
Chinese state-backed hackers spent years quietly breaking into the Justice Department, NASA, the Federal Reserve and the U.S. Senate before federal agents finally shut down the digital tools making it possible.
Quick Take
- The Justice Department and the FBI seized platforms linked to a China-state-sponsored hacking group known as QTFY on August 26, 2026.
- Court documents unsealed in California name victims including NASA, the Federal Reserve, the Senate, the Justice Department, and multiple health agencies.
- Investigators say the group sold hacking access to China’s Ministry of State Security and the People’s Liberation Army through a private company.
- China’s embassy in Washington denied wrongdoing and accused the U.S. of using cybersecurity claims to “smear” the country.
Federal Agencies Confirm A Years-Long Intrusion Campaign
The Justice Department and FBI announced that they had seized platforms used by Chinese state-sponsored hackers to target American critical infrastructure.
A federal affidavit unsealed in the Southern District of California identifies the group as QTFY and ties it to a company called Nanjing Xinjiuwei Network Technology Company. Authorities say the campaign against U.S. government networks dates back to at least 2018 and has hit hundreds of targets.
China’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ. https://t.co/3Kdpl4RA4j
— WIRED (@WIRED) August 26, 2026
The list of victims reads like a roll call of America’s most sensitive institutions. It was reported that the affidavit names the Justice Department, NASA, the Federal Reserve, the Senate, the Department of Energy, Health and Human Services, and the National Institutes of Health as targets. Hospitals, telecom providers, power companies, banks, and defense contractors also appear on the list.
How The Hacking Tools Actually Worked
A joint advisory from the FBI, National Security Agency, and Cyber National Mission Force lays out the mechanics. The group used a tool called QScan to hunt for vulnerabilities and QRouter to hide where attacks were coming from.
Those tools reportedly hit a U.S. state government, a water district, a hospital system, and even an American election system, letting hackers scan for weaknesses while masking their digital fingerprints.
What makes this case stand out is the alleged business model behind it. Court documents claim the hackers didn’t just spy for Beijing directly.
Instead, they sold access to their hacking services to China’s Ministry of State Security and the People’s Liberation Army through a private company acting as a middleman.
That structure lets a government keep its hands technically clean while still reaping the intelligence benefits, a pattern cybersecurity researchers have flagged in Chinese operations for years.
Beijing Pushes Back, But Offers No Specific Rebuttal
China’s embassy in Washington denied the accusations outright, saying the Chinese government “opposes and combats all forms of cyberattacks” and urging the U.S. to “stop using cybersecurity issues to smear or discredit China”.
That mirrors language Chinese diplomats used in Singapore last year, when embassy officials dismissed similar hacking allegations as “baseless slanders and accusations”.
Neither statement offers a specific, evidence-based rebuttal to the technical findings laid out in the American court filings.
That gap matters. Denial without counter-evidence is common in state-sponsored cyber disputes, and it doesn’t erase what investigators documented. The affidavit and the joint federal advisory point to named victims, specific dates, and identified tools rather than vague suspicion.
Americans concerned about government accountability should welcome this kind of public attribution, even as they recognize that formal charges, if any follow, would still need to be proven in court.
Why This Fits A Bigger, Troubling Pattern
This isn’t an isolated incident. Security researchers have tracked Chinese cyber espionage groups growing “stealthier and more agile” since at least 2016, deliberately complicating efforts to trace attacks back to Beijing.
U.S. agencies have increasingly relied on public seizures, advisories, and indictments as tools of deterrence, a strategy some legal scholars call “attribution by indictment,” used against China, Russia, Iran, and North Korea alike since 2014.
🔴 U.S. Says Chinese State-Sponsored Hackers Targeted NASA, Federal Reserve, DOJ and Senate
📍WASHINGTON — August 26, 2026 | HewadPress
The U.S. Justice Department and FBI announced Wednesday that they have dismantled two hacking platforms allegedly operated by a Chinese… pic.twitter.com/ktsFL3IYXG
— HewadPress (@HewadPress) August 26, 2026
Federal agencies handling health data, financial policy, and national security infrastructure were reportedly compromised for years before this seizure happened.
That timeline alone should push Congress to demand stronger cyber defenses and faster detection, regardless of how the diplomatic back-and-forth with Beijing plays out.
Sources:
abcnews.com, nypost.com, cnbc.com, media.defense.gov, yahoo.com, berndpulch.org, reuters.com, justice.gov, nextgov.com












