Federal officials on Wednesday announced they had disrupted a yearslong Chinese hacking campaign that compromised or targeted several U.S. institutions, including NASA, the Federal Reserve, and even the Senate. The Justice Department said in a statement it had seized internet domains used by two hacking platforms, called “QScan” and “QTRouter,” that were created and operated by a Chinese state-sponsored group. The platforms were used to target U.S. critical infrastructure and other sensitive networks.
FBI Director Kash Patel said tools were used by Chinese government actors “to hide the origin of their attacks.” An attached affidavit from an FBI agent accused the state-sponsored group, referred to as “QTFY,” of targeting the Department of Energy, Department of Justice, Department of Health and Human Services, and the National Institutes of Health. The group also allegedly targeted networks “operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.” The DOJ’s announcement did not specify if anybody had been charged or apprehended in relation to the hacking, and the extent of what has been compromised remains unclear. TIME has reached out to the DOJ for comment.
The group’s hacking activity, which dates back to 2018 according to the FBI, adds to an ongoing record of U.S. allegations of Chinese state-backed cyberespionage operations. A spokesperson for the Chinese Embassy in Washington, D.C. pushed back against the accusations in a statement to TIME, insisting that China is a “firm defender” of cybersecurity. QTFY members, according to the DOJ affidavit, include former members of the People’s Liberation Army—China’s military forces—who used their PLA relationships “to obtain contracts and subcontracts supporting offensive cyber operations.” The QTFY actors were allegedly employed by the Nanjing Xinjiuwei Network Technology Company, which “conducts malicious cyber activities” for the Chinese government, per the FBI.
The affidavit stated that not all of the attempted intrusions had been successful. In August 2019, the group failed in attempting to break into NASA's server by exploiting a vulnerability in its virtual private network. In September 2024, QTFY actors conducted computer intrusions at three unnamed laboratories of the Department of Energy, the NIH, an HHS agency, and another unnamed U.S. security device manufacturer.
Other efforts by the hacking group were detailed in a joint cybersecurity advisory authored by the FBI, the National Security Agency, and the U.S. Cyber Command's Cyber National Mission Force. According to the advisory, the group conducted a vulnerability scan of the U.S.
Senate and an American hospital system in March 2026, and of an unidentified U.S. election system in June 2026. Both attempts to gain access to these networks failed. Speaking to Fox News, Attorney General Todd Blanche said Wednesday that the operation has been happening for many years and is a “major national security issue” for the U.S., adding that the authorities have not only stopped the operation, but have also shared the information with the private sector to stop further attempts.
Extract — continue reading at the source.