Four State AGs File TP-Link Lawsuits Over Router Claims
Independently fact-checked against primary sources (last audited October 10, 2026). · 18 primary sources cited on this page. How we verify our legal content

Four State AGs File TP-Link Lawsuits Over Router Claims
Florida, Iowa, Montana and Nebraska each sued TP-Link Systems Inc. on October 6, 2026, alleging the company marketed its routers as secure and as separated from China when neither was true. All four are new filings, nothing has been proven, and TP-Link denies the allegations.
Information last verified on October 10, 2026. This is a developing story; we update it as the record changes.
Jurisdiction scope: This article covers the five US state consumer-protection suits against TP-Link Systems Inc. (Florida, Iowa, Montana, Nebraska and Texas) and the federal FCC and Defense Department actions those complaints cite. It does not cover private class actions, non-US proceedings, or any claim against TP-Link Technologies Co., Ltd., which is not a defendant in these cases.
What Happened
On October 6, 2026, the attorneys general of Florida, Iowa, Montana and Nebraska each filed a consumer-protection suit against TP-Link Systems Inc. in their own state court. The four complaints share a structure, a set of allegations and, in all four, the same outside counsel: Brunn (Beau) Roysden of Culper Law PLLC in Phoenix appears on the signature page of each.
Florida Attorney General James Uthmeier e-filed a five-count complaint in the Circuit Court of the Tenth Judicial Circuit, Polk County (Filing # 258584264, 10/06/2026 11:41:18 AM). All five counts arise under a single provision, Section 501.204(1) of the Florida Deceptive and Unfair Trade Practices Act: deceptive security representations, deceptive corporate-separation and supply-chain representations, data-practices omissions, unfair acts, and unconscionable acts.
Nebraska Attorney General Michael T. Hilgers filed in Keith County District Court, Case No. D68CI260000109, stamped 10/06/2026 06:27:21 AM MDT. Nebraska's pleading is the most heavily subdivided of the four: Counts I through VI under the Nebraska Consumer Protection Act, Neb. Rev. Stat. 59-1601 et seq.; Counts VII through XII under the Uniform Deceptive Trade Practices Act's unconscionability provision, Neb. Rev. Stat. 87-303.01; and Counts XIII through XVII under the UDTPA's deceptive-practices provision, Neb. Rev. Stat. 87-302. Seventeen counts, two statutes, pleaded as three grouped blocks rather than seventeen separate headings.
Iowa Attorney General Brenna Bird filed a petition in the Iowa District Court for Polk County under a single statute, the Iowa Consumer Fraud Act, Iowa Code 714.16, organized into five claim sections that track Florida's themes. Montana Attorney General Austin Knudsen filed four counts under the Montana Consumer Protection Act, Mont. Code Ann. 30-14-103 et seq., in the Montana First Judicial District Court, Lewis and Clark County; the clerk's stamp reads FILED 10/06/2026 and assigns Case No. DV-25-2026-0000720-OC to Judge Christopher David Abbott.
Texas came first and came alone. Attorney General Ken Paxton announced his office's suit on February 17, 2026, brought in Collin County District Court under the Texas Deceptive Trade Practices Act, Tex. Bus. & Com. Code 17.46, and Chapter 521 of the Texas Business and Commerce Code. That petition is signed by the Texas Consumer Protection Division, with no outside counsel.
The core allegations
Two allegations drive all five cases. The first is that TP-Link marketed devices as secure while shipping and supporting models with known, actively exploited firmware flaws. The second is that TP-Link overstated how far it had separated from China.
On the manufacturing claim, the complaints allege a specific number:
"Only 0.5% of the components used in TP-Link's Vietnamese factory by value are bought in Vietnam; all other inputs are imported from or through China." Source: Florida v. TP-Link Systems Inc., Complaint para. 67
The Florida complaint attributes that figure to Bloomberg reporting based on trade data and alleges TP-Link confirmed it. The same 0.5% allegation appears in the Nebraska complaint, at paragraph 60 and again inside the Counts I through VI block, in the Montana complaint, and in the 21-state letter to the FCC. The Montana attorney general's own press release renders it as "less than one percent." The complaints further allege that a contractor the US government has designated a Chinese military company performed recent construction at the Vietnam plant.
Iowa's petition states the legal theory more cleanly than any of the others:
"Whether TP-Link's routers may be sold in the United States is a question for federal regulators. The question here is whether TP-Link told Iowans the truth about them. It did not." Source: State of Iowa ex rel. Bird v. TP-Link Systems Inc., Petition para. 7
Which corporate entity is which
This distinction is the easiest thing in the story to get wrong, and the complaints are careful about it.
The defendant in all five cases is TP-Link Systems Inc., a corporation organized under California law with its headquarters at 10 Mauchly, Irvine, California. The complaints allege it took over the US business, brand, product lines and customer relationships of the earlier TP-Link enterprise following a restructuring the company announced as complete in May 2024.
TP-Link Technologies Co., Ltd. is the China-based entity. On June 10, 2026, the Defense Department published its Section 1260H designations at 91 Fed. Reg. 35189, identifying TP-Link Technologies Co., Ltd. as a Chinese military company operating in the United States, on the grounds that "TP-Link is directly affiliated with the PLA" and is a military-civil fusion contributor to the Chinese defense industrial base. The notice lists Hikvision and Dahua in the same batch.
TP-Link Technologies Co., Ltd. is not a defendant. The Florida complaint says so expressly at paragraph 25, which also explains that the complaint uses the short form "TP-Link" to mean the defendant and, for conduct predating the restructuring, the enterprise from which the defendant was allegedly carved out. So the 1260H designation is not a finding against the company being sued. The states' theory is that the designation of the Chinese entity is a material fact the defendant allegedly failed to disclose while representing that it had separated completely from that entity.
The cyberattack allegations
The complaints allege that TP-Link routers were exploited in named campaigns, and they rest those attributions on federal and vendor sources rather than on the states' own findings.
For the Volt Typhoon and Flax Typhoon campaigns, the Florida and Montana complaints cite March 5, 2025 congressional testimony by former NSA Cybersecurity Director Rob Joyce before the House Select Committee on the Chinese Communist Party, who stated that TP-Link routers were among the brands exploited by Chinese state-sponsored hackers. The National Security Determination that the FCC received from an Executive Branch interagency body on March 20, 2026, attached as Appendix C to Public Notice DA 26-278, separately states that foreign-produced routers "were directly implicated in the Volt, Flax, and Salt Typhoon cyberattacks," without naming a manufacturer.
For Storm-0940, the complaints cite a Microsoft Threat Intelligence report of October 31, 2024 describing a covert network, tracked as CovertNetwork-1658 and also known as Quad7, that Microsoft said was made up predominantly of compromised TP-Link routers and used for password-spray attacks against targets including government organizations, think tanks and the defense industrial base.
One attribution does not depend on the complaints at all. An FBI public service announcement issued April 7, 2026 (Alert No. I-040726-PSA), jointly with the NSA and 15 international partners, states that Russian GRU 85th Main Special Service Center actors, also tracked as APT28 and Fancy Bear, have been "compromising TP-Link routers using CVE-2023-50224" to hijack DNS settings and run adversary-in-the-middle attacks. CISA's Known Exploited Vulnerabilities catalog lists CVE-2023-50224 under TP-Link, product TL-WR841N, added September 3, 2025; TP-Link's own May 1, 2026 customer update identified additional affected models and the complaints allege the company admitted the flaw reaches the TL-WR940N as well. Five other TP-Link CVEs sit in the same CISA catalog, including CVE-2023-1389 for the Archer AX21.
The letter to the FCC
On October 7, 2026, the day after the four filings, Nebraska led 21 attorneys general in a letter to FCC Chairman Brendan Carr and Commissioners Anna Gomez and Olivia Trusty, addressed to WC Docket No. 18-89, ET Docket No. 21-232 and EA Docket No. 21-233 in its subject line. The copy Nebraska published carries an internal draft-stage header and no date line of its own, so the October 7 date here comes from the Nebraska and Montana news releases rather than from the document. The letter asks the Commission to weigh three consumer-protection concerns, security representations, corporate separation and data practices, before ruling on TP-Link's reported request for conditional approval to sell new router models. It closes: "We stand ready to work with the FCC to protect American consumers."
The signatories are Nebraska plus Alabama, Alaska, Arkansas, Georgia, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Montana, North Dakota, Ohio, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah and West Virginia. Montana's release quotes Attorney General Knudsen saying he hopes the FCC "declines to grant the conditional approval they are seeking."
What TP-Link says
TP-Link issued a statement the same day the four suits were filed. Steve Kovsky, the company's corporate affairs officer, said:
"The coordinated lawsuits are built on false premises. They do nothing to advance national security while unfairly penalizing an industry-leading U.S. company." Source: TP-Link Systems Inc., press statement, October 6, 2026
The statement says TP-Link Systems has given state regulators "clear, verifiable documentation" of two facts: that its US-market devices are manufactured in Vietnam, and that it is an independent US company not owned or controlled by any foreign government. It calls any claim that its products grant unauthorized network access to foreign governments "baseless," says the company does not and will not share customer network data with foreign governments, and says it looks forward to "refuting these baseless allegations in court." The statement names Florida, Montana, Iowa and Nebraska. One limit on this account is worth stating plainly: we did not search the court dockets in any of the five cases, and the public portals for Collin County, Keith County, Polk County and Lewis and Clark County were not reachable to us as of October 10, 2026. Everything above rests on the filings and news releases each attorney general published and on TP-Link's own statement, so we cannot say what has been filed in any of the five cases since.
What the Law Actually Says
Every one of these suits runs on a state UDAP statute, shorthand for unfair and deceptive acts and practices. Each state has one, they are broadly worded, and the attorney general enforces them directly. They are the same statutes used against odometer rollbacks and phantom fees, pointed here at a networking device.
The specific provisions are worth separating, because what each state can win differs:
- Florida, Fla. Stat. 501.204(1), reaches "unfair methods of competition, unconscionable acts or practices, and unfair or deceptive acts or practices." Civil penalties run to $10,000 per willful violation under Section 501.2075, and $15,000 where the violation targets a senior citizen, a person with a disability, a servicemember, a servicemember's spouse or dependent child, or a veteran, under Section 501.2077.
- Iowa, Iowa Code 714.16(2)(a), reaches unfair practices, deception, misrepresentation and the concealment of material facts. Penalties reach $40,000 per violation under Section 714.16(7), plus $5,000 per violation against an older individual under Section 714.16A.
- Montana, Mont. Code Ann. 30-14-103, declares unfair or deceptive acts in trade or commerce unlawful, with penalties of not more than $10,000 per violation under Section 30-14-142.
- Nebraska uses two statutes at once: the Consumer Protection Act, Neb. Rev. Stat. 59-1602, and the Uniform Deceptive Trade Practices Act, Neb. Rev. Stat. 87-302 and 87-303.01, with penalties under Sections 59-1614 and 87-303.11.
- Texas, Tex. Bus. & Com. Code 17.46, carries penalties of up to $10,000 per violation under Section 17.47(c)(1) and up to an additional $250,000 where the practice targeted a consumer 65 or older.
Two features of UDAP law explain why these cases look the way they do.
First, a state attorney general generally does not have to prove that any individual consumer was actually deceived or lost money. Iowa's statute says so on its face at Section 714.16(2)(a), and the Texas petition cites Texas appellate authority for the same proposition. That is why the complaints are built around what the marketing said and what was omitted, not around named purchasers.
Second, the remedies are backward and forward looking but not prohibitory. Read the five prayers for relief together and the pattern is consistent: a declaration, an injunction against the challenged representations, affirmative disclosure obligations, restitution or disgorgement, civil penalties and fees. Iowa asks for both a preliminary and a permanent injunction; the others ask for permanent relief. Iowa goes furthest on disclosure, asking the court to order TP-Link to notify at its own expense every identifiable Iowa purchaser of a router that is end-of-life or subject to a known exploited vulnerability, and to disclose at the point of sale the date through which each model will receive security updates. Nebraska asks for clear and conspicuous disclosures about sourcing, China ties and known exploited vulnerabilities. Texas asks the court to enjoin "Made in Vietnam" representations and to order "Made in China" labeling instead.
None of the five asks for a recall. None asks a court to stop sales of routers as such. The word "recall" does not appear in any of the four October complaints.
Whether these devices may be sold at all is a federal question running on a separate track, and it is useful to understand how that track works because it is the one most likely to be mistaken for a ban. Under the Secure and Trusted Communications Networks Act of 2019, 47 U.S.C. 1601 to 1609, the FCC's Public Safety and Homeland Security Bureau maintains a Covered List of equipment that poses an unacceptable risk to national security. On March 23, 2026, acting on a National Security Determination from an executive branch interagency body, the Bureau added a new entry:
"Routers produced in a foreign country, except routers which have been granted a Conditional Approval by DoW or DHS." Source: FCC Public Notice DA 26-278, WC Docket No. 18-89, at 2 (Mar. 23, 2026)
Three details matter. The entry is defined by place of production, not by company, and it reaches routers produced in a foreign country "regardless of nationality of the producer," not TP-Link specifically; the Public Notice says expressly that it therefore does not trigger the rules that apply to entities "identified" on the list. Its operative effect is on equipment authorization: under 47 CFR 2.903(a), covered equipment cannot receive an FCC equipment authorization, and under 47 CFR 2.911 an applicant must certify its equipment is not covered. And producers can apply to the Department of War or the Department of Homeland Security for a Conditional Approval that exempts specific routers. That approval process is what the 21 attorneys general wrote to the FCC about.
What the Public Notice addresses is equipment authorization and the Conditional Approval process. It contains no recall provision, and it says nothing about routers that already hold an authorization or that consumers have already bought.
The Defense Department's Section 1260H list, authorized by the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021, Pub. L. 116-283, is a third and separate mechanism, and it names TP-Link Technologies Co., Ltd. rather than the defendant in these suits.
Readers tracking how states regulate connected-device data more generally will find the per-state rules on our guide to US data privacy statutes, and the three filing states with dedicated pages are covered individually: what Florida requires of companies holding consumer data, Montana's consumer data privacy regime and how Nebraska's data privacy act works. Because TP-Link also sells Tapo-branded home cameras, and the Florida and Montana complaints both reach the Tapo app's data collection, the rules on recording in and around a home are relevant background: see our state-by-state look at home camera laws.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
Everything below concerns allegations. No court has found, so far as we are aware, that TP-Link Systems Inc. did anything unlawful, and the company has denied the claims.
The notable thing here is the mechanism, not the defendant. Five states have taken a dispute that is usually framed in national-security language and moved it into consumer-protection court, where the question is narrow and familiar: did the marketing match the product. Iowa states that division expressly at paragraph 7 of its petition. A UDAP claim turns on a representation and a material omission rather than on any national-security determination, which is why these pleadings read as marketing cases.
That choice has consequences in both directions. It gives the states a forum they control, on a timetable no federal agency sets, and it lets them seek money and mandatory disclosures that no FCC proceeding would produce. It also narrows what they can win. A UDAP judgment can order a company to stop saying something, to start saying something else, to pay penalties and to return money. It cannot declare a device unsafe to own, and none of these states asked a court to try.
The practical shape of the requested relief is worth sitting with, because it is narrower than the headlines imply. Read together, the five prayers for relief ask for labeling changes, point-of-sale disclosure of a security-support end date, and in Iowa's case direct notice to identified owners of end-of-life or known-vulnerable models, alongside penalties, restitution and disgorgement. None of them asks a court to halt router sales, order a recall or require anyone to give up a device. The support-lifespan disclosure Iowa requests concerns a fact every router has, the date after which it stops receiving security updates; TP-Link's own May 1, 2026 customer update tells owners that end-of-life networking equipment cannot always be patched.
The contested core is the corporate separation, and it is a factual dispute rather than a legal one. TP-Link Systems says it is an independent US company and that it has given regulators verifiable documentation. The states allege the separation was presented as total while research, development and manufacturing stayed in China. Both propositions are checkable. Employee counts, facility ownership, component sourcing and construction contracts are the kind of evidence discovery produces. We are not going to guess how that comes out.
One pattern is observable now without predicting anything. Four states filed on the same day, with substantially parallel complaints and the same outside counsel, and 21 states wrote to the FCC the next day asking it to coordinate with their consumer-protection work. That is a coalition using state UDAP law as leverage inside a federal licensing decision, and the letter says as much when it offers to "work to jointly resolve our concerns about remedying past and ongoing state-law violations in conjunction with your conditional-approval review." That is a template available to other states for other connected-device makers. Iowa announced two more China-related consumer-protection suits the same week: against video-surveillance distributor ADI Global Distribution Inc. on October 7, 2026 and against camera maker Lorex Corporation on October 9, 2026.
The entity question deserves one more note, because it is where coverage of this story is most likely to go wrong. The Defense Department designated TP-Link Technologies Co., Ltd. in June 2026. The company being sued is TP-Link Systems Inc. Treating the designation as a government finding against the defendant would misstate the record, and it would also miss the states' actual theory, which is not that the defendant is a designated military company but that it allegedly failed to tell consumers about the designated company it says it separated from.
How This Affects You
None of the five complaints asks a court to ban, recall or seize routers or to bar owning one, and we found no law that makes owning one unlawful. There is no recall order, no seizure order and no requirement in any of the five prayers for relief that anyone replace or surrender a device. What the states ask for, read across those prayers, is different disclosures and money.
The federal Covered List entry of March 23, 2026 addresses equipment authorization: under 47 CFR 2.903(a), covered equipment cannot receive an FCC equipment authorization, and under 47 CFR 2.911 an applicant must certify that its equipment is not covered. The Public Notice imposes no obligation on anyone who already owns a router, and it says nothing about routers already authorized or already sold.
Separately from the litigation, federal agencies have published general guidance for anyone using a small-office or home-office router, from any manufacturer. The FBI and NSA announcement of April 7, 2026 encourages SOHO router users to upgrade end-of-support devices, update to the latest firmware, change default usernames and passwords, and disable remote management interfaces exposed to the internet, and advises all users to take certificate warnings in browsers and email clients seriously. CISA maintains an Edge Device Security page and the Known Exploited Vulnerabilities catalog, which is searchable by vendor and lists the specific router CVEs that are known to have been exploited. That is ordinary security hygiene, it applies to every brand, and it is unrelated to the merits of these lawsuits.
TP-Link has published its own guidance on the models implicated in the GRU activity. Its May 1, 2026 customer update tells owners of affected models that the most effective step is to replace the device with one still receiving security updates, and notes that end-of-life networking equipment cannot always be patched. That is the manufacturer's recommendation, reported here as part of the record; it is not our advice about your equipment.
Consumers in the five filing states should know that these are government enforcement actions, not class actions. There is no claim form, no settlement fund, no eligibility check and no deadline to file anything. Nobody is collecting consumer claims in connection with these suits. Any website that invites you to submit personal information to claim money from a TP-Link case as of October 10, 2026 is not connected to any of these proceedings. Several states do ask for restitution or disgorgement, but no court has ordered any payment and no distribution mechanism exists.
Courts have generally held that state UDAP statutes also support private suits by individual consumers, on terms that vary considerably by state, including on whether a private plaintiff must show an individual loss. Whether any particular purchase could support any particular claim depends on facts and on state law that differ case by case, so that is a question for a lawyer licensed where you live.
This is general legal information, not legal advice. It covers Florida, Iowa, Montana, Nebraska and Texas state consumer-protection law plus federal FCC and Defense Department actions, and reflects sources verified on October 10, 2026. All five lawsuits describe allegations that have not been proven. Laws change and this story is developing; consult a lawyer licensed in your jurisdiction about your specific situation.
Related articles
- How the states regulate consumer data, compared side by side
- Who has to register as a data broker, and where
- Rules for cameras pointed at your own front door
Last updated: 2026-10-10. This is a developing story; details verified as of 2026-10-10.
Frequently Asked Questions
Are TP-Link routers being banned in the United States?
None of the five state lawsuits asks a court to ban, recall or seize routers; their prayers for relief seek injunctions against the challenged representations, disclosures, restitution or disgorgement, civil penalties and fees. Separately, the FCC's March 23, 2026 Public Notice (DA 26-278, WC Docket No. 18-89) added routers produced in a foreign country, regardless of the producer's nationality, to its Covered List, which bars new FCC equipment authorizations for covered equipment and lets producers seek a Conditional Approval from the Department of War or Homeland Security. The notice does not say what happens to routers already authorized or already sold.
Is it illegal to own or keep using a TP-Link router?
None of the Florida, Iowa, Montana, Nebraska or Texas complaints asks a court to ban, recall or seize routers or to bar owning one, and we found no law that makes owning one unlawful. The word recall does not appear in any of the four October 6, 2026 complaints, whose prayers for relief seek injunctions, disclosures, restitution or disgorgement, penalties and fees.
Which states have sued TP-Link, and when?
Florida, Iowa, Montana and Nebraska each filed on October 6, 2026. Texas filed earlier and separately; Attorney General Ken Paxton announced that Collin County case on February 17, 2026. All five name TP-Link Systems Inc. as the defendant.
Has any court found that TP-Link did anything wrong?
No court has made any finding that we are aware of. The filings are allegations: Florida, Iowa, Montana and Nebraska filed on October 6, 2026 and Texas announced its suit on February 17, 2026. We did not search the court dockets, so we report these cases as announced by each attorney general and cannot say what has been filed since. TP-Link's October 6, 2026 statement called the suits built on false premises and said the company looks forward to refuting the allegations in court.
Did the Defense Department designate TP-Link a Chinese military company?
It designated TP-Link Technologies Co., Ltd., the China-based entity, on June 10, 2026 at 91 Fed. Reg. 35189. That company is not a defendant in these suits. The defendant is TP-Link Systems Inc., a California corporation. The states allege the defendant failed to disclose the designation while claiming a complete separation from the designated company.
What laws are the states actually suing under?
Ordinary state consumer-protection statutes, not national-security authorities: FDUTPA (Fla. Stat. 501.204(1)), the Iowa Consumer Fraud Act (Iowa Code 714.16), the Montana Consumer Protection Act (Mont. Code Ann. 30-14-103), the Nebraska Consumer Protection Act and Uniform Deceptive Trade Practices Act (Neb. Rev. Stat. 59-1601 and 87-301 et seq.), and the Texas Deceptive Trade Practices Act (Tex. Bus. & Com. Code 17.46).
Can I join these lawsuits or file a claim for money?
No. These are state enforcement actions brought by attorneys general, not class actions, and there is no claim form, fund, eligibility check or filing deadline attached to them. Some states do seek restitution or disgorgement, but no court has ordered any payment. Treat any site soliciting your personal information to claim TP-Link settlement money as unconnected to these cases.
What is the 0.5% Vietnam allegation about?
The complaints allege TP-Link told consumers its US-market products are made in its own Vietnamese facility as a supply-chain security measure, when only 0.5% of that factory's components by value are bought in Vietnam and the rest are imported from or through China (Florida Complaint para. 67). TP-Link says its US-market devices are manufactured in Vietnam and that it has given regulators verifiable documentation. The allegation is unproven.
Which TP-Link vulnerabilities are confirmed by the government, as opposed to alleged?
CISA's Known Exploited Vulnerabilities catalog independently lists six TP-Link CVEs, including CVE-2023-50224 (TL-WR841N, added September 3, 2025) and CVE-2023-1389 (Archer AX21). An FBI and NSA announcement of April 7, 2026 states that Russian GRU actors tracked as APT28 compromised TP-Link routers using CVE-2023-50224. Those are federal statements about the vulnerabilities and their exploitation, not findings about TP-Link's marketing; whether that marketing was deceptive is what the lawsuits allege and what the courts will decide.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Office of the Attorney General, State of Florida v. TP-Link Systems Inc., Complaint, Circuit Court of the Tenth Judicial Circuit, Polk County, Fla., Filing # 258584264 (e-filed Oct. 6, 2026)(myfloridalegal.com).gov
- Florida Attorney General James Uthmeier, news release, Attorney General James Uthmeier Files Lawsuit Against TP-Link Systems (Oct. 6, 2026)(myfloridalegal.com).gov
- State of Iowa ex rel. Attorney General Brenna Bird v. TP-Link Systems Inc., Petition, Iowa District Court for Polk County (dated Oct. 6, 2026)(iowaattorneygeneral.gov).gov
- Iowa Attorney General Brenna Bird, news release, Attorney General Brenna Bird Sues TP-Link Systems for Violating Iowa Consumer Fraud Act and Allowing China Access to Iowans' Routers (Oct. 6, 2026)(iowaattorneygeneral.gov).gov
- State of Montana ex rel. Austin Knudsen v. TP-Link Systems Inc., Complaint, Montana First Judicial District Court, Lewis and Clark County, Case No. DV-25-2026-0000720-OC (filed Oct. 6, 2026), published as the attachment to the Montana Department of Justice news release(content.govdelivery.com)
- Montana Department of Justice, news release, Attorney General Knudsen files lawsuit against China-founded tech company TP Link (Oct. 6, 2026)(dojmt.gov).gov
- Montana Department of Justice, news release, Attorney General Knudsen asks FCC to review TP-Link's China ties ahead of router sales (Oct. 7, 2026)(dojmt.gov).gov
- State of Nebraska ex rel. Michael T. Hilgers v. TP-Link Systems Inc., Complaint, Keith County District Court, Neb., Case No. D68CI260000109 (e-filed Oct. 6, 2026)(ago.nebraska.gov).gov
- Nebraska Attorney General Mike Hilgers, news release, Attorney General Hilgers Files Suit Against TP-Link as Part of Ongoing Fight to Protect Nebraskans from Exploitation by the Chinese Communist Party (Oct. 6, 2026)(ago.nebraska.gov).gov
- Nebraska Attorney General Mike Hilgers, news release, Attorney General Hilgers Leads Multi-State Coalition Raising Concerns Over TP-Link's China Ties (Oct. 7, 2026)(ago.nebraska.gov).gov
- Letter from 21 state attorneys general to FCC Chairman Brendan Carr and Commissioners Anna M. Gomez and Olivia Trusty, RE: Potential Conditional approval of TP-Link Systems, Inc., WC Docket No. 18-89, ET Docket No. 21-232, EA Docket No. 21-233 (Oct. 7, 2026), published by the Nebraska Attorney General(ago.nebraska.gov).gov
- The State of Texas v. TP-Link Systems Inc., Plaintiff's Original Petition and Application for Temporary and Permanent Injunctions, Collin County District Court, Tex.(texasattorneygeneral.gov).gov
- Texas Attorney General Ken Paxton, news release, Attorney General Paxton Sues TP Link for Allowing the CCP to Access Americans' Devices (Feb. 17, 2026)(texasattorneygeneral.gov).gov
- FCC Public Safety and Homeland Security Bureau, FCC's Public Safety and Homeland Security Bureau Announces Addition of Routers Produced in Foreign Countries to FCC Covered List, Public Notice DA 26-278, WC Docket No. 18-89 (Mar. 23, 2026), including the National Security Determination at Appendix C(docs.fcc.gov).gov
- U.S. Department of Defense, Notice of Availability of Designation of Chinese Military Companies, 91 Fed. Reg. 35189 (June 10, 2026), designating TP-Link Technologies Co., Ltd.(govinfo.gov).gov
- Federal Bureau of Investigation and National Security Agency, Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information, IC3 Public Service Announcement Alert No. I-040726-PSA (Apr. 7, 2026)(ic3.gov).gov
- Cybersecurity and Infrastructure Security Agency, Known Exploited Vulnerabilities Catalog, catalog version 2026.10.08 (listing six TP-Link CVEs, including CVE-2023-50224 and CVE-2023-1389)(cisa.gov).gov
- TP-Link Systems Inc., TP-Link Systems Inc. Issues Statement in Response to Attorney General Lawsuits (Oct. 6, 2026)(tp-link.com)
- TP-Link, An Important Update for TP-Link Customers Regarding Recent CVE-2023-50224 Reporting (May 1, 2026)(tp-link.com)
- Microsoft Threat Intelligence, Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network (Oct. 31, 2024)(microsoft.com)
- Iowa Attorney General Brenna Bird, news release, Attorney General Brenna Bird Sues Video Surveillance Company ADI Global Distribution for Making Iowans' Private Data Available to China (Oct. 7, 2026)(iowaattorneygeneral.gov).gov
- Iowa Attorney General Brenna Bird, news release, Attorney General Brenna Bird Sues Baby Monitor Company with Ties to China (Lorex Corporation) (Oct. 9, 2026)(iowaattorneygeneral.gov).gov