Justice Department and FBI Seize Domains Behind Two China-Linked Hacking Platforms, Naming NASA, the Federal Reserve and the Senate Among Targets
Court-authorized seizures announced August 26, 2026 disabled the QScan and QTRouter tools that U.S. officials link to a Chinese group active since 2018; Beijing calls the allegations false.
Two Domain Names Just Silenced a Hacking Platform That Ran Two Million Break-Ins a Day
Somewhere in a Justice Department filing, a small technical fact is doing most of the work: two hacking tools called QScan and QTRouter needed to phone home. Every time they scanned a device or routed an attack, they checked in with a handful of hard-coded domain names[1]. On August 26, 2026, the FBI and Justice Department got a court order and took those domains away. Without them, both tools went dark[1].
That is the whole mechanism behind a case that also names NASA, the Federal Reserve, the U.S. Senate, and four other federal agencies as targets[1][6]. Officials say the tools were built and run by a China-based group they call QTFY, working for a Chinese company, Nanjing Xinjiuwei Network Technology Co[1][2]. China's government says the accusation is false[5][11]. Both things are now part of the public record, and neither cancels the other out.
What QScan and QTRouter Actually Did
The two tools worked as a pair, and understanding them explains why the case matters beyond Washington. QScan combed the internet for weakly secured devices — home routers, security cameras, other everyday gear plugged into the internet — and broke into the ones it found automatically[1]. On a single day in 2024, it ran more than two million scanning and break-in attempts[7].
QTRouter took over from there. It strung the hijacked devices into a relay chain, so an attack launched from China would appear to come from an ordinary computer somewhere else entirely — a home in Ohio, say[1]. Investigators call this an obfuscation network. Its entire purpose is to make foreign intrusions look domestic, which is exactly what defeats most basic cyber defenses that block traffic by geography[1][7].
Officials say QTFY did not just use this network. It sold access to it, including to China's Ministry of State Security and the People's Liberation Army[1][7]. That detail is why prosecutors are treating the case as more than routine espionage — they describe it as a commercial hacking-for-hire operation with state customers[1].
The Word Doing the Most Work in the Government's Own Filing
Read closely, the Justice Department's release says NASA, the Federal Reserve, the Senate, and the Departments of Energy, Justice, and Health and Human Services, plus the National Institutes of Health, were "among the targets" of QTFY[1][6]. Targeted is not the same word as breached. An FBI agent's affidavit dates the group's activity back to 2018 and says it continued into 2026 — roughly eight years[3][6].
A joint advisory from the NSA, FBI, and Cyber National Mission Force adds a detail that sharpens that distinction rather than blurring it. It says QTFY's scans of the Senate and a hospital system in March 2026, and of a U.S. election system in June 2026, all failed to break in[13]. So for at least some of the named targets, the record shows an attempt and a failure, not a confirmed compromise.
That nuance mostly disappeared once the story reached the public. Attorney General Todd Blanche told Fox News the campaign is "a major national security issue" and said law enforcement had "investigated and disabled" the software[9]. Breitbart's headline read that Chinese hackers "breached" the Senate, the Federal Reserve, and multiple agencies — applying that word to the entire list, not just the confirmed cases[9].
A Denial That Skips the Forensics and Goes Straight to a Different Question
China's embassy in Washington said the country "opposes and combats all forms of cyberattacks" and told the United States to stop using cybersecurity claims to "smear or discredit" it[11][8]. Beijing's foreign ministry called the allegations false[5]. Notably absent from that response is any technical rebuttal of the QScan and QTRouter forensics themselves.
Instead, Beijing points to its own accusation. In October 2025, Chinese authorities said the NSA ran a years-long attack on China's National Time Service Center, the system that keeps national time for the country's finance, power grid, and transportation networks[12]. Chinese officials say the attack began with credential theft in 2022, with the NSA gaining initial access in April 2023 and further intrusion attempts running through 2024.
That comparison is the core of China's argument, whether or not you find it persuasive. It's not that hacking doesn't happen — it's that the United States runs its own large-scale intrusion programs and is, in this reading, applying a legal process to conduct it also engages in. The Justice Department's filing does not resolve that argument, because proving QTFY sold access to Chinese state buyers is not the same as proving the state ordered the intrusions[1].
Why "Seize the Domains" Is the Tool the U.S. Actually Has
There's a structural reason this case looks the way it does, and it has little to do with how serious the intrusions were. The United States cannot arrest hackers sitting in Nanjing. So the tools available to prosecutors are narrow: take away infrastructure the malware needs, publish technical advisories, sanction the companies involved[1][9]. Seizing two domain names is, in practice, close to the ceiling of what's achievable without cooperation from Beijing.
That constraint also explains why routing operations through a private contractor is useful to a state that wants deniability. A company that sells hacking access to multiple buyers can generate real revenue while giving the government an easier story to deny — the sales are documented, but the direction is not[1][7]. Whether or not that's what happened here, the structure of contractor-run operations is built to produce exactly that gap in the evidence.
Underneath both governments' programs sits the same raw material: insecure consumer hardware. Neither Washington nor Beijing created the market for cheap routers and cameras with default passwords and no update path. That market is what let QScan run two million scans in a day[7]. It's also, by extension, what makes these obfuscation networks cheap to rebuild — nothing about this seizure stops QTFY from standing up new domains and starting over[1].
The People Least Mentioned in Any Version of This Story
Thousands of hijacked devices made up the QTRouter relay network, and most of their owners were never named as victims and likely never will be notified[1][7]. These are the routers, cameras, and building systems that got quietly drafted into someone else's attack. Coverage from CNN and Time widened the frame to include hospitals, utilities, and universities among those affected, which shifts the story from a state-to-state dispute toward civilian exposure[3][4].
For a hospital or a small business running outdated equipment, the consequence isn't state secrets — it's a device that slows down, gets blocklisted, or exposes the rest of the network. Consumer-security advocates argue the real fix sits with device manufacturers, not end users who often have no way to know their equipment is compromised, let alone patch it[3][4][7].
What happens next isn't settled. Court records name the group and the company, but nothing in this seizure recovers data already taken, and nothing stops QTFY from rebuilding its network on new domains[1]. The technical details from the advisory have been shared with private companies so they can check their own systems[9] — which means the next chapter of this story, if there is one, will likely start with someone else's network logs.
Summary
On August 26, 2026, the Justice Department and the FBI said they had seized internet domains behind two hacking platforms called QScan and QTRouter[1][2]. Officials say a China-based group they call QTFY built and ran both tools, and that the group is employed by a Chinese company, Nanjing Xinjiuwei Network Technology Co.[1][2]. According to the government, QTFY sold hacking services to paying customers, including China's Ministry of State Security and the People's Liberation Army[1][5].
The two tools worked as a pair. QScan hunted the internet for weakly protected devices — routers, cameras, and other everyday gear connected online — and broke into them automatically[1]. QTRouter then strung those hijacked devices together into a relay network, so that an attack launched from China appeared to come from an ordinary machine somewhere else[1]. The FBI and NSA say QScan handled more than two million scanning and break-in tasks on a single day in 2024[7].
The Justice Department named NASA, the Federal Reserve, the Senate, and the Departments of Justice, Energy, and Health and Human Services, plus the National Institutes of Health, among QTFY's targets[1][6]. Coverage has also described hospitals, utilities and universities among those hit[3][4]. An FBI agent's affidavit dates the activity to 2018 and says it continued into 2026[3][6]. Attorney General Todd Blanche called it a 'major national security issue'[9].
China rejects the account. The Chinese Embassy in Washington said China 'opposes and combats all forms of cyberattacks' and told the U.S. to 'stop using cybersecurity issues to smear or discredit China'[11][8]. Beijing's foreign ministry called the U.S. claims false information[5]. The sharpest genuine dispute is not whether these tools existed — Beijing has not challenged the technical forensics — but whether the Chinese state directed them, and whether a U.S. government that runs its own large cyber-espionage programs is describing a crime or describing normal spycraft it also practices.
The Event
On August 26, 2026, the Justice Department and FBI announced court-authorized seizures of internet domains tied to two hacking platforms, QScan and QTRouter[1][2]. DOJ said the domains were hard-coded into both tools for communication and authentication, so the seizures made them inoperable[1]. The same day, the NSA and FBI issued a joint cybersecurity advisory on the group behind them, identified as QTFY and dated to 2018[7]. China's embassy in Washington and its foreign ministry denied state involvement within 48 hours[5][11].
Undisputed Facts
- The Justice Department and FBI announced the domain seizures on August 26, 2026, under court authorization[1][2].
- DOJ says the seized domains were hard-coded into the QScan and QTRouter malware for essential functions, and that the seizures rendered both platforms inoperable[1].
- Court documents name the group as QTFY and say it is employed by China-based Nanjing Xinjiuwei Network Technology Co.[1][2].
- DOJ lists NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate among QTFY's targets[1][6].
- An FBI agent's affidavit supporting the seizures dates the activity to 2018 and says it ran through 2026[3][6].
- The NSA and FBI issued a joint advisory saying QScan processed more than two million scanning and exploitation tasks on a single day in 2024[7].
- Attorney General Todd Blanche said federal law enforcement 'investigated and disabled' the software and called the case a major national security issue[9].
- China's embassy in Washington said China opposes all forms of cyberattacks and urged the U.S. to stop using cybersecurity issues to 'smear or discredit' it[11][8].
- In October 2025, Chinese authorities publicly accused the U.S. National Security Agency of a years-long cyberattack on China's National Time Service Center[12].
The Pressure
Strip away the moralizing and blame. What structural realities persist regardless of which narrative wins?
- Enforcement without reach
- The U.S. cannot arrest hackers sitting in Nanjing. So its usable tools are narrow: seize domains, publish advisories, sanction firms. That constraint, not a change in the threat, explains why 'technical operations' have become the standard American response[1][9].
- Contractors buy deniability
- Routing operations through a private company that sells to multiple buyers gives a state an honest-sounding denial. The same structure also means DOJ's filing can prove the sales without proving the orders[1][7].
- Insecure consumer hardware is the raw material
- Neither government made the internet-of-things device market insecure. Cheap gear with default passwords and no updates is what made a two-million-task-a-day scanning platform possible[7]. Both sides' operations depend on that same weakness.
- Mutual accusation is now routine
- Beijing's October 2025 claim about the NSA and the U.S. National Time Service Center allegation runs on the same template as Washington's[12]. Each announcement raises the price of the next denial for both.
Material realityTwo working hacking platforms existed and are now offline, because the domain names their code needed were taken[1]. Networks at NASA, the Federal Reserve, the Senate, DOJ, Energy, HHS and NIH were targeted over roughly eight years, and some were entered[1][3][6]. A joint FBI/NSA/Cyber National Mission Force advisory says QTFY's scans of Senate and hospital-system networks in March 2026, and of a U.S. election system in June 2026, specifically failed to gain access — direct confirmation that 'targeted' did not mean 'breached' for every named entity[13]. Thousands of hijacked consumer and business devices around the world formed the relay layer, and most of their owners will never be told[1][7]. Nothing in the seizure recovers data already taken, and nothing prevents the same group from rebuilding on new domains — obfuscation networks are cheap to reconstitute. The structural fact underneath the dispute is that both governments run large intrusion programs and both call the other's version a crime.
How Each Side Sees It
Each major actor’s view — how it frames things, its underlying incentive, and how it’s materially affected. Tap a side to read it.
Frames it asThe government's case rests on a mechanism, not a mood. QTRouter is what investigators call an obfuscation network — a chain of hijacked everyday devices used to launder the origin of an attack[1]. Its whole purpose is to make a Chinese intrusion look like traffic from a home router in Ohio. Prosecutors argue that building such a network for hire, and selling access to a foreign intelligence service and an army, is not ordinary espionage but the construction of a commercial weapons platform[1][7]. They also argue the seizure is proportionate: no arrests, no retaliation, just taking the domain names the malware needs to phone home, which switches the tools off[1]. And they stress the defensive follow-through — the technical details were handed to private companies so others could clean their own networks[9].
WhyDeterrence without escalation, and visible results. Indictments of hackers inside China are unenforceable, so 'technical operations' that actually break a tool are the enforcement lever available[1][9]. Public attribution also pressures the private firms whose devices were hijacked to patch them[7].
Impact on themThe department is itself on the victim list, which sharpens the institutional stake[1][6]. A disclosed multi-year breach of the DOJ, Federal Reserve and Senate networks invites congressional scrutiny of why it ran from 2018 to 2026 before being disrupted[3][6].
Frames it asBeijing's strongest argument is not a denial of the forensics — it is an argument about the standard being applied. Officials say China 'opposes and combats all forms of cyberattacks' and that Washington uses cybersecurity claims as a geopolitical tool[11][8]. The deeper claim is symmetry: the United States operates the world's most capable signals-intelligence apparatus, and China points to its own October 2025 allegation that the NSA spent years inside China's National Time Service Center — the system that keeps national time for finance, power grids and transport[12]. From that vantage, an affidavit naming a Nanjing company is a legal ritual dressed as a moral one. Beijing also notes a real gap in the U.S. filing: DOJ says QTFY sold to state buyers, which is a step short of proving the state ordered the intrusions[1].
WhyProtect the deniability that makes contractor-based operations useful, and keep the argument on the terrain of hypocrisy rather than evidence[11][12].
Impact on themNamed Chinese firms and individuals face sanctions exposure and are cut off from Western infrastructure. Repeated attributions also feed U.S. and allied restrictions on Chinese-made network hardware[7].
Frames it asNASA, the Federal Reserve, the Senate, the Energy Department, HHS and NIH sit on data of very different kinds — spaceflight engineering, monetary policy deliberations, nuclear research, and medical records[1][6]. Their common argument is that an obfuscation network defeats the ordinary defense: if the traffic looks domestic, geography-based blocking fails. Institutions in this position argue they need the government to disrupt the relay layer itself, because no single agency can defend against attacks that arrive wearing a neighbor's address[1][7].
WhySecure funding and legal cover for network modernization, and avoid being blamed for eight years of undetected access[3].
Impact on themRemediation costs, forced audits, and reputational damage. For the Federal Reserve specifically, any suggestion of access to pre-release economic data carries market consequences even absent evidence it occurred[6].
Frames it asThis group is the least represented and arguably most affected. The devices that made up QTRouter were ordinary internet-connected equipment: routers, cameras, building systems[1]. Their owners were neither the attacker's goal nor, mostly, notified. Consumer-security advocates argue the real lesson is manufacturer accountability — devices shipped with default passwords and no update path become national-security infrastructure by accident. Hospital and utility operators, named in coverage among those affected, argue they cannot patch what vendors no longer support[3][4].
WhyShift cost and liability toward device makers rather than end users, and get clear notification when their equipment is used in an attack[7].
Impact on themHijacked devices slow down, get blocklisted, or expose the owner's network. A hospital whose gear is drafted into a botnet may find its own IP addresses blocked by partners[3][4].
Like this article?
The Bias Ledger average rating 4
The same story, as framed by outlets across the spectrum, ordered least to most biased. The bias score (1 = straight, 10 = heavily spun) is an AI assessment of that framing — click an outlet to see its track record. The tell is the word choice or omission that reveals the angle.
| Outlet | Vantage | Bias | How they frame it | The tell |
|---|---|---|---|---|
| CNBC | U.S. center / business | 2 | 'Fed, NASA and DOJ among victims of Chinese state-sponsored hacker group: Court documents' — attributes to the filing in the headline itself. | Puts the Federal Reserve first, which is an audience choice for a business readership, but the 'Court documents' tag keeps the claim sourced rather than asserted. |
| The Register | U.K. technology trade press | 2 | 'FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks' — 'it says' carries the attribution. | Focuses on mechanism over geopolitics, which is its beat. The trade-press habit of trusting the advisory's technical detail while skipping the political dispute is its own kind of narrowing. |
| Time | U.S. center-left | 3 | 'U.S. Says Chinese Hackers Targeted Senate, NASA, Hospitals, and More' — leads with 'U.S. Says' and adds hospitals to the list. | Widening the frame to hospitals moves the story from statecraft to civilian harm. Defensible, but it is an editorial choice about which victim makes the reader care. |
| Al Jazeera | Qatari state-funded | 3 | 'US says Chinese-linked hackers attacked NASA, Senate, and gov't agencies' — 'US says' plus 'Chinese-linked' rather than 'Chinese state'. | The hedge is consistent and visible: every claim is tagged to Washington, and Beijing's rebuttal appears high in the piece. The framing keeps the U.S. as an accuser rather than a narrator. |
| United States Department of Justice | U.S. government — party to the case | 5 | 'Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure' — asserts state sponsorship in the headline. | The release states 'state-sponsored' as settled while its own body language is careful: agencies are 'among the targets,' and MSS and the PLA are described as paying customers rather than as commanders. That gap between headline and text is doing work. |
| Breitbart | U.S. right | 6 | 'DOJ: Chinese State-Sponsored Hackers Breached Senate, Federal Reserve, Multiple Agencies' — 'breached' applied across the whole list. | DOJ's word was 'targeted' for the group as a whole; 'breached' upgrades every named agency to a confirmed compromise. Beijing's denial gets little or no room. |
| RT | Russian state | 7 | 'US accuses China of hacking NASA, Fed and critical infrastructure' — the story is the accusation, not the conduct. | Frames Washington as the actor throughout and routes toward the hypocrisy argument, with the technical findings treated as an unexamined claim rather than evidence to weigh. |
References
- Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure — United States Department of Justice · U.S. government; the prosecuting party in the case
- Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers (Southern District of California) — United States Department of Justice · U.S. government; charging district for the seizure warrants
- US says Chinese hackers hit hospitals, NASA, Senate and more — CNN · U.S. center-left, advertiser-funded cable and digital news
- U.S. Says Chinese Hackers Targeted Senate, NASA, Hospitals, and More — Time · U.S. center-left newsmagazine, privately owned
- US says Chinese-linked hackers attacked NASA, Senate, and gov't agencies — Al Jazeera · Qatari state-funded international broadcaster
- Fed, NASA and DOJ among victims of Chinese state-sponsored hacker group: Court documents — CNBC · U.S. center, business news owned by Comcast/NBCUniversal
- NSA and FBI issue warning about Chinese hacking group QTFY — Intelligence Community News · U.S. trade publication covering the intelligence contracting sector; summarizes the NSA/FBI joint advisory
- Beijing denies US claims it backed hacking operation — Taipei Times · Taiwanese English-language daily, editorially pro-independence and critical of Beijing
- DOJ: Chinese State-Sponsored Hackers Breached Senate, Federal Reserve, Multiple Agencies — Breitbart · U.S. right, explicitly conservative advocacy-oriented outlet
- FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks — The Register · U.K. technology trade press, subscription and advertising funded
- US accuses China of hacking NASA, Fed and critical infrastructure — RT · Russian state-funded international broadcaster
- China accuses US of yearslong cyberattack on national time service — Fox News · U.S. right, advertiser-funded cable and digital news
- Officials disrupt Chinese espionage operation that hit multiple federal agencies — CyberScoop · U.S. trade publication covering federal cybersecurity policy