Key Points
Justice Department disrupted Chinese hacking platforms QScan and QTRouter on August 26.
NASA, Federal Reserve, and US Senate confirmed among the breached agencies.
Nanjing Xinjiuwei Network Technology Company allegedly operated both hacking platforms since 2018.
Clients reportedly included China's Ministry of State Security and military intelligence.
NASA was among several federal agencies breached by a China-affiliated hacking network, the Justice Department confirmed Wednesday, August 26, 2026. Authorities seized domains tied to two hacking platforms, dubbed QScan and QTRouter, used since at least 2018.
The Federal Reserve, US Senate, Department of Justice, and Department of Energy were also confirmed victims. FBI Director Kash Patel described it as the disruption of “a global botnet and hacking platform.”
Who Ran the Hacking Operation Targeting NASA
A China-Based Firm Behind the Platforms
The Justice Department identified Nanjing Xinjiuwei Network Technology Company as the operator behind both hacking platforms. A state-sponsored group called “QTFY,” employed by this firm, created and ran QScan and QTRouter. Court documents unsealed in the Southern District of California detailed the group’s operations.
Clients Reportedly Included Chinese Intelligence
Investigators said QTFY’s client list included China’s Ministry of State Security, its civilian intelligence agency, and the People’s Liberation Army. QTFY offered computer hacking services to paying customers beyond direct state operators. Reuters could not immediately locate contact details for Nanjing Xinjiuwei for comment.
The Full List of Confirmed Victims
Government Agencies Breached Since 2018
Beyond NASA, the Federal Reserve, and the Senate, hackers also compromised the Department of Health and Human Services and the National Institutes of Health. An affidavit noted hackers first attempted to access NASA networks unsuccessfully back in August 2019. Four unnamed companies in the US and South Korea were also victims.
Critical Infrastructure Also Targeted
CNN reported the campaign also hit US military networks, hospitals, power companies, and defense contractors. This wider scope suggests the hacking infrastructure supported espionage well beyond routine government network intrusions. The full extent of compromised information remains undisclosed by federal officials as of Wednesday.
How the Hacking Platforms Actually Worked
Hiding Attack Origins Through Routing
QScan and QTRouter let hackers route attacks through devices outside China, disguising the true source of intrusions. That routing technique made attacks appear to originate from nearby devices rather than overseas servers, slowing attribution efforts significantly. Richard Hummel of SecurityScorecard said this capability bought operators valuable time.
A Major Setback for China’s Cyber Capabilities
Hummel noted that taking two platforms of this size offline costs the operators real capability they used daily. The disruption doesn’t eliminate the broader hacking group’s activity entirely. Domain seizures interrupt access to these specific tools without dismantling the underlying threat actor completely.
Broader Context of US-China Cyber Tensions
Part of a Sustained Government Effort
Attorney General Pam Bondi’s deputy said federal law enforcement “investigated and disabled the PRC’s malicious software.” This marks the latest in a series of court-authorized operations targeting Chinese state-sponsored hacking infrastructure. Beijing routinely denies responsibility for hacking activity attributed to it by Washington and allied governments.
Technology Sector Implications
Companies like Microsoft, CrowdStrike, and Palo Alto Networks often see increased demand for cybersecurity services following major disclosures like this one. Defense contractors and critical infrastructure operators typically reassess network security following confirmed nation-state intrusions. This disclosure adds to mounting evidence of persistent Chinese cyber-espionage targeting American institutions.
Final word
This disruption marks a real setback for Chinese state-linked hacking infrastructure, though officials admit broader group activity likely continues. The scale of agencies breached, from NASA to the Federal Reserve, underscores persistent vulnerabilities. Continued vigilance across federal networks remains essential going forward.
Disclaimer:
The content shared by Meyka AI PTY LTD is for research and informational purposes only. Meyka is not a financial advisory service, and the information provided should not be treated as investment or trading advice.
What brings you to Meyka?
Pick what interests you most and we will get you started.
I'm here to read news
Find more articles like this one
I'm here to research stocks
Ask Meyka Analyst about any stock
I'm here to track my Portfolio
Get daily updates and alerts (coming March 2026)