China's CAC opens unexplained security probe into Palo Alto Networks

China's CAC opens unexplained security probe into Palo Alto Networks

China's Cyberspace Administration (CAC) has opened a review of Palo Alto Networks' products. The regulator's announcement gives no specific concern, vulnerability, or incident, only a general justification: it says the review is needed "to ensure the safe and stable operation of critical information infrastructure, prevent cybersecurity risks and vulnerabilities, and safeguard national security." That is all Beijing has said on the matter so far.

A Palo Alto Networks spokesperson gave The Register the following statement: "We maintain the highest standards of business conduct and security practices and ethics across our global operations. At this time, there is no impact to our ability to support customers or deliver our products and services in the region."

The episode closely mirrors the CAC's 2023 investigation into memory-maker Micron, which was also announced without explanation. Micron had previously fought intellectual property and antitrust cases in China, but neither the company nor Chinese authorities linked those matters to the security probe. Weeks after opening that investigation, the CAC found Micron's products posed an unacceptable security risk to critical infrastructure operators, effectively banning sales to them, again without a detailed explanation. Micron eventually stopped selling its datacenter and server products in China altogether, a decision that cost it billions in annual revenue. The exit also opened room for China's own memory-makers, which are largely shut out of selling to US companies. Micron's later AI-driven earnings have since made that hit to its China revenue look minor in hindsight.

Palo Alto Networks does not disclose revenue by country, so it is not possible to estimate what a ban would cost the company. China has domestic security vendors, including Huawei and H3C, whose product lines overlap with Palo Alto's and could pick up any business a ban would free up. The Register notes that China has for years accused Western tech companies of assisting US surveillance and offensive hacking, the same accusation Western governments level at Huawei and ZTE, and suggests Beijing could lean on similar reasoning when it eventually publishes findings on Palo Alto, though that framing is the outlet's own speculation rather than anything the CAC has stated.

Key facts

  • China's Cyberspace Administration (CAC) has opened a review of Palo Alto Networks' products, citing only general language about protecting critical infrastructure and national security.
  • No specific reason, vulnerability, or incident has been given, echoing the CAC's unexplained 2023 investigation into Micron.
  • That earlier probe led the CAC to bar Micron products from Chinese critical infrastructure operators; Micron then stopped selling datacenter and server products in China, costing it billions in annual revenue.
  • Palo Alto Networks says the review currently has no impact on its ability to support customers or deliver products in the region.
  • Palo Alto does not disclose country-level revenue, so the potential cost of a ban is unknown; domestic vendors Huawei and H3C could benefit from any restriction.

Why it matters

An unexplained national-security review from Chinese regulators is how the 2023 Micron case began, and that case ended with Micron barred from selling to Chinese critical infrastructure operators and eventually exiting the datacenter and server market in China entirely. The same regulator using the same vague justification against another major security vendor raises the question of whether Palo Alto Networks is heading toward a similar outcome.

Who it affects

Palo Alto Networks and any Chinese customers that rely on its products for critical infrastructure security. China's own security vendors, Huawei and H3C among them, stand to gain if Chinese buyers are steered away from Palo Alto. The pattern also matters to other Western security and technology vendors doing business in China, since the CAC has shown it is willing to open this kind of review without stating a cause.

How to use it

There is no ban and no finding yet, only a review, so no action is required from Palo Alto customers today. What to watch for is the CAC's eventual findings, expected on the same kind of delayed, unexplained timeline the Micron case followed, and whether Palo Alto starts disclosing any region-specific revenue impact once those findings land.

How solid is it

The facts here are narrow but well sourced: The Register carries direct statements from both the CAC's own review announcement and an on-record Palo Alto Networks spokesperson, and the Micron parallel is drawn from that regulator's own documented 2023 findings. What is not solid is any explanation for the Palo Alto review itself, which neither Beijing nor Palo Alto has provided.

Risks and caveats

The CAC has not accused Palo Alto Networks of anything specific, has not banned its products, and has not set a timeline for findings. The Micron comparison is a pattern, not a guarantee of the same outcome. Because Palo Alto does not break out revenue by country, any estimate of financial exposure would be speculation, and none is offered here.

“We maintain the highest standards of business conduct and security practices and ethics across our global operations. At this time, there is no impact to our ability to support customers or deliver our products and services in the region.”

— Palo Alto Networks spokesperson, quoted by The Register