersecurity practices. Recommendations include using strong, unique passwords, enabling multi-factor authentication, and utilizing Virtual Private Networks (VPNs) to enhance personal security against potential future attacks.
