Four U.S. states jointly sued TP-Link, accusing it of exaggerating its security capabilities and concealing its connections with the Chinese supply chain.

📅 2026-10-08

Abstract:

A number of U.S. state governments have recently launched legal proceedings against network equipment manufacturer TP-Link, accusing the company of misleading consumers on product safety promotions and corporate ties to China. Joining the prosecution are the attorneys general offices of Florida, Iowa, Montana and Nebraska.

According to the complaint, TP-Link Systems, headquartered in California, USA, is accused of exaggerating the security capabilities of its routers during the marketing process, while failing to fully disclose its connections with relevant Chinese companies and supply chains. The state argued that these practices constituted deceptive and unfair business practices.

TP-Link has long occupied an important position in the US consumer network equipment market. According to data from market research organization Circana, the company's sales share in the US router market in 2024 will be approximately 36.6%, and its sales share will be approximately 31%.

The lawsuit documents pointed out that TP-Link has publicly stated that its business operations have been cut off from China and some production activities have been transferred to Vietnam. However, the plaintiff state government cited investigation data and stated that the company's R&D and manufacturing systems are still highly dependent on Chinese companies and supply chains. According to the complaint, only about 0.5% of the parts and components used in Vietnamese factories come from Vietnam in terms of value, and most of the remaining inputs are obtained through the Chinese supply chain.

The state government also claimed that a company identified by the United States as having ties to the Chinese military had participated in the construction of TP-Link's Vietnam factory, thus questioning the company's claims about the independence and security of the supply chain.

In terms of network security, the lawsuit specifically mentions that some TP-Link products have been used by hacker groups with Chinese and Russian backgrounds. The document quoted the testimony of former NSA cybersecurity director Rob Joyce that TP-Link routers had appeared in China-related cyber attack operations such as "Volt Typhoon" and "Flax Typhoon."

The plaintiff also questioned some of TP-Link’s marketing propaganda. For example, the company once claimed that its HomeShield security service can cover "all security scenarios" and stated on its website that it can provide "100% network security guarantee." The state government believes that such representations are inconsistent with the actual serious security vulnerabilities of the products and can easily cause consumers to have misunderstandings about the protective capabilities of the equipment.

Faced with the accusation, TP-Link strongly refuted it. Steve Kofsky, the company's head of corporate affairs, said these lawsuits are based on false premises and will not only do nothing to improve national security, but will unfairly hit an important company operating in the United States.

TP-Link emphasized that the products sold to the U.S. market are all manufactured in Vietnam, and the company is an independent U.S. company not controlled by any foreign government. The company also denies that its products pose a threat to user security or that it provides user network data to foreign governments, saying the accusations are baseless.

As the U.S. government and state regulators continue to increase scrutiny of critical network infrastructure and consumer electronics equipment supply chains, the lawsuit against TP-Link once again highlights the United States’ long-term concerns about cybersecurity, data privacy, and the influence of China’s technology supply chain. The subsequent development of the case and the court's final ruling are expected to have a broad impact on the U.S. network equipment market.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet