The United States announced on 26 August that it had shut down a Chinese hacking campaign that had burrowed into NASA, the Federal Reserve, the Justice Department, and the US Senate. The Justice Department and the FBI seized the internet domains behind two hacking platforms, QScan and QTRouter. Court papers unsealed in San Diego name the operators as QTFY, a state-sponsored group. Prosecutors say QTFY worked for a Chinese firm that sold hacking services to Beijing’s spy agency and its army.
The Justice Department listed seven federal victims in all. Beyond NASA, the Federal Reserve, the Senate, and Justice itself, it named the Energy Department, Health and Human Services, and the National Institutes of Health. An affidavit added four unnamed companies in the United States and South Korea.
Attorney General Todd Blanche said state-sponsored hackers preying on American critical infrastructure “will be stopped and prosecuted.” FBI Director Kash Patel said the tools let Chinese operators disguise the origin of their attacks. Beijing pushed back: a Chinese Embassy spokesperson said the government “firmly opposes and combats all forms of cyberattacks in accordance with the law.”
How the Hacking Campaign Worked
The operation ran on two platforms that worked in tandem. QScan trawled the internet for vulnerable internet-of-things devices and infected them automatically. QTRouter then pooled those compromised machines with rented servers and commercial proxy services into a single relay network. Traffic routed through this network passed through computers outside China, so an attack on a Washington agency could appear to originate from a router down the street.
Crucially, the seized domains were hard-coded into the malware. Because the software depended on them to communicate, the seizures left both platforms inoperable, the Justice Department said.
Richard Hummel, a vice-president at SecurityScorecard, said that local-looking traffic slows attribution and buys operators time — and that taking down a platform of this scale “costs the operators real capability.”
A Hacking Timeline Stretching Back to 2018
The affidavit traces the campaign to at least May 2018. In August 2019, the group attempted to enter NASA’s networks through a VPN flaw; that attempt failed. September 2024 went differently: the hackers breached three Energy Department laboratories, the NIH, an unnamed HHS agency, and a US security-device manufacturer.
More recently, the group has shifted from breaching to scanning. A joint advisory from the FBI, the National Security Agency, and Cyber Command says the group probed the Senate and an American hospital system in March 2026, then scanned an unidentified US election system in June 2026. Both attempts failed.
Not the First Chinese Hacking Campaign
This marks the fourth takedown of a Chinese state-linked hacking operation in as many years. The FBI disrupted a Volt Typhoon botnet in 2023, disabled a Flax Typhoon network of hundreds of thousands of devices in 2024, and stripped PlugX malware from more than 4,000 American computers in 2025.
A separate group, Salt Typhoon, reached at least nine US telecom carriers, including AT&T and Verizon, and touched law-enforcement wiretap systems. In March 2026, the FBI told Congress that intruders had entered an internal system holding data on people under investigation — officials classified it a “major incident” under federal law.
The Breach That Emptied a CIA Station
For scale, nothing matches the Office of Personnel Management breach. In 2015, OPM disclosed two intrusions exposing records on 22.1 million people, including 21.5 million security-clearance files. Those SF-86 forms detail debts, drug histories, foreign contacts, and family information.
The fallout arrived quickly. The CIA pulled officers from its Beijing embassy post after China identified them through stolen personnel lists. Many of the officers had worked under State Department cover. China matched the stolen lists against embassy rosters and identified missing names.
The killings, however, came earlier. Between late 2010 and the end of 2012, Chinese authorities killed or jailed 18–20 CIA sources. One source was shot in a government courtyard. Colleagues witnessed the shooting. Investigators remain split on the cause, with some blaming a mole and others pointing to a compromised covert messaging system the agency had imported from its Middle East operations.
Hackers for Hire
Analysts say the contractor market explains the reach of this campaign. “Over the last decade, the number of companies offering niche offensive services has exploded,” said Dakota Cary, a China analyst at SentinelOne.
Court filings say QTFY included former members of the People’s Liberation Army. Nanjing Xinjiuwei also accepted payments from the Ministry of State Security.
