Chinese State-Sponsored Hackers Breached NASA, Federal Reserve, DOJ and U.S. Senate as Beijing Hid Attacks Behind Thousands of Hijacked Devices


Aug. 27, 2026, 4:12 a.m.

Views: 1677


ChatGPT Image Aug 27, 2026, 09_28_03 AM (1)

Chinese State-Sponsored Hackers Breached NASA, Federal Reserve, DOJ and U.S. Senate as Beijing Hid Attacks Behind Thousands of Hijacked Devices

A Chinese state-sponsored hacking operation penetrated some of the most sensitive institutions in the United States—including NASA, the Federal Reserve, the Justice Department, the Department of Energy and the U.S. Senate—while using a worldwide network of compromised internet-connected devices to conceal where the attacks actually originated. The Justice Department and FBI on August 26 dismantled two cyber platforms known as QScan and QTRouter that federal investigators say were created and operated by a People’s Republic of China state-sponsored group known as QTFY. Court documents identify QTFY personnel as employees of China-based Nanjing Xinjiuwei Network Technology Company and say the organization sold hacking services to customers that included China’s Ministry of State Security and the People’s Liberation Army. This is not another vague allegation of suspicious traffic originating somewhere in China. The U.S. government has identified the operator, the infrastructure, the tools, the targets and the Chinese intelligence and military customers that allegedly benefited from the system.

The list of American victims demonstrates how broad the operation became. According to the FBI affidavit, QTFY infrastructure was used from at least 2018 onward to compromise critical infrastructure and sensitive networks in the United States and around the world. Federal targets included NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and, in 2026, the U.S. Senate. Other targets included hospitals, telecommunications companies, electric-power providers, financial institutions and defense contractors. Taken together, those sectors provide a disturbing map of what Beijing’s cyber ecosystem considers valuable: government decision-making, financial information, scientific research, public health, energy infrastructure, communications networks and the companies supporting American defense capabilities.

The sophistication of QTFY was not limited to breaking into individual computers. Investigators say the Chinese operation developed an industrialized platform for finding targets and hiding the attackers. QScan automatically searched the internet for vulnerable systems and infected thousands of Internet-of-Things devices around the world. Those compromised devices were then incorporated into QTRouter, which combined hacked IoT equipment with commercial proxy services and leased virtual private servers. The resulting network functioned as an obfuscation layer. Instead of malicious traffic appearing to come directly from China, an intrusion could appear to originate from an ordinary router or device somewhere else in the world—or even from a machine geographically close to the American organization being targeted.

That architecture is particularly dangerous because it turns ordinary civilian technology into camouflage for Chinese state-sponsored espionage. A home router, internet-connected camera or other poorly secured IoT device may appear insignificant on its own, yet once compromised it can become a relay point for attacks against government agencies, power companies, hospitals or defense contractors. This gives Beijing-linked hackers two strategic advantages. First, the attacker acquires enormous numbers of disposable infrastructure nodes without having to build them from scratch. Second, investigators attempting to trace the attack may initially see malicious traffic coming from an innocent device in the United States or another country instead of infrastructure directly associated with China. QTRouter was built specifically to provide that concealment function, according to DOJ.

The relationship between the private Chinese company and the Chinese security apparatus deserves particular American scrutiny. The FBI affidavit says QTFY actors include former members of the PLA who used their military relationships to obtain contracts and subcontracts supporting offensive cyber operations. DOJ further states that QTFY offered computer-hacking services to paying customers including the Ministry of State Security and the PLA. This demonstrates an increasingly important feature of China’s cyber model: Beijing does not need every hacker to sit behind a government desk with a military insignia on the wall. Private or nominally commercial Chinese companies can provide vulnerability scanning, intrusion infrastructure, proxy networks and technical services while state intelligence and military organizations purchase or exploit those capabilities.

That commercialized structure creates a serious attribution problem for the United States. A company can maintain the outward appearance of an ordinary cybersecurity or network-services business while providing technical capabilities useful for state espionage. Contractors and subcontractors create distance between the Chinese government and the computers actually conducting the intrusion. Compromised routers create another layer of separation. Commercial proxy networks create another. By the time malicious traffic reaches an American target, the visible source may be several layers removed from the organization directing or benefiting from the operation. The system therefore does more than improve hacking efficiency—it creates plausible distance and consumes the time of American defenders who must reconstruct an intentionally obscured chain.

The targets also show why these attacks must be treated as a national-security problem rather than ordinary cybercrime. The Federal Reserve sits at the center of the American financial system. NASA possesses aerospace, satellite and scientific capabilities of obvious strategic value. The Department of Energy oversees sensitive energy and national-security programs. NIH and HHS hold extraordinarily valuable health and biomedical information. The Senate handles legislation, oversight, foreign policy and sensitive communications involving national priorities. Defense contractors possess technology and operational information that can affect American military superiority. Successfully penetrating even one of these environments can provide intelligence useful for diplomacy, economic competition, military planning or technological development. Penetrating several categories over a period stretching back to at least 2018 suggests a sustained intelligence-collection capability rather than a single opportunistic hack.

The operation also fits a much larger pattern of Chinese state-sponsored cyber activity against American infrastructure. DOJ noted that the QTFY disruption follows previous operations against Mustang Panda, Flax Typhoon and Volt Typhoon. In 2025, the FBI removed PlugX surveillance malware from more than 4,000 U.S. computers infected by the PRC-sponsored Mustang Panda group. In 2024, federal authorities disabled a botnet containing hundreds of thousands of compromised IoT devices that the PRC-sponsored Flax Typhoon group was providing to Chinese government customers. In 2023, the FBI disrupted another botnet used by Volt Typhoon to conceal intrusions into U.S. and foreign critical infrastructure. These are different operations, but together they show an enduring Chinese strategy: compromise large quantities of civilian internet infrastructure, hide state activity inside ordinary traffic and preserve access to systems that could matter during geopolitical confrontation.

Volt Typhoon established why Americans should think beyond conventional intelligence theft. U.S. and private-sector cybersecurity officials have warned that Chinese operators targeted American critical infrastructure in ways consistent with preparing capabilities that could be useful during a future crisis. Communications, electricity, transportation and other civilian systems are not merely repositories of interesting information. They are systems whose disruption could complicate American military mobilization, interfere with government decision-making or impose economic and psychological costs on the population during a confrontation in the Indo-Pacific. The QTFY case does not mean every compromised system was prepared for sabotage, but a Chinese state-sponsored ecosystem that can repeatedly penetrate U.S. infrastructure while hiding behind civilian devices gives Beijing an operational foundation that America cannot afford to treat casually.

The August 26 seizures were strategically valuable because investigators exploited a weakness in QTFY’s own architecture. DOJ says the seized internet domains had been hard-coded into QScan and QTRouter and were required for functions such as authentication and communication. By obtaining court authorization to seize those domains, U.S. authorities rendered both platforms inoperable. That is a useful model for cyber defense because it does more than identify malicious code after an intrusion. It attacks the infrastructure that allows adversaries to operate at scale. The United States should continue combining intelligence analysis, criminal process, technical intervention and private-sector cooperation to destroy the platforms Chinese state-sponsored groups rely upon, rather than merely blocking individual IP addresses after each intrusion.

But the takedown should not create complacency. QTFY operated from at least 2018 until 2026, and the public record does not disclose the full extent of information obtained from every compromised American organization. Cyber operators can rebuild infrastructure, change domain architecture, purchase different proxy services and infect another generation of vulnerable devices. The strategic response therefore has to extend to the enormous pool of poorly secured routers, cameras and IoT equipment that makes networks like QTRouter possible. Manufacturers need secure-by-default configurations and longer security-update lifecycles; American organizations need to remove abandoned equipment, patch internet-facing systems aggressively and monitor traffic patterns that indicate compromised proxy infrastructure. A forgotten router should not be allowed to become Beijing’s next anonymous doorway into an American government network.

The United States should also scrutinize Chinese cybersecurity and network companies that maintain unusually close relationships with the PLA, MSS or other state-security organs. The QTFY model shows why the line between a commercial hacking service and a government cyber capability can be strategically meaningless. If a company develops tools that identify vulnerable systems, automatically compromises devices and provides anonymized attack infrastructure to Chinese intelligence agencies, Washington should evaluate the entire corporate network surrounding it: executives, affiliates, cloud providers, payment channels, contractors and overseas infrastructure. Disrupting one domain is useful; making it difficult for the organization to reconstitute itself under another corporate name is more important.

Americans should recognize what the QTFY operation ultimately represents. China’s cyber capabilities are not aimed only at stealing one company’s intellectual property or spying on one government office. According to U.S. court documents, a PRC state-sponsored organization built a reusable hacking ecosystem capable of reaching federal agencies, financial institutions, hospitals, power companies, telecommunications networks and defense contractors while disguising its operations behind ordinary devices around the world. The same system served customers that included China’s intelligence service and military. When Beijing-linked hackers can hide behind someone else’s router while penetrating the Federal Reserve, NASA, the Justice Department and the U.S. Senate, America is confronting more than cybercrime. It is confronting a state-backed infrastructure for persistent access into the institutions that keep the country functioning.


Return to blog