Chinese Hackers Breached NASA, the Fed and US Senate — Now America Says It Has Shut Their Secret Network Down

America Says Chinese Cyber Spies Broke Into Some of Its Most Sensitive Institutions

Who is QTFY?

America’s Hidden Cyber War With China

The United States says a China-linked hacking operation penetrated some of the most sensitive institutions in the American government, including NASA, the Federal Reserve, the Justice Department and the US Senate. Federal authorities have now taken the extraordinary step of seizing internet infrastructure underpinning two hacking platforms they say were central to the campaign.

The scale of the target list is what turns the case from another cybersecurity incident into a national-security warning. The Department of Energy, Department of Health and Human Services and National Institutes of Health were also identified among victims of intrusion activity attributed by US investigators to a group known as QTFY.

The Network Reached Deep Into Washington

Court documents unsealed in California describe QTFY as a group of cyber operators based in China and employed by Nanjing Xinjiuwei Network Technology Company. Investigators allege payments from China's Ministry of State Security indicate the company conducted malicious cyber operations for the Chinese government, while QTFY members included former members of the People's Liberation Army.

The alleged activity stretches back years. Investigators say QTFY infrastructure has been used since at least 2018 to compromise critical infrastructure and other sensitive networks in the United States and overseas, with the US Senate specifically identified as having been targeted in 2026.

The list went beyond federal departments. Hospitals, telecommunications providers, power companies, financial institutions and defence contractors were among networks targeted by the operators, according to the court material.

That breadth matters. A campaign reaching central government, healthcare, finance, telecommunications, energy and defence is not simply about stealing a password or compromising an isolated computer; it creates opportunities to gather intelligence across several of the systems upon which a modern state depends.

QScan Found Targets — QTRouter Hid the Attack

At the centre of the operation were two complementary platforms called QScan and QTRouter. US authorities say QScan scanned for vulnerable internet-connected devices and automatically compromised thousands of them around the world.

Those compromised devices could then become part of QTRouter, alongside commercial proxy devices and rented virtual private servers. The resulting network effectively provided infrastructure through which hacking operations could be routed.

Its most important feature was concealment.

Investigators describe QTRouter as an "obfuscation network" capable of making malicious communications originating with Chinese cyber actors appear to come from machines somewhere else. In some cases, traffic could appear to come from systems geographically close to the organisation being targeted.

That creates a major problem for defenders. Blocking traffic simply because it originates in China becomes far less useful when an attacker can bounce activity through a compromised device in another country — or potentially through infrastructure that appears superficially ordinary.

QScan and QTRouter therefore complemented each other. One helped discover and compromise infrastructure; the other helped transform compromised machines and commercial services into a network through which further operations could be disguised.

US Investigators Link the Operation to Chinese State Customers

The American allegation goes considerably further than saying the hackers happened to be located in China.

The Justice Department says QTFY offered computer-hacking services to paying customers including China's Ministry of State Security and the People's Liberation Army. Federal court papers also say people associated with QTFY used former military relationships to secure contracts and subcontracts supporting offensive cyber operations.

That is important because China has developed an increasingly complicated cyber ecosystem in which government interests, military capabilities, contractors and private technology organisations can potentially overlap.

The allegation here is therefore not merely that a private criminal gang independently attacked American government institutions for money. Washington is accusing infrastructure created by a Chinese company and associated operators of providing hacking capability to organs of the Chinese state.

China has routinely rejected US allegations that it sponsors malicious cyber activity, and its embassy did not immediately provide a response to requests for comment on Wednesday's announcement.

The distinction remains important: the claims concerning the Ministry of State Security, People's Liberation Army and Nanjing Xinjiuwei are allegations made by US authorities and set out in US court documents, rather than findings produced by an adversarial trial.

Why NASA and the Federal Reserve Matter

NASA is an obvious intelligence target. It sits at the intersection of cutting-edge science, aerospace research, satellites, space exploration, contractors and technologies with potentially strategic applications.

The Federal Reserve presents a different prize. It occupies the centre of the world's most influential financial system, handles extraordinarily sensitive economic information and plays a decisive role in US monetary policy.

The Justice Department itself is a major law-enforcement and national-security institution. The Senate sits at the centre of American political decision-making. Energy Department systems can touch areas ranging from energy security to America's nuclear establishment.

Not every penetration automatically means attackers reached the most sensitive information inside an organisation. Public disclosure of an intrusion also does not establish that classified material, monetary-policy plans, nuclear information or mission-critical systems were stolen.

That distinction is essential. US authorities have identified organisations affected by QTFY intrusion activity, but a complete public accounting of exactly what information was obtained from every victim has not yet been released.

The significance is nevertheless substantial. A foreign intelligence operation does not need to achieve catastrophic sabotage to be valuable. Access itself can expose network architecture, credentials, personnel, relationships, communications and weaknesses that may become useful later.

America Has Now Pulled the Plug

The most immediate development is that US authorities did more than name the alleged hackers.

The Justice Department and FBI obtained court authorisation to seize domains essential to QScan and QTRouter. Those domains were hard-coded into the malware and were required for functions including communication and authentication.

According to the Justice Department, removing that infrastructure made both platforms inoperable.

That turns the operation into what American cyber investigators increasingly call a disruption rather than merely an investigation. Instead of waiting to identify and prosecute every individual involved, authorities attempt to take away the infrastructure the adversary needs to operate.

Washington has increasingly adopted that model against Chinese cyber operations.

In 2025, the FBI removed PlugX surveillance malware from more than 4,000 infected US computers attributed to the China-linked Mustang Panda group. In 2024, investigators dismantled a botnet involving hundreds of thousands of compromised internet-connected devices that authorities associated with Flax Typhoon. The previous year, the FBI disrupted infrastructure used by Volt Typhoon against critical infrastructure.

The latest action suggests the same strategy is becoming institutionalised: identify hostile cyber infrastructure, obtain court authority and destroy its operational usefulness before the hackers can continue exploiting it.

The Bigger Fear Is What Access Could Be Used for Later

Chinese cyber espionage has increasingly concerned Western security agencies because access obtained during peacetime can potentially serve several purposes.

Intelligence gathering is the most obvious. Governments want to understand the political intentions, technology, military capability, economic policy and vulnerabilities of their rivals.

But persistent access to critical infrastructure raises a more dangerous possibility.

A network penetrated for espionage can potentially offer knowledge or positioning that becomes strategically important during a future confrontation. Energy, communications, transport, healthcare, financial and government systems therefore represent intelligence targets and potential pressure points.

That does not mean QTFY was preparing to disable every organisation it breached. The public evidence announced on Wednesday does not establish such an intention.

It does, however, explain why US officials increasingly treat apparently quiet Chinese intrusion campaigns as a national-security problem rather than conventional computer crime.

The Operation Also Shows How Cyber Espionage Is Changing

The structure described in the court documents reveals another evolution.

The attackers did not simply connect directly from an easily identifiable Chinese government network to an American target. They allegedly built infrastructure designed specifically to break that connection in the eyes of anyone watching.

Ordinary routers, internet-connected equipment, proxy services and rented servers can become layers between an attacker and victim. Malicious traffic then becomes harder to distinguish from the enormous volume of legitimate communications moving around the internet.

Compromised civilian devices can effectively become camouflage.

That means a homeowner, company or organisation could theoretically have an internet-connected device hijacked and incorporated into infrastructure used to mask operations against an entirely different victim without realising it.

For national cyber defenders, attribution increasingly becomes an intelligence exercise rather than simply an examination of IP addresses.

What Happens Next

The FBI and National Security Agency have released technical information designed to help organisations identify signs associated with QTFY activity, while investigators will continue examining the campaign's infrastructure, victims and operators. US authorities say their analysis of QTFY malicious activity extends back to at least 2018.

Potential victims now face a different problem: discovering whether the operation left anything behind. Destroying command infrastructure can disable the tools being used today, but organisations previously compromised still need to establish what was accessed, whether credentials remain exposed and whether other persistence mechanisms exist.

More detail may also emerge from the unsealed court proceedings. The affidavit already connects the alleged operators with a Chinese technology company, former PLA personnel and payments associated with China's Ministry of State Security.

The immediate operation is therefore a US victory, but it does not end the wider contest.

America has disabled two tools. It has not removed China's ability to conduct cyber espionage, nor the strategic incentive to penetrate government and critical infrastructure networks.

The most uncomfortable part of Wednesday's disclosure is therefore not simply that hackers got inside NASA, the Federal Reserve, the Justice Department and the Senate. It is that investigators say an infrastructure built to make those attacks harder to see had been operating against sensitive networks since at least 2018 — and the full intelligence value extracted during those years may never become public.

Previous
Previous

Tim Curry Dead At 80 As Hollywood Loses One Of Its Most Unforgettable Performers

Next
Next

Lindsay Clancy Trial Reaches Its Final Battle as Prosecutors Attack the Voice at the Heart of Her Defence