US seizes China state-sponsored hacking platforms (August 26, 2026) — NASA and the Fed were on the victim list
The US Justice Department and FBI said on August 26, 2026 that they had seized, under court authorization, the domains behind two complementary hacking platforms called QScan and QTRouter. The platforms were built and run by a China-based company, Nanjing Xinjiuwei Network Technology, through a state-sponsored group known as QTFY, which sold hacking services to customers including operators working for China's Ministry of State Security. Victims include NASA, the Federal Reserve, and the Departments of Energy, Justice and Health and Human Services. Intrusion activity dates to 2018, and the Senate was targeted as recently as 2026
The three lines
- Action — Justice Department and FBI seized the domains behind QScan and QTRouter under court order
- Actor — QTFY, inside China-based Nanjing Xinjiuwei Network Technology, with Ministry of State Security hackers as customers
- Victims — NASA, the Federal Reserve, Energy, Justice, HHS, NIH. The Senate was scanned but not breached
Key questions
- What exactly did the US seize?
- **Domains, not servers or hardware.** The Justice Department and FBI obtained court authorization to seize the domains used by two complementary hacking platforms, **QScan** and **QTRouter**. The Department said the seizures rendered the botnet and its command and control servers **inoperable**, and gave a specific reason: **those domains were hardcoded into the botnet's code**. Infected machines were built to contact that fixed address for instructions, so removing control of the address leaves them with nowhere to check in. This matters because seizing physical servers located in China is not available to a US court — but **taking the address severs the connection** regardless of where the hardware sits.
- Who ran it, and why is a private company named?
- **Because the state did not operate it directly — a commercial vendor did.** According to the Justice Department, the two platforms were created and operated by **Nanjing Xinjiuwei Network Technology**, a China-based company, through a group known as **QTFY**. QTFY **sold hacking services to customers**, and those customers included **hackers working for China's Ministry of State Security**. The structure inserts a commercial layer between the state and the intrusion. That has two effects: it complicates direct attribution to the government, and it **scales the operation**, because the same tooling can be resold to multiple customers. This publication covered the market for vulnerabilities in "What a zero-day is."
- Were these agencies actually breached, or just targeted?
- **It differs by agency, and the distinction matters.** The victim list in the court documents includes **NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services and the National Institutes of Health**; one outlet also reported hospitals among the targets. Intrusion activity dates back to **2018**. For the **Senate**, however, an NSA advisory stated the hackers **scanned the networks but were unsuccessful in gaining access**. So the Senate was a target, not a confirmed breach. Headlines frequently group it with the others, but **targeted and compromised are different claims**. What data was taken from which agency, and in what volume, does not appear in the public materials.
The US Justice Department and FBI announced on August 26, 2026 that they had seized the domains behind two China-linked hacking platforms.
The platforms: QScan and QTRouter.
On the victim list: NASA and the Federal Reserve.
1. A company, not a ministry
| Element | Name |
|---|---|
| Company | Nanjing Xinjiuwei Network Technology (China-based) |
| Group | QTFY |
| Customers | Hackers working for the Ministry of State Security, among others |
| Platforms | QScan · QTRouter |
The structure has an extra layer. The state did not run the intrusion directly — a commercial vendor built and operated the tooling and sold access.
That arrangement does two things. It complicates direct attribution to the government. And it scales the operation, because the same platform can be resold to multiple customers rather than built once for one client.
The Justice Department said QTFY offered hacking services to its customers, and that those customers included Ministry of State Security operators.
2. The victims
| Agency | Domain |
|---|---|
| NASA | Space |
| Federal Reserve | Central banking |
| Department of Energy | Energy, nuclear |
| Department of Justice | Law enforcement |
| HHS · National Institutes of Health | Health, research |
| Senate | Legislature |
Intrusion activity dates back to 2018. The Senate was targeted as recently as 2026.
One distinction has to be preserved here. The Senate was targeted but not breached. An NSA advisory stated the hackers scanned the networks but were unsuccessful in gaining access.
Headlines routinely group the Senate with the confirmed victims. Targeted and compromised are different claims.
3. Why taking a domain stops a botnet
The seizure covered domains, not machines. A US court cannot seize hardware sitting in China.
Yet the Justice Department said the action rendered the botnet and its command and control servers inoperable. The reason:
| Step | What happens |
|---|---|
| 1 | An infected device must contact something to receive instructions |
| 2 | That address was hardcoded into the botnet's code |
| 3 | Investigators took control of the domain |
| 4 | The devices had nowhere to check in |
The infections themselves remain in place. But a device that cannot receive orders does nothing.
Cut the address, cut the connection — regardless of where the servers physically sit. Why botnets borrow other people's devices in the first place, and why routers are the preferred host, is covered in "What a botnet is."
4. What the tooling was for
The Justice Department described QScan and QTRouter as two complementary platforms, and characterized the botnet's purpose as an obfuscation network.
Obfuscation networks hide an attacker's traffic to frustrate detection. If an operation originates in one country but arrives through thousands of compromised devices in third countries, the defender's logs record only those third-party addresses.
In other words, the primary purpose of this tooling was closer to hiding than to stealing.
5. Where this sits
US-China technology confrontation ran through August in several forms. This publication covered pressure to pick sides in "The Pax Silica letters — the US tells 35 countries to choose one AI bloc," and export controls in "What AI chip export controls are."
This episode is a different layer of the same contest. It played out in network infrastructure rather than in chips or alliances, and the instrument the US reached for was neither sanctions nor tariffs but a court order.
6. What we could not confirm
- Domain count — access to the Justice Department release was blocked; the number seized is unknown to us.
- Device count — described only as thousands.
- Platform roles — the technical split between QScan and QTRouter was not confirmed. The names suggest scanning and router relay; we do not assert it.
- Exfiltration — what was taken from each agency does not appear in public materials.
- Hospitals — reported by one outlet, not confirmed against the release.
- Chinese response — no official statement located.
Sources
- US Department of Justice — Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure
- TechCrunch — US seizes domains of Chinese botnet used to target NASA, Justice Department, and the Senate
- CNBC — Fed, NASA and DOJ among victims of Chinese state-sponsored hacker group: Court documents
- CNN — US says Chinese hackers hit hospitals, NASA, Senate and more
- CNY Central — DOJ says China-linked hackers breached NASA, Federal Reserve and Senate networks