US officials said Aug. 26 that they have disrupted a Chinese hacking operation responsible for cyber break-ins at the departments of Justice and Energy, NASA, the Federal Reserve, the U.S. Senate and other sensitive federal agencies in one of the most significant state-sponsored cyber espionage takedowns in recent years.
- Hacking Platforms Seized: DOJ disrupted two Chinese hacking platforms—”QScan” and “QTRouter”—used to infiltrate U.S. federal networks and conceal the origin of cyber intrusions.
- Agencies Breached: Victims include NASA, the Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, NIH, and the U.S. Senate.
- State-Sponsored Group: The hacking operation, attributed to the China-based group “QTFY,” is linked to the People’s Liberation Army and China’s Ministry of State Security.
- FBI & DOJ Response: Attorney General Todd Blanche and FBI Director Kash Patel announced the disruption, calling it a critical step in defending U.S. critical infrastructure.
- Chinese Response: Beijing’s embassy in Washington said China “firmly opposes and combats all forms of cyberattacks” and urged the U.S. to stop using cybersecurity to smear China.
Chinese Hackers Breached DOJ, NASA, Federal Reserve, Senate: What We Know
The Justice Department announced that it has seized internet domains used by two hacking platforms, dubbed “QScan” and “QTRouter,” which it said were employed in a penetration campaign by the Beijing government. According to court documents unsealed in the Southern District of California, hackers from a People’s Republic of China state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company, allegedly created and operated the two hacking platforms to burrow into U.S. target networks and then cover their tracks.
The operation’s scale is staggering. Among the victims of QTFY’s computer intrusion activity, the Justice Department documents alleged, are the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the U.S. Senate. Federal officials did not comment on the potential damage done by the cyber-spying effort or how long it was ongoing before being disrupted, citing classified security concerns.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” Attorney General Todd Blanche said in a statement. “We are here to ensure security for the American people and will use every tool we have to keep that promise.” Blanche said federal law enforcement “investigated and disabled the PRC’s malicious software” in the latest series of technical operations to dismantle “indiscriminate hacking activities sponsored by the People’s Republic of China.”
QScan and QTRouter: How the Chinese Hacking Platforms Worked
According to court documents, QTFY’s computer hacking services work in tandem. QScan scans and automatically infects thousands of “internet-of-things” (IoT) devices worldwide, including common smart devices like routers, cameras, and network-connected appliances. Those compromised devices are then added to the QTRouter network of QTFY-controlled devices, creating a massive botnet infrastructure.
QTRouter also serves as an “obfuscation network” to conceal the Chinese government-linked origin of their computer intrusion activities. By routing attacks through compromised devices around the globe, the hackers could disguise their location and make attribution significantly more difficult for U.S. investigators. The scale and sophistication of this operation have drawn comparisons to other high-profile cyber incidents, including the GTA 6 Cyberleak Conspiracy Theories: Why Fans Think Rockstar Is Behind the Leaks, where questions about attribution and insider involvement sparked widespread speculation.
The Justice Department’s official statement on the disruption detailed how the court-authorized seizures announced Aug. 26 made QScan and QTRouter inoperable, effectively dismantling the infrastructure these hackers relied upon. FBI Director Kash Patel emphasized that the bureau played a key role in disrupting “a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure.”
FBI Director Kash Patel and Attorney General Blanche Lead Cyber Disruption Effort
FBI Director Kash Patel said the bureau’s involvement was central to the operation’s success. “In support of President Donald Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace,” Patel said. The disruption effort represents a significant escalation in the U.S. government’s approach to combating state-sponsored cyber threats.
Michael Lebowitz, a former senior attorney in DOJ’s National Security Division and former senior legal adviser to U.S. Army Cyber Command, told USA TODAY that the public announcement “looks to me like a ‘name-and-shame’ campaign where the U.S. essentially publicly calls out foreign hackers to let them know that we’re on to them.” Lebowitz noted that the U.S. often takes similar tactics when indicting foreign hackers because it’s unlikely those hackers would ever be brought to trial in the U.S.
According to court documents, QTFY offers computer hacking services to its paying customers, including China’s Ministry of State Security and People’s Liberation Army, which possesses one of the world’s most formidable hacking capabilities. The targeting of these entities specifically within court documents marks a rare public acknowledgment of the direct government-to-government nature of the cyber conflict.
China’s Response and Diplomatic Tensions Over Cyber Espionage
In a statement to USA TODAY, the Chinese embassy in Washington said Beijing “firmly opposes and combats all forms of cyberattacks in accordance with the law. We urge the US side to stop using cybersecurity issues to smear or discredit China.” The embassy also said China “will firmly safeguard the legitimate rights and interests of Chinese companies” in response to any U.S. efforts to impose punitive restrictions on them based on accusations of hacking.
Beijing’s response reflects the growing diplomatic tensions between the two superpowers over cybersecurity. The U.S. has increasingly used legal and technical means to publicly expose Chinese hacking operations, even as diplomatic channels continue to address the issue.
The Broader Cyber Threat Landscape: China’s Pervasive Hacking Operations
“China’s hacking activities are so pervasive, and they’re able to operate at a scale that very few other countries around the world can match. And they’re very sophisticated,” said Mieke Eoyang, a former deputy assistant secretary of Defense for Cyber Policy and now a visiting professor at Carnegie Mellon University. “But the U.S. is also very sophisticated, and we’ve seen over the past five to 10 years a real increase in focus by the Department of Justice and FBI on being able to go after these types of cyberattacks.”
Such Chinese attacks—and U.S. disruptions—have become a virtually routine cat-and-mouse game as Beijing has successfully penetrated U.S. critical infrastructure over the past decade, including financial institutions and power plants. The U.S. Cybersecurity and Infrastructure Security Agency (CISA), part of the Department of Homeland Security, has designated 16 critical infrastructure sectors whose assets, systems and networks are considered so vital that their incapacitation or destruction would have a debilitating effect on U.S. physical and economic security.
Microsoft warned in May 2023 that it had uncovered “stealthy and targeted malicious activity” by a state-sponsored hacking group known as Volt Typhoon that was targeting U.S. critical infrastructure organizations. That campaign, one of many sustained Chinese hacking efforts, focused on espionage and information gathering, Microsoft said, and was “pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and the Asia region during future crises.”
Private Sector Involvement in Cyber Defense: A New Era of Offensive Operations
The new DOJ announcement is significant because it acknowledges China’s use of cybercriminals to help camouflage its malicious activity on the internet, even as the Trump administration is enlisting the private sector to combat such activity, Eoyang said. “We’ve long known that China has this ecosystem that’s not just the government but involves the commercial side, too, of people selling services to their state security apparatus,” she told USA TODAY.
President Donald Trump signed a national security memorandum on Aug. 12 titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime” that authorizes vetted private U.S. companies to conduct offensive cyber operations against foreign criminal groups under federal supervision.
“I think the jury’s still out on whether or not this is a good thing” for the U.S. to do in response to pervasive hacking efforts by China, Russia, Iran and other government and nonstate entities, Eoyang said. “It certainly makes it harder to call out China for this particular type of bad behavior when the U.S. authorizes it itself,” she said. “But it’s also an admission that the volume of this type of activity happening on the internet is bigger than government’s ability to get after it itself.”
Expert Analysis: The Cat-and-Mouse Game of Cyber Espionage
Lebowitz said the Chinese government has been increasingly effective in sneaking malware and nefarious cyber tools into U.S. systems, especially since it has begun using “niche hacking services that add an extra layer of secrecy and obfuscation that makes detecting those threats so much harder.”
“It’s now a cat and mouse game to detect these threats before they can cause significant damage,” he said. And while Washington is using a whole-of-government approach to detecting Beijing’s hacks, including forensic, intelligence and legal tools, the latest disruption, Lebowitz said, “is likely just the tip of the iceberg in terms of existing threats.”
The ongoing battle between U.S. cyber defenders and Chinese state-sponsored hackers illustrates the new reality of modern warfare—where breaches of government networks, financial systems, and critical infrastructure occur daily, often invisible to the public until operations like this one are disrupted and revealed.



