
Federal agents say a China-backed hacking crew quietly prowled U.S. government and critical systems for years—and they just yanked key tools out of its hands.
Story Snapshot
- Justice Department and FBI seized platforms used in attacks on U.S. critical infrastructure.
- Court records tie the group, called QTFY, to hits on top federal agencies.
- Defense officials link QTFY’s tools to scanning and targeting across core sectors.
- China’s embassy denies state ties and condemns hacking claims as smears.
U.S. Seizes Hacker Platforms After Years Of Intrusions
The Department of Justice said it seized internet platforms run and used by a China state-backed group that targeted U.S. critical infrastructure. The announcement landed August 26, 2026, and paired law enforcement action with public warning.
The Federal Bureau of Investigation described the campaign as years-long and aimed at hundreds of targets, including government systems. This move fits a playbook that turns technical findings into visible costs and alerts for potential victims.
China’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ. https://t.co/3Kdpl4RA4j
— WIRED (@WIRED) August 26, 2026
It was reported that court documents cite intrusions and attempts on the Department of Justice, the National Aeronautics and Space Administration, the Federal Reserve, and the United States Senate.
The filings also list energy sector targets, health agencies, and companies in the United States and South Korea. The records identify a group known as QTFY as the operator behind the seized infrastructure and the broader campaign.
Who Is QTFY And What Did They Use?
A Defense Department advisory names QTFY as linked to Nanjing Xinjiuwei Network Technology Company, established in 2018. It describes QTFY’s products as designed to hide attacker locations and route traffic through layers of compromised devices.
It details use of a tool called QScan, which probed targets across defense, communications, government, and higher education. The advisory lists scanning of a United States state government, a water district, the Senate, a hospital system, and an election system in 2026.
A review of the unsealed affidavit says QTFY also pushed services branded as QScan and QTRouter to clients in China’s security services through a private firm.
The document lists a failed 2019 attempt to breach a National Aeronautics and Space Administration network and successful 2024 intrusions at three Department of Energy labs, the National Institutes of Health, the Department of Health and Human Services, and a United States security device maker. It also cites targeting of hospitals, telecoms, power companies, banks, and defense contractors.
China’s Denial, And What Matters For Defenders
The Chinese embassy in Washington rejects the claims. It says China opposes all cyberattacks and urges the United States to stop using cybersecurity to smear China.
That line mirrors past embassy statements calling similar allegations baseless and stressing that China neither endorses nor tolerates hacking. These denials present a clear position but do not address the detailed technical claims in U.S. filings and advisories.
American readers should weigh the sources and the evidence posture. On one side are sworn affidavits, domain seizures, and a joint Defense advisory that lays out tools, tactics, and named targets. On the other are diplomatic statements without technical refutation.
Why This Operation Signals A Shift In Risk
This case is not about one agency breach. It shows a service model that sells stealth, reach, and speed to many operators at once. That model lowers the skill bar for complex intrusions and spreads risk across hospitals, labs, utilities, and legislatures. It also creates a durable base for future operations.
Cutting off core platforms raises adversaries’ costs now, but defenders should plan for replacements and copycats to emerge quickly.
🚨🇺🇸 MAJOR U.S. CYBER OPERATION TARGETS CHINA-BACKED HACKING INFRASTRUCTURE
The DOJ and FBI have announced a court-authorized disruption operation against two hacking platforms — QScan and QTRouter — that U.S. authorities say were operated and used by China state-sponsored…
— Peace Maker (@princezar) August 26, 2026
Policy signals matter here as much as arrests. The United States has grown more willing to name names, seize infrastructure, and warn sectors in plain language. The method—attribution by indictment and seizure—sets a public record and aids civil defenders who must prioritize scarce resources.
That approach works best when paired with rapid patching, network segmentation, offline backups, and strict access controls around remote support tools that attackers often exploit.
What To Watch Next
Watch for follow-on actions such as Treasury sanctions, new advisories, and patch mandates for vendors whose tools are everywhere. Expect more detail from the Federal Bureau of Investigation and partners as victims complete forensics.
Monitor for QTFY-linked infrastructure reappearing under new branding, which often occurs after takedowns. Track China’s official channels for any technical rebuttal beyond general denials; concrete counter-evidence would change the picture, but it has not surfaced yet.
Sources:
nypost.com, cnbc.com, media.defense.gov, berndpulch.org, reuters.com, justice.gov, nextgov.com


















