Key Points
- U.S. authorities seized domains tied to hacking platforms used against the Justice Department, NASA, Federal Reserve and Senate.
- The Justice Department linked QScan and QTRouter to a China-based company serving intelligence and military clients.
- The campaign targeted critical infrastructure and sensitive networks in the United States and worldwide from at least 2018.
The latest
The United States on Wednesday, August 26, 2026, disrupted a Chinese hacking operation blamed for intrusions and attempted break-ins across sensitive government networks, including the Justice Department, NASA, the Federal Reserve, the Senate and other sensitive agencies. The Justice Department seized domains used by two platforms, QScan and QTRouter, that formed part of the campaign. A court affidavit also identified the Energy Department, Department of Health and Human Services, National Institutes of Health, and four unnamed U.S. and South Korean companies as victims.
Details
- Scope of access: Access varied across the targets. In August 2019, the hackers tried unsuccessfully to enter NASA networks by exploiting a virtual private network vulnerability. The affidavit said tools developed by the group had been used since at least 2018 to compromise critical infrastructure and other sensitive networks in the United States and abroad.
- Platform operator: The Justice Department said the platforms were operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm. Its clients included China’s civilian intelligence agency, the Ministry of State Security, and the People’s Liberation Army, according to the department. The company did not immediately respond outside normal business hours.
- September intrusions: In September 2024, the hackers carried out intrusions at three unnamed Energy Department laboratories, the NIH, an unidentified HHS agency and a U.S. security-device manufacturer. The affidavit distinguished successful intrusions from unsuccessful access attempts and said the level of access gained differed among affected organizations.
- Chinese response: China’s embassy in Washington did not immediately respond to a request for comment. Beijing routinely denies responsibility for hacking activity. Representatives for the agencies and government organizations identified as targets also did not immediately respond.
- Contractor market: Private contractors routinely conduct high-profile intrusions for Chinese government agencies, said Dakota Cary, a China analyst at cybersecurity company SentinelOne. “Over the last decade, the number of companies offering niche offensive services has exploded,” Cary said.
Background
Chinese-linked hacking campaigns have compromised a series of sensitive U.S. government and private networks in recent years. In March, the FBI notified Congress that hackers had penetrated certain agency networks connected to people under FBI investigation; public reporting later attributed that breach to China. Chinese-linked hackers have also been tied to compromises affecting certain U.S. House of Representatives committee networks and several major telecommunications companies. Cybersecurity specialists say private contractors carry out prominent intrusions on behalf of different Chinese government agencies.
What’s next
The next indicator will be whether QScan and QTRouter remain operational after the domain seizures, alongside any response from the Chinese embassy, Nanjing Xinjiuwei or the affected U.S. organizations.