
The FBI says a China-backed hacking crew quietly poked at America’s vital systems for years—and the tools they used were just seized.
Story Snapshot
- Justice Department and FBI seized platforms tied to China-backed hackers targeting U.S. critical systems.
- Court filings and a Pentagon advisory link the group known as QTFY to wide U.S. targeting.
- Victims listed include NASA, the Justice Department, the Federal Reserve, and the Senate.
- China’s embassy denies state ties and calls such claims smears.
What U.S. Authorities Say Happened
The Justice Department said agents seized internet platforms used to go after U.S. critical infrastructure. The announcement landed on August 26, 2026, and named China-state-sponsored hackers as the operators behind the systems. Federal filings and briefings described a years-long campaign.
Targets included government agencies and sectors that keep daily life running. The thrust is simple: the government is treating this as a national security issue, not a run-of-the-mill data breach, and moved to cut off the attackers’ tools at the source.
China’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ. https://t.co/3Kdpl4RA4j
— WIRED (@WIRED) August 26, 2026
Reporters who reviewed unsealed court documents said the list of victims was not theoretical. The filings cite attempted and successful intrusions touching the Justice Department, the National Aeronautics and Space Administration, the Federal Reserve, and the United States Senate.
That blend hits law enforcement, space operations, monetary policy, and the legislative branch. A campaign that reaches across those pillars signals focus and patience. It speaks to tradecraft that hides in plain sight, lives off the land, and forces defenders to hunt instead of react.
Who QTFY Is And Why It Matters
A defense advisory tied the activity to a group called QTFY and linked it to a Chinese company, Nanjing Xinjiuwei Network Technology Company. The document names two core tools: QScan and QTRouter. These tools help attackers hide their location, move traffic through layers of proxies, and scan for weak points in targets.
The advisory says the group’s reach touched defense contractors, communications networks, higher education, and government systems across the United States. That scope reflects a sustained effort to map and test the country’s digital backbone.
The same advisory described specific U.S. targets tested with QScan. Those included a state government, a water district, a hospital system, and the United States Senate. It also mentioned scanning of a United States election system.
The pattern points to reconnaissance and access-building against services that must run every day. When hackers case water systems and hospitals, they are learning how to break things at the worst time. That is the core risk for any community that relies on digital control systems.
What Makes This Campaign Different
Federal officials did not just publish a warning. They seized the infrastructure they say enabled the attacks. That step forces the adversary to rebuild trust, tooling, and logistics. It also signals to other actors who rent or share these services.
The filings and coverage say QTFY’s platforms supported both espionage and access sales to Chinese government customers through a private firm, a model that blurs the lines between state and contractor. That “platform plus contractor” blend aligns with a broader shift in how modern cyber operations are conducted.
🚨🇺🇸 MAJOR U.S. CYBER OPERATION TARGETS CHINA-BACKED HACKING INFRASTRUCTURE
The DOJ and FBI have announced a court-authorized disruption operation against two hacking platforms — QScan and QTRouter — that U.S. authorities say were operated and used by China state-sponsored…
— Peace Maker (@princezar) August 26, 2026
Some will ask whether public attributions hold up. China’s embassy in Washington rejected the claims and urged the United States to stop using cybersecurity to smear China. Denials are part of the ritual. But the United States backed its claims with seizures, affidavits, and a joint defense advisory that named tools, tradecraft, and targets.
Why This Hits Home For Regular Americans
This is not just a Beltway story. If a hospital’s network goes down, patients feel it within minutes. If a water utility’s controls fail, an entire town feels it by nightfall. If a state network goes down during an election cycle, trust drops even if the vote is safe.
The filings and the advisory map to these very stakes. The country cannot afford to treat cyberattacks like background noise. Strong deterrence, fast disruption, and clear public guidance are the only sane path.
Practical steps flow from the facts. Governors should demand audits of water, energy, and hospital systems against scanning and proxy abuse.
Agencies should block the known tool traffic and verify remote access paths with hardware keys. Boards should fund tabletop drills for outage scenarios.
Congress should match words with resources so local networks can patch faster than adversaries pivot. The government showed its cards and swung the hammer. Now operators in every county must close the doors left ajar.
Sources:
nypost.com, media.defense.gov, berndpulch.org, reuters.com, justice.gov

















