Pressure of Truth
Exposing the spin on all sides of the news.
U.S.

Justice Department and FBI Seize Domains Behind Two China-Linked Hacking Platforms, Naming NASA, the Federal Reserve and the Senate Among Targets

Court-authorized seizures announced August 26, 2026 disabled the QScan and QTRouter tools that U.S. officials link to a Chinese group active since 2018; Beijing calls the allegations false.

How spun is the coverage?Coverage bias 4.0 / 10
4 sides analyzed13 sources cited

Two Domain Names Just Silenced a Hacking Platform That Ran Two Million Break-Ins a Day

Somewhere in a Justice Department filing, a small technical fact is doing most of the work: two hacking tools called QScan and QTRouter needed to phone home. Every time they scanned a device or routed an attack, they checked in with a handful of hard-coded domain names[1]. On August 26, 2026, the FBI and Justice Department got a court order and took those domains away. Without them, both tools went dark[1].

That is the whole mechanism behind a case that also names NASA, the Federal Reserve, the U.S. Senate, and four other federal agencies as targets[1][6]. Officials say the tools were built and run by a China-based group they call QTFY, working for a Chinese company, Nanjing Xinjiuwei Network Technology Co[1][2]. China's government says the accusation is false[5][11]. Both things are now part of the public record, and neither cancels the other out.

What QScan and QTRouter Actually Did

The two tools worked as a pair, and understanding them explains why the case matters beyond Washington. QScan combed the internet for weakly secured devices — home routers, security cameras, other everyday gear plugged into the internet — and broke into the ones it found automatically[1]. On a single day in 2024, it ran more than two million scanning and break-in attempts[7].

QTRouter took over from there. It strung the hijacked devices into a relay chain, so an attack launched from China would appear to come from an ordinary computer somewhere else entirely — a home in Ohio, say[1]. Investigators call this an obfuscation network. Its entire purpose is to make foreign intrusions look domestic, which is exactly what defeats most basic cyber defenses that block traffic by geography[1][7].

Officials say QTFY did not just use this network. It sold access to it, including to China's Ministry of State Security and the People's Liberation Army[1][7]. That detail is why prosecutors are treating the case as more than routine espionage — they describe it as a commercial hacking-for-hire operation with state customers[1].

The Word Doing the Most Work in the Government's Own Filing

Read closely, the Justice Department's release says NASA, the Federal Reserve, the Senate, and the Departments of Energy, Justice, and Health and Human Services, plus the National Institutes of Health, were "among the targets" of QTFY[1][6]. Targeted is not the same word as breached. An FBI agent's affidavit dates the group's activity back to 2018 and says it continued into 2026 — roughly eight years[3][6].

A joint advisory from the NSA, FBI, and Cyber National Mission Force adds a detail that sharpens that distinction rather than blurring it. It says QTFY's scans of the Senate and a hospital system in March 2026, and of a U.S. election system in June 2026, all failed to break in[13]. So for at least some of the named targets, the record shows an attempt and a failure, not a confirmed compromise.

That nuance mostly disappeared once the story reached the public. Attorney General Todd Blanche told Fox News the campaign is "a major national security issue" and said law enforcement had "investigated and disabled" the software[9]. Breitbart's headline read that Chinese hackers "breached" the Senate, the Federal Reserve, and multiple agencies — applying that word to the entire list, not just the confirmed cases[9].

A Denial That Skips the Forensics and Goes Straight to a Different Question

China's embassy in Washington said the country "opposes and combats all forms of cyberattacks" and told the United States to stop using cybersecurity claims to "smear or discredit" it[11][8]. Beijing's foreign ministry called the allegations false[5]. Notably absent from that response is any technical rebuttal of the QScan and QTRouter forensics themselves.

Instead, Beijing points to its own accusation. In October 2025, Chinese authorities said the NSA ran a years-long attack on China's National Time Service Center, the system that keeps national time for the country's finance, power grid, and transportation networks[12]. Chinese officials say the attack began with credential theft in 2022, with the NSA gaining initial access in April 2023 and further intrusion attempts running through 2024.

That comparison is the core of China's argument, whether or not you find it persuasive. It's not that hacking doesn't happen — it's that the United States runs its own large-scale intrusion programs and is, in this reading, applying a legal process to conduct it also engages in. The Justice Department's filing does not resolve that argument, because proving QTFY sold access to Chinese state buyers is not the same as proving the state ordered the intrusions[1].

Why "Seize the Domains" Is the Tool the U.S. Actually Has

There's a structural reason this case looks the way it does, and it has little to do with how serious the intrusions were. The United States cannot arrest hackers sitting in Nanjing. So the tools available to prosecutors are narrow: take away infrastructure the malware needs, publish technical advisories, sanction the companies involved[1][9]. Seizing two domain names is, in practice, close to the ceiling of what's achievable without cooperation from Beijing.

That constraint also explains why routing operations through a private contractor is useful to a state that wants deniability. A company that sells hacking access to multiple buyers can generate real revenue while giving the government an easier story to deny — the sales are documented, but the direction is not[1][7]. Whether or not that's what happened here, the structure of contractor-run operations is built to produce exactly that gap in the evidence.

Underneath both governments' programs sits the same raw material: insecure consumer hardware. Neither Washington nor Beijing created the market for cheap routers and cameras with default passwords and no update path. That market is what let QScan run two million scans in a day[7]. It's also, by extension, what makes these obfuscation networks cheap to rebuild — nothing about this seizure stops QTFY from standing up new domains and starting over[1].

The People Least Mentioned in Any Version of This Story

Thousands of hijacked devices made up the QTRouter relay network, and most of their owners were never named as victims and likely never will be notified[1][7]. These are the routers, cameras, and building systems that got quietly drafted into someone else's attack. Coverage from CNN and Time widened the frame to include hospitals, utilities, and universities among those affected, which shifts the story from a state-to-state dispute toward civilian exposure[3][4].

For a hospital or a small business running outdated equipment, the consequence isn't state secrets — it's a device that slows down, gets blocklisted, or exposes the rest of the network. Consumer-security advocates argue the real fix sits with device manufacturers, not end users who often have no way to know their equipment is compromised, let alone patch it[3][4][7].

What happens next isn't settled. Court records name the group and the company, but nothing in this seizure recovers data already taken, and nothing stops QTFY from rebuilding its network on new domains[1]. The technical details from the advisory have been shared with private companies so they can check their own systems[9] — which means the next chapter of this story, if there is one, will likely start with someone else's network logs.

Like this article?

Share this article

The Bias Ledger average rating 4

The same story, as framed by outlets across the spectrum, ordered least to most biased. The bias score (1 = straight, 10 = heavily spun) is an AI assessment of that framing — click an outlet to see its track record. The tell is the word choice or omission that reveals the angle.

OutletVantageBiasHow they frame itThe tell
CNBCU.S. center / business2'Fed, NASA and DOJ among victims of Chinese state-sponsored hacker group: Court documents' — attributes to the filing in the headline itself.Puts the Federal Reserve first, which is an audience choice for a business readership, but the 'Court documents' tag keeps the claim sourced rather than asserted.
The RegisterU.K. technology trade press2'FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks' — 'it says' carries the attribution.Focuses on mechanism over geopolitics, which is its beat. The trade-press habit of trusting the advisory's technical detail while skipping the political dispute is its own kind of narrowing.
TimeU.S. center-left3'U.S. Says Chinese Hackers Targeted Senate, NASA, Hospitals, and More' — leads with 'U.S. Says' and adds hospitals to the list.Widening the frame to hospitals moves the story from statecraft to civilian harm. Defensible, but it is an editorial choice about which victim makes the reader care.
Al JazeeraQatari state-funded3'US says Chinese-linked hackers attacked NASA, Senate, and gov't agencies' — 'US says' plus 'Chinese-linked' rather than 'Chinese state'.The hedge is consistent and visible: every claim is tagged to Washington, and Beijing's rebuttal appears high in the piece. The framing keeps the U.S. as an accuser rather than a narrator.
United States Department of JusticeU.S. government — party to the case5'Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure' — asserts state sponsorship in the headline.The release states 'state-sponsored' as settled while its own body language is careful: agencies are 'among the targets,' and MSS and the PLA are described as paying customers rather than as commanders. That gap between headline and text is doing work.
BreitbartU.S. right6'DOJ: Chinese State-Sponsored Hackers Breached Senate, Federal Reserve, Multiple Agencies' — 'breached' applied across the whole list.DOJ's word was 'targeted' for the group as a whole; 'breached' upgrades every named agency to a confirmed compromise. Beijing's denial gets little or no room.
RTRussian state7'US accuses China of hacking NASA, Fed and critical infrastructure' — the story is the accusation, not the conduct.Frames Washington as the actor throughout and routes toward the hypocrisy argument, with the technical findings treated as an unexamined claim rather than evidence to weigh.

References

  1. Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure — United States Department of Justice · U.S. government; the prosecuting party in the case
  2. Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers (Southern District of California) — United States Department of Justice · U.S. government; charging district for the seizure warrants
  3. US says Chinese hackers hit hospitals, NASA, Senate and more — CNN · U.S. center-left, advertiser-funded cable and digital news
  4. U.S. Says Chinese Hackers Targeted Senate, NASA, Hospitals, and More — Time · U.S. center-left newsmagazine, privately owned
  5. US says Chinese-linked hackers attacked NASA, Senate, and gov't agencies — Al Jazeera · Qatari state-funded international broadcaster
  6. Fed, NASA and DOJ among victims of Chinese state-sponsored hacker group: Court documents — CNBC · U.S. center, business news owned by Comcast/NBCUniversal
  7. NSA and FBI issue warning about Chinese hacking group QTFY — Intelligence Community News · U.S. trade publication covering the intelligence contracting sector; summarizes the NSA/FBI joint advisory
  8. Beijing denies US claims it backed hacking operation — Taipei Times · Taiwanese English-language daily, editorially pro-independence and critical of Beijing
  9. DOJ: Chinese State-Sponsored Hackers Breached Senate, Federal Reserve, Multiple Agencies — Breitbart · U.S. right, explicitly conservative advocacy-oriented outlet
  10. FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks — The Register · U.K. technology trade press, subscription and advertising funded
  11. US accuses China of hacking NASA, Fed and critical infrastructure — RT · Russian state-funded international broadcaster
  12. China accuses US of yearslong cyberattack on national time service — Fox News · U.S. right, advertiser-funded cable and digital news
  13. Officials disrupt Chinese espionage operation that hit multiple federal agencies — CyberScoop · U.S. trade publication covering federal cybersecurity policy