Chinese Hackers Breach NASA, Federal Reserve, DOJ and U.S. Senate in Massive State Sponsored Cyberattack

Chinese State Backed Hackers Targeted NASA, Federal Reserve, DOJ and U.S. Senate

“Why doesn’t Congress pass a law that imposes a real world financial penalty every time China is proven responsible for a cyberattack against the United States? If a state sponsored Chinese operation attacks American government agencies or critical infrastructure, deduct a predetermined amount from the U.S. debt held by China. Cyberattacks need consequences that extend beyond sanctions and strongly worded statements. If there is no meaningful cost for attacking America, what is the deterrent?” — Patrick Zarrelli

The United States has disrupted a sprawling Chinese state sponsored hacking operation that federal investigators say targeted some of the most sensitive institutions in the American government, including NASA, the Federal Reserve, the Department of Justice, the Department of Energy and the U.S. Senate.

The Justice Department and FBI announced Wednesday that federal authorities had obtained court authorization to seize three internet domains critical to two hacking platforms known as QScan and QTRouter. According to court documents unsealed in the Southern District of California, the platforms were developed and operated by a Chinese hacking group known as QTFY, which investigators say works for Nanjing Xinjiuwei Network Technology Company, a private technology company based in China with alleged financial and operational ties to the Chinese government.

The operation was not limited to Washington. Federal investigators say the same infrastructure has been used since at least 2018 to target critical infrastructure and sensitive networks in the United States and around the world, including hospitals, telecommunications providers, power companies, financial institutions and defense contractors. The newly unsealed records provide another detailed look at the increasingly industrialized nature of Chinese cyber espionage. Rather than relying exclusively on hackers directly operating from Chinese government facilities, investigators describe a system involving private contractors, sophisticated exploitation tools and enormous networks of compromised internet-connected devices that can disguise where an attack is actually coming from.

Federal Authorities Say QTFY Targeted Some of America’s Most Sensitive Networks

According to the Justice Department, QTFY activity targeted networks belonging to NASA, the Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health and the U.S. Senate. The operation also targeted private organizations in sectors including telecommunications, health care, energy, finance and defense. The distinction between being targeted and being successfully compromised is important. The federal court documents describe multiple intrusion attempts with varying outcomes, and the evidence does not establish that every agency targeted by QTFY was successfully breached.

NASA provides a clear example. Investigators say QTFY attempted to penetrate a NASA network in 2019 by exploiting a known vulnerability, but the attempt failed because NASA had already patched the security flaw. Other operations were more successful. Reuters reported Wednesday that U.S. authorities attributed actual network break-ins at several major federal institutions to the operation, underscoring why federal law enforcement treated QTFY’s infrastructure as a national security threat rather than an ordinary cybercrime network.

The Hackers Allegedly Worked Through a Chinese Technology Company

Federal investigators identified QTFY as a group of malicious cyber actors working for Nanjing Xinjiuwei Network Technology Company. An FBI affidavit goes considerably further, alleging financial and personnel connections between the company and the Chinese state. According to the affidavit, payments from China’s Ministry of State Security to Nanjing Xinjiuwei indicate that the company conducted malicious cyber activities on behalf of the Chinese government. Investigators also allege that QTFY includes former members of the People’s Liberation Army who used relationships developed through the Chinese military to obtain contracts and subcontracts supporting offensive cyber operations.

The Justice Department says QTFY offered computer hacking services to paying customers that included China’s Ministry of State Security and People’s Liberation Army. Those allegations are significant because they illustrate a model increasingly familiar to Western intelligence and cybersecurity agencies: private Chinese companies and contractors allegedly providing tools, infrastructure and operational capabilities to state intelligence and military organizations. The result is a cyber ecosystem in which the line separating a commercial technology company from a government espionage operation can become increasingly difficult to identify from the outside.

QScan Found the Targets and QTRouter Helped Hide the Attackers

At the center of the operation were two complementary systems known as QScan and QTRouter. QScan functioned as a vulnerability scanning and exploitation platform. According to federal investigators, the system scanned the internet for vulnerable devices and could automatically compromise thousands of internet-connected devices around the world. Those infected devices could then become part of a larger network controlled through QTRouter.

QTRouter provided the second critical capability: concealment.

The platform combined compromised Internet of Things devices with commercial proxy services and leased virtual private servers to create what the Justice Department describes as an “obfuscation network.” Instead of malicious traffic appearing to originate directly from China, hackers could route their activity through compromised computers, routers and other devices located elsewhere in the world.

In some circumstances, the malicious traffic could appear to originate from infrastructure physically close to the organization being attacked. That capability matters enormously in modern cyber espionage. Security teams routinely use the apparent geographic and network origin of internet traffic as one signal for detecting suspicious activity. Routing an attack through an ordinary compromised device inside the United States can make Chinese state-sponsored activity substantially harder to distinguish from legitimate domestic traffic.

Thousands of Ordinary Internet Devices Became Part of the Infrastructure

The allegations also demonstrate how seemingly insignificant consumer and business devices can become components of international espionage operations. Internet connected cameras, routers and other devices frequently operate for years without receiving adequate security updates. Once compromised, they can be quietly incorporated into botnets without their owners realizing anything unusual has happened.

QTFY allegedly industrialized that process. QScan searched for exploitable devices, while QTRouter transformed compromised systems into relay points capable of concealing malicious activity.

In practical terms, a vulnerable router sitting inside an American home or small business could potentially become infrastructure used to disguise an operation targeting a federal agency, power company or defense contractor. Researchers at Lumen Technologies’ Black Lotus Labs, which worked with federal authorities on the investigation, described the organization behind the infrastructure as effectively serving as a technological “quartermaster” for Chinese cyber operations, supplying the tools and routing infrastructure needed by other actors to conduct espionage.

The FBI Seized the Domains That Kept the System Running

The federal disruption was designed around a vulnerability in the hackers’ own infrastructure. According to the Justice Department, critical internet domains were hard-coded into QScan and QTRouter and were necessary for functions including communication and authentication. Federal authorities obtained court authorization to seize those domains, preventing the platforms from communicating through infrastructure they were designed to trust.

Authorities seized three domains associated with the operation. The Justice Department says the action rendered QScan and QTRouter inoperable. That is materially different from simply publishing a warning about the hacking group. Federal investigators effectively took control of infrastructure necessary for the platforms to function, immediately disrupting the attackers’ ability to continue using the existing system.

It does not mean the broader Chinese cyber threat has disappeared. The operators can potentially develop new tools, register new infrastructure or redesign their systems. But rebuilding an established global platform costs time, money and operational resources while exposing attackers to additional intelligence collection.

FBI and NSA Say the Operation Goes Back to at Least 2018

The newly disclosed campaign was not a short-term operation. Federal investigators say QTFY infrastructure has been used against critical infrastructure and sensitive networks since at least 2018. The FBI and National Security Agency simultaneously released cybersecurity information related to QTFY activity, providing technical indicators intended to help organizations determine whether their networks may have encountered the group’s infrastructure.

The duration of the campaign is particularly significant because cyber espionage operations often prioritize persistence over immediate destruction. An attacker does not necessarily need to shut down a power plant, destroy a government database or publicly leak stolen information for an intrusion to have strategic value. Long term access can provide intelligence about government operations, technology, personnel, vulnerabilities and institutional decision making. Access to critical infrastructure can also potentially provide information that could become valuable during a future geopolitical crisis.

Chiina

Washington Has Been Fighting a Much Larger Chinese Cyber Campaign

The QTFY takedown is the latest in a series of U.S. operations against hacking infrastructure attributed to Chinese state-sponsored groups.

In 2023, the FBI disrupted a botnet used by the Chinese state sponsored group known as Volt Typhoon to conceal activity targeting American and foreign critical infrastructure. In 2024, federal authorities disabled another botnet involving hundreds of thousands of compromised Internet of Things devices associated with infrastructure used by Flax Typhoon. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 infected computers in the United States after the malware had been linked to the Chinese state-sponsored hacking group Mustang Panda.

Taken together, the operations reveal a persistent strategic problem for American cybersecurity officials. Chinese-linked hacking groups have repeatedly used compromised civilian infrastructure to disguise their operations, making it more difficult for defenders to identify malicious traffic based simply on where it appears to originate. The groups and malware may change, but the broader strategy is remarkably consistent: compromise legitimate infrastructure, hide behind it and use that anonymity to approach high-value targets.

Beijing Has Repeatedly Denied Sponsoring Cyberattacks Against the United States

The Chinese government has historically rejected American accusations that it sponsors hacking operations against the United States, frequently accusing Washington of politicizing cybersecurity and making unsupported allegations against China. China had not immediately responded to the latest allegations when the operation was announced Wednesday, according to news reports.

The claims released by the Justice Department, however, go beyond a general attribution statement. The FBI affidavit alleges payments from China’s Ministry of State Security to the company employing QTFY and says members of the hacking organization include former People’s Liberation Army personnel who used their military relationships to obtain offensive cyber contracts.

Those allegations remain claims by U.S. investigators presented in federal court records, but they provide considerably more detail about the alleged relationship between the hacking infrastructure and Chinese state institutions than a simple assertion that an attack originated from China.

The Real Battlefield Is Increasingly the Infrastructure Americans Depend On

The most important part of the QTFY case may not be the list of famous agencies involved.

NASA, the Federal Reserve, the Justice Department and U.S. Senate understandably generate headlines, but the broader target list reveals a cyber campaign reaching into the infrastructure underlying everyday American life. Hospitals were targeted. Telecommunications companies were targeted. Power companies were targeted. Financial institutions and defense contractors were targeted.

Modern geopolitical competition increasingly takes place inside computer networks long before conventional military conflict begins. Governments can collect intelligence, map infrastructure, identify vulnerabilities and potentially establish access that could become strategically valuable during a future confrontation.

That makes cyber defense something far larger than protecting government email accounts. The attack surface now includes everything from federal networks and telecommunications infrastructure to poorly secured routers and Internet of Things devices sitting inside ordinary homes and businesses. The Justice Department and FBI successfully knocked QScan and QTRouter offline. The larger confrontation they represent is nowhere close to finished.

Patrick Zarrelli - PJZNY -Sources

Sources

USA TODAY, “DOJ Says Chinese Hackers Targeted NASA, Federal Reserve, Senate,” August 26, 2026.

Watch the USA TODAY report

U.S. Department of Justice, “Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure,” August 26, 2026. (Department of Justice)

U.S. Department of Justice announcement

Federal Bureau of Investigation affidavit filed in the Southern District of California, detailing the investigation into QTFY, Nanjing Xinjiuwei, QScan and QTRouter. (Department of Justice)

Read the federal affidavit

Reuters, “US Says Chinese Hackers Broke Into Justice Department, NASA, Federal Reserve, Senate,” August 26, 2026. (Reuters)

Reuters report

WIRED, “FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure,” August 26, 2026. (WIRED)

WIRED cybersecurity report

Nextgov/FCW, “FBI Disables China-Linked Hacking Tools Used Against US Agencies,” August 26, 2026. (Nextgov/FCW)

Nextgov/FCW report

BleepingComputer, “FBI Disrupts Proxy Network Enabling Chinese Espionage Operations,” August 26, 2026. (bleepingcomputer.com)

BleepingComputer technical analysis

Share this post :

Join the Conversation:

guest
0 Comments
Newest Oldest Most Voted
[approved_comments_ajax]
0
Would love your thoughts, please comment.x
()
x