BREACH WATCH BRIEF High 📡 Threat intel

Five US States Sue TP‑Link Over Router Security Claims Amid FCC Ban on New Foreign‑Made Devices

Five state attorneys general allege TP‑Link misled consumers about router security and failed to disclose Chinese affiliations, while the FCC bans new foreign‑made routers. This highlights the need for robust vendor‑risk oversight and continuous control‑assurance evidence.

SeverityHigh
Type📡 Threat intel
ConfidenceHigh
ReportedOct 8, 2026
Technology & SaaS Technology Third-Party Dependency
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

State attorneys general in Florida, Iowa, Montana, Nebraska and Texas filed lawsuits claiming TP‑Link misrepresented the security of its home routers and did not adequately disclose ties to Chinese affiliates. The suits align with an FCC rule that prohibits certification of new foreign‑produced routers, though existing devices remain usable.

Why it matters for trust and compliance

  • The case underscores the importance of a continuous third‑party risk management program that validates vendor security claims and supply‑chain transparency, providing audit‑ready evidence of due diligence.
  • Documented vendor assessments satisfy control‑assurance requirements for supply‑chain risk.
  • Continuous monitoring of hardware vendors creates a defensible audit trail.

Who is affected

Technology

Recommended actions

  1. Inventory all TP‑Link routers and verify firmware versions.
  2. Collect and review vendor security disclosures and past vulnerability patches.
  3. Develop a migration plan for high‑risk or unsupported devices.
  4. Record evidence of the assessment for audit readiness.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.