US disrupts Chinese hacking network linked to cyberattacks on Justice Department, NASA, Federal Reserve
- In Reports
- 02:05 PM, Aug 27, 2026
- Myind Staff
The United States on Wednesday said it had disrupted a Chinese hacking operation linked to break-ins and attempted intrusions targeting several sensitive government agencies. The targets included the Justice Department, NASA, the Federal Reserve and the US Senate, along with other government and private networks. US officials said the campaign had been active for years and involved efforts to access critical infrastructure and sensitive systems in the US and other countries.
The Justice Department said it had seized domains used by two hacking platforms known as QScan and QTRouter. The department said the platforms played a role in the wider cyber campaign. It identified China-based Nanjing Xinjiuwei Network Technology Company as the operator of the platforms. According to the Justice Department, the company’s clients included China’s civilian intelligence agency, the Ministry of State Security, and the country’s military, the People’s Liberation Army.
China rejected the US allegations and said it opposed cyberattacks. A spokesperson for the Chinese Embassy in Washington said in an email that while they were not familiar with the specifics mentioned in the DOJ statement, the "Chinese government firmly opposes and combats all forms of cyberattacks in accordance with the law." The spokesperson also accused the US of using cybersecurity concerns to target China. The US uses cybersecurity issues to "smear or discredit China," the spokesperson said, and China "opposes the U.S. overstretching the concept of national security and using it as a pretext to impose discriminatory restrictions on Chinese companies and will firmly safeguard the legitimate rights and interests of Chinese companies."
US authorities said the hacking tools had been used against critical infrastructure and other sensitive networks since at least 2018. An affidavit linked to the case said the hackers developed tools to identify weaknesses and gain access to targeted systems. Not every attempt succeeded. One failed operation targeted NASA networks in August 2019. The hackers tried to exploit a vulnerability in a virtual private network to enter the agency’s systems.
The campaign continued in later years. In September 2024, the hackers successfully carried out intrusions at three unnamed laboratories linked to the Energy Department, the National Institutes of Health and an unnamed agency under the Department of Health and Human Services. They also targeted a US manufacturer of security devices, according to the affidavit. The incidents showed the wide range of organisations that came under attack.
A joint cybersecurity advisory from the FBI, the National Security Agency and US Cyber Command’s Cyber National Mission Force outlined several other hacking attempts. The advisory said the hackers successfully stole data from unnamed defence contractors, financial institutions and universities in May 2024. These operations showed that the group targeted both government-linked organisations and private institutions.
The hackers also continued to scan US networks for weaknesses. In March 2026, they searched for vulnerabilities in the networks of the US Senate and a US hospital. Their attempts to access both networks were unsuccessful, according to the affidavit. The activity formed part of a wider campaign to identify vulnerable systems and gain access to sensitive networks.
NASA declined to comment on specific incidents. A spokesperson for the agency said it does not comment on individual cyber incidents. The Department of Health and Human Services referred questions about the matter to the Justice Department. The DOJ did not respond to a request for additional details.
The latest case adds to a long list of cyber incidents that US authorities have linked to China. In March, the FBI informed Congress that hackers had gained access to certain agency networks connected to people under FBI investigation. Public reports later linked that breach to China. Chinese-linked hackers have also been associated with attacks on networks belonging to US House of Representatives committees and several major telecommunications companies in recent years.
Cybersecurity experts who track Chinese hacking activity say private contractors often conduct major cyber operations on behalf of Chinese government agencies. These companies provide specialised services that can support intelligence and cyber operations. Dakota Cary, a China analyst with cybersecurity company SentinelOne, said, "Over the last decade, the number of companies offering niche offensive services has exploded."
The US action against QScan and QTRouter marks another effort by American authorities to disrupt cyber networks they say support Chinese intelligence and military interests. The investigation also highlights the long-running nature of the threat. The affidavit shows that the hackers have targeted a wide range of organisations over several years, with some attempts succeeding and others failing. US agencies continue to investigate the scope of the activity and the networks affected by the campaign.

Comments