Technology 42 sources · over 8 days Latest coverage 2 Sept 2026, 8:25 am UTC

US Seizes Chinese Hacking Platforms After Attempted Attacks on Federal Agencies

US authorities disrupted a major Chinese-linked cyber operation that targeted government agencies like NASA and the Federal Reserve, raising concerns about state-sponsored hacking and prompting clarifications about the scope of the breaches.

By Claire Dubois · First published 26 Aug 2026

In brief

  1. US authorities seized domains linked to a Chinese hacking group, disrupting their operations against government agencies like NASA and the Federal Reserve.
  2. The hacking group, known as QTFY, targeted multiple US agencies using sophisticated platforms called QScan and QTRouter since at least 2018.
  3. While several agencies were targeted, US officials clarified that not all were successfully breached, with ongoing investigations into the attacks.
  4. The FBI and Justice Department continue to monitor for further activity linked to Chinese state-sponsored cyber operations.
  5. The US government plans to increase diplomatic pressure on China and enhance cyber defenses across federal agencies.
US Seizes Chinese Hacking Platforms After Attempted Attacks on Federal Agencies
Source: Technology

Timeline · 7 moments

7 moments Open the full timeline →

FBI disrupts China-linked hacking operation targeting US agencies

Technology ↗

US claims Chinese hackers breached Justice Department, NASA, Fed

ITPro ↗

Fed, NASA, DOJ among victims of China hacker group: Court documents

CNBC ↗

US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate

The Record by Recorded Future ↗

US revises statements suggesting Chinese hackers attacked agencies

Al Jazeera ↗

US officials backpedal on claims that gov agencies were hacked

iTnews ↗

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

The Hacker News ↗

How it started

In late August 2026, US officials revealed that a Chinese state-sponsored hacking group had been targeting American government agencies and critical infrastructure. According to the FBI and the Department of Justice, the group, known as QTFY, used custom-built hacking platforms to carry out their activities. The group reportedly had ties to Nanjing Xinjiuwei Network Technology Company and connections to China's Ministry of State Security, as reported by SC World and Infosecurity Magazine.

The operation was notable for its sophistication. The hackers used platforms called QScan and QTRouter, which blended malicious activity with regular internet traffic, making their attacks harder to detect. The targets included high-profile agencies such as NASA, the Federal Reserve, and the Department of Justice.

How it unfolded

On August 26, 2026, the FBI and Justice Department announced they had disrupted the Chinese hacking operation by seizing internet domains tied to the QScan and QTRouter platforms. Outlets like ITPro, CNBC, and The Independent detailed how these platforms were used to orchestrate attempted breaches against multiple US government agencies.

The same day, agencies including NASA, the Federal Reserve, and the Department of Justice were named as targets. Some early reports, such as from CBC News and ABC News, characterized the incidents as successful breaches, suggesting sensitive systems had been infiltrated.

Over the following days, more details emerged about the technical infrastructure behind the hacking campaign. The Record and Infosecurity Magazine reported that the group had been active since at least 2018, using tools developed by or for Chinese state interests. The FBI described the operation as part of a broader pattern of state-sponsored cyber activity targeting not only government agencies but also critical infrastructure and hospitals.

By August 29 and into early September, the story shifted. Outlets including Al Jazeera, iTnews, and The Hacker News reported that US officials clarified their earlier statements. While Chinese hackers had indeed targeted the agencies, there was no evidence that all of them had been successfully breached. The Department of Justice revised its press release to reflect this distinction.

Where it stands

As of early September 2026, US authorities have seized the domains and infrastructure used by the QTFY group. The FBI and the Department of Justice say this action has disrupted the hackers' ability to continue their operations against US targets.

The US government now emphasizes that several agencies were targeted, but not all were compromised. The Justice Department and FBI continue to investigate the scope of the attempted attacks and monitor for further activity linked to Chinese state-sponsored groups.

What to watch

Questions remain about the full extent of the attempted intrusions and whether any sensitive data was accessed during these campaigns. Ongoing investigations may reveal more about the tactics used and the possible involvement of other actors. The US is also expected to increase diplomatic pressure on China and bolster cyber defenses across federal agencies.

Written from 42 outlets' coverage of this story. Every timeline entry links to the original report.

More in Technology

All →