Chinese Hackers Breached NASA, the Federal Reserve and DOJ, US Says: What We Know
The United States said a China-linked state-sponsored hacking group compromised or targeted networks belonging to NASA, the Federal Reserve, the Department of Justice and other federal agencies over several years.
The Justice Department and FBI announced court-authorized seizures of domains associated with two hacking platforms, QScan and QTRouter, on Aug. 26.
According to court documents unsealed in the Southern District of California, the group, identified as QTFY, is linked to China-based Nanjing Xinjiuwei Network Technology Co.
The Justice Department said QTFY developed and operated QScan and QTRouter, which were used against U.S. critical infrastructure and other sensitive networks.
The court affidavit said QTFY computer infrastructure had been used since at least 2018 to compromise critical infrastructure and sensitive networks in the United States and elsewhere. It identified NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and, in 2026, the U.S. Senate among targeted federal networks.
Inside the QScan and QTRouter Network
QScan was described by U.S. authorities as a vulnerability scanning and exploitation platform. It scanned internet-connected devices and could automatically infect vulnerable internet-of-things devices, which were then incorporated into infrastructure controlled by QTFY.
QTRouter functioned as an “obfuscation network.” It consisted of compromised IoT devices, commercial proxy service devices and leased virtual private servers.
The network allowed communications associated with intrusions to appear to originate from systems outside China, including devices that could be geographically close to a targeted network, according to the Justice Department.
The seized domains were hard-coded into QScan and QTRouter malware and were required for functions including communication and authentication. The DOJ said seizing the domains therefore rendered both platforms inoperable.
The National Security Agency, FBI and Cyber National Mission Force separately said QTFY had developed several malicious platforms, including QScan, QTRouter and systems for managing botnets of compromised IoT devices.
The agencies said the group had targeted organizations in sectors including the Defense Industrial Base, telecommunications, local government and higher education.
Court Documents Identify QTFY’s Chinese Connections
The FBI affidavit said QTFY actors worked for Nanjing Xinjiuwei and that payments from China’s Ministry of State Security to the company indicated that it conducted malicious cyber activities on behalf of the Chinese government.
The affidavit also said some QTFY actors included former members of the People’s Liberation Army who used those relationships to obtain contracts and subcontracts supporting offensive cyber operations.
According to the court documents, QTFY offered computer hacking services to paying customers, including China’s Ministry of State Security and the People’s Liberation Army. The Justice Department described those assertions as information contained in court documents supporting the seizure action.
The affidavit said QTFY activity extended beyond federal agencies. Other targeted networks included hospitals, telecommunications providers, power companies, financial institutions and defense contractors.
U.S. Officials Explain the Disruption Operation
Attorney General Todd Blanche said, in an official FBI statement, the operation was part of a broader U.S. effort to disrupt China-linked cyber activity.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” Blanche said. “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
FBI Director Kash Patel said the platforms were designed to conceal the origin of cyberattacks.
“These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down. Today’s action is just the latest technical operation against PRC-sponsored hacking, and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace,” Patel said.
Blanche separately told Fox News the campaign had persisted for years. “This is something that’s been happening for many years, and in this case this was sponsored, this is state sponsored, and this is a major national security issue for the U.S.,” he said.
Federal Agencies Targeted Over Several Years
The Justice Department identified the federal agencies and institutions whose networks were targeted or compromised but did not provide a detailed accounting of damage caused by the intrusions in its Aug. 26 announcement.
The court affidavit states that QTFY infrastructure was used to compromise sensitive networks. The affidavit specifically identifies federal networks targeted across different years, including the Senate in 2026.
The FBI and NSA also said QTFY actors exploited zero-day and N-day vulnerabilities to gain initial access to victim networks and obtained legitimate credentials from compromised systems to maintain persistence.
Key U.S. Actions Against China-Linked Hackers
The QTFY operation follows several previous U.S. efforts to disrupt China-linked cyber infrastructure.
In 2023, the FBI disrupted a botnet that U.S. authorities said was used by the China-linked Volt Typhoon group to conceal the exploitation of U.S. and foreign critical infrastructure.
In 2024, the FBI disabled a botnet containing hundreds of thousands of infected IoT devices that the Justice Department said China-linked Flax Typhoon was providing to customers in the Chinese government.
In 2025, the FBI removed PlugX surveillance malware from more than 4,000 U.S. computers infected by the China-linked Mustang Panda group.
The DOJ said the QTFY disruption is part of the same broader series of court-authorized technical operations against China-linked hacking activity.
FBI, NSA Issue Cybersecurity Warning
Alongside the domain seizures, the FBI and NSA issued a joint cybersecurity advisory providing indicators of compromise associated with QTFY activity dating to at least 2018.
The agencies advised organizations to ensure that systems are running current software and firmware, routinely schedule audits of internet-facing applications, and scan their networks for the signs that appeared in the advisory and isolate critical systems from edge devices.
The investigation was led by the FBI’s San Diego Field Office and Cyber Division, the U.S. Attorney’s Office for the Southern District of California and the National Security Cyber Section of the Justice Department’s National Security Division.
The latest action disrupted QScan and QTRouter, but the public disclosures indicate that U.S. authorities continue to investigate QTFY’s broader infrastructure, targeting methods and connections to Chinese government entities.