The AGs of Florida, Iowa, Montana, and Nebraska sue TP-Link, alleging it deceptively marketed its routers' security and didn't properly disclose ties to China
First reported by The Register ·
Router security and data privacy are now under direct scrutiny for millions of consumers, potentially impacting future device purchases and network configurations.
The Attorneys General of Florida, Iowa, Montana, and Nebraska have filed a lawsuit against TP-Link, a major networking and smart home technology provider. The suit alleges that TP-Link engaged in deceptive marketing practices regarding the security of its routers and failed to adequately disclose its significant ties to China. The complaint cites exploitation of TP-Link devices by state-backed hackers from China and Russia, and claims the company concealed its ongoing connections to the People's Republic of China. It further asserts that TP-Link's supply chain remains reliant on Chinese entities, despite claims of shifting operations to Vietnam, with minimal local component sourcing. The lawsuit also points to repeated firmware vulnerabilities and TP-Link's subjection to Chinese laws that could compel cooperation with state intelligence agencies. TP-Link denies the allegations, stating its US-based operations are compliant with US laws and its products are secure.
This lawsuit signals increased regulatory scrutiny on hardware manufacturers with significant supply chain ties to China, particularly within the networking and IoT sectors. It highlights a growing concern among US officials regarding the potential for state-sponsored espionage through consumer-grade devices and the adequacy of vendor disclosures about these risks. The complaint's specific mention of exploitation by Chinese and Russian state-backed actors, along with the detailed analysis of TP-Link's supply chain reliance on China, suggests a pattern that regulators may seek to address more broadly.
The legal action directly challenges TP-Link's claims of robust security and its assertions of independence from Chinese governmental influence. This could lead to stricter disclosure requirements for hardware vendors regarding their supply chains and data handling practices. Companies will need to provide more transparent and verifiable information about their manufacturing processes and affiliations to maintain consumer trust and regulatory compliance, especially for devices handling sensitive personal and network data.
AI-written summary. May contain errors.