House Intel Republicans request FBI, SEC briefing on Temu
Full article998 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The members cited concerning news reports, including the exploitation of a zero-day vulnerability by parent company Pinduoduo in 2023.
Congressional Republicans on the House Permanent Select Committee on Intelligence are requesting a briefing from the FBI and Securities Exchange Commission on e-commerce app Temu and its parent company, Pinduoduo, saying both pose a potential threat to national security and the personal data of Americans.
In a letter sent Tuesday to FBI Director Christopher Wray and SEC Chair Gary Gensler, Chair Michael Turner, R-Ohio, and 13 other Republicans on the committee said they were concerned about numerous news reports over the past year that have detailed concerning business practices of Temu and Pinduoduo, which is incorporated in the Cayman Islands and headquartered in Shanghai, China.
Among those concerns was Pinduoduo’s suspension from the Google Play Store last year, after researchers discovered that its Android app contained a zero-day vulnerability that was capable of elevating administrative privileges, stealing personal data from, and installing malicious software on user devices.
“Due to the above cited incidents and many others, we are concerned about the protection of Americans’ data,” the lawmakers wrote. “Analogous to Congress’ action on TikTok, the relationship between the Chinese Communist Party, Chinese national security laws, and Americans’ data must be understood.”
The concerns come as Pinduoduo executives have reported surging profits over the past year, in part due to the rising popularity of Temu with American consumers. According to Statista, the app has averaged more than 50 million global downloads a month since May, numbers that outpace numbers for American e-commerce giant Amazon.
Global monthly downloads for Temu from September 2022-August 2024. (Source: Statista)
Many American-based applications and platforms have also been accused of conducting widespread surveillance on their users, but cybersecurity experts have said Pinduoduo’s app goes beyond normal business practices.
Additionally, U.S. officials have long maintained that Chinese national security and cybersecurity laws may require domestic companies to hand over personal user data in response to requests from the Chinese government.
Pinduoduo has readily acknowledged the risk of company data being handed over to Chinese authorities in regulatory filings. In its latest annual report to the SEC, the company highlights data security laws in China as a potential business risk, noting that one of its “challenges” around data security was “complying with applicable laws and regulations relating to the collection, use, storage, transfer, disclosure and security of personal data, including any requests from regulatory and government authorities relating to this data.”
Earlier filings by the company from 2018 flatly state “we may be required by Chinese governmental authorities to share personal information and data that we collect to comply with PRC laws relating to cybersecurity.”
But Pinduoduo has also denied wrongdoing and pushed back on claims that its code contains malware, saying in its 2024 annual report that the company has faced increased business risks because “competitors” were using the 2023 Google Play Store incident to unfairly smear the company.
“Competitors or third parties with ulterior motives could launch aggressive marketing and publicity strategies against us and place the media coverage about this incident among other innocuous or unrelated matters,” the company wrote. “We are working with stakeholders to refute the allegations while using this opportunity to review our practices.”
CyberScoop has reached out to Pinduoduo and Temu for comment.
In addition to requesting a briefing, House Republicans posed a number of questions to Wray and Gensler around the extent of information and intelligence sharing between the FBI and SEC on matters related to Temu and Pinduoduo.
More Scoops
House Republicans roll out national privacy bill
Experts say the federal legislation takes inspiration from states laws in Virginia and Kentucky, but a lack of bipartisan support could spell trouble.
Your AI doctor doesn’t have to follow the same privacy rules as your real one
CESER chief touts AI projects as congressional Dems point to federal cuts
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/house-intelligence-republicans-temu-pinduoduo-zero-day/