Post

Four US States Allege TP-Link Defrauded Customers, Seek Damages

Four US States Allege TP-Link Defrauded Customers, Seek Damages

Four US states have filed lawsuits against TP-Link Systems, alleging that the company misled consumers about the security of its products and underplayed its ties to the Chinese government. According to the lawsuit, TP-Link overstated its security protection by claiming it covers all security scenarios and promised a 100% safeguard as recently as November 2025. The lawsuits seek injunctions, civil penalties, and the return of money obtained through the alleged infractions. They also seek damages for small companies that become unwitting accomplices to larger campaigns against critical infrastructure by Chinese threat actors, as well as Russian threat groups.

Much of the concern for enterprises revolves around TP-Link having about 60% of the U.S. retail market share for small-office, home-office (SOHO) routers. Chinese-linked threat actors exploit these routers at small businesses and home offices to launch attacks on U.S. critical infrastructure. These routers are also used at mid-sized businesses and at branch offices of larger companies. The lawsuit alleges exploits into TP-Link routers were used in the Volt Typhoon and Flax Typhoon campaigns linked to the Chinese and used by Chinese threat actor “Storm-0940” in password-spray attacks. Volt Typhoon targeted the energy, rail, water, and aviation sectors, while Flax Typhoon aimed for the academic, government, and IT sectors. According to the Florida lawsuit, the risk to consumers and the public at large is ongoing: many consumers keep their routers for years, and many of the compromised TP-Link models in homes do not support automatic firmware updates and no longer receive security support at all.

This activity has prompted federal government action. The Federal Communications Commission banned the sale of foreign-produced Wi-Fi routers in the U.S. in March. TP-Link has not yet been granted a temporary conditional exemption, which means it still can’t sell its new Wi-Fi 8 routers in the U.S. John Gallagher, vice president at Viakoo, said the lawsuits serve as notice to TP-Link that its actions are not going unnoticed, but otherwise does nothing to address the core issue of OT/IoT security for organizations still using these routers: legal battles take years; threat actors strike in minutes. Gallagher recommended, “Organizations need to take action immediately, starting with having an accurate inventory of TP-Link routers, followed by a decommissioning program.” He added, “Consumer grade routers and ones unsupported for new firmware updates have no place in enterprise situations.”

Adam Marrè, chief information security officer at Arctic Wolf, noted that customers have a right to expect that the security being promoted to them is being taken seriously beyond just marketing claims. Marrè warned, “The vulnerabilities cited in the complaints are evidence of the prevalence of attackers targeting devices at the edge. They are often neglected when it comes to monitoring and slow to be updated. Every internet-facing device is a potential foothold for attackers, and any company who fails to prioritize securing devices at the edge are creating risk for both their customers and the broader ecosystem.” Tony Turner, vice president of product at Frenos, stated that teams should patch supported equipment when they can, but more urgently, reduce the attack surface by eliminating web and management interfaces on internet and untrusted networks and long-term, prioritize replacement of unsupported routers. Turner concluded, “Most edge networking device security failures are preventable through better hardening and configuration by removing access to the vulnerable attack surface.”

To read the complete article see: Read full article

This post is licensed under CC BY 4.0 by the author.