**Title: US Disrupts Chinese-Linked Hacking Operation Targeting Government Agencies**
**Date: August 26, 2026**
The United States government has announced the disruption of a hacking operation linked to China that targeted several sensitive government entities, including the Department of Justice, NASA, the Federal Reserve, and the US Senate. This operation, revealed in a statement from the Justice Department, involved the dismantling of two hacking platforms known as QScan and QTRouter.
According to the Justice Department, these platforms were utilized to infiltrate internet-connected devices and obscure the origins of cyberattacks. The hacking infrastructure had reportedly been in use since at least 2018, compromising critical infrastructure and sensitive networks in the US and beyond.
The announcement highlighted that the hackers had previously attempted to breach NASA’s networks in August 2019 but were unsuccessful. However, they managed to successfully infiltrate networks at three Department of Energy laboratories, the National Institutes of Health (NIH), the Department of Health and Human Services (HHS), and a US security-device manufacturer in September 2024.
In addition to the aforementioned government agencies, the Federal Reserve and four unnamed companies in the US and South Korea were also identified as targets of the hacking campaign.
The Justice Department's investigation revealed that the hacking platforms were operated by a China-based firm, Nanjing Xinjiuwei Network Technology Company. This company reportedly had connections with various Chinese state entities, including the Ministry of State Security and the People’s Liberation Army.
Neither the Chinese embassy in Washington nor Nanjing Xinjiuwei responded to inquiries regarding the allegations.
QScan was specifically designed to locate and infect thousands of internet-connected devices, such as routers and other network equipment. Once compromised, these devices were integrated into a network through QTRouter, enabling the hackers to route their attacks through computers and devices located outside of China. This tactic allowed them to disguise the origin of their attacks, making it appear as though they were emanating from within the target's vicinity rather than from overseas.
Richard Hummel, a vice president at cybersecurity firm SecurityScorecard, explained the implications of this disruption. He noted that when an attack appears to originate from a nearby device, it complicates the attribution process, thereby providing the hackers with additional time to execute their plans. The seizure of these platforms significantly impacts the hackers' operational capabilities, as it removes critical tools they relied on for their activities.
This operation is part of a broader initiative targeting what Attorney General Todd Blanche described as "indiscriminate hacking activities" sponsored by China. The investigation was led by the FBI’s Cyber Division, along with federal prosecutors in California and the San Diego field office.
Chinese-linked hacking campaigns have become increasingly prevalent, with numerous sensitive US government and private networks compromised in recent years. In March, the FBI informed Congress that certain agency networks had been breached, with subsequent reports attributing the compromise to Chinese hackers. Additionally, there have been instances of hacking incidents involving US House of Representatives committee networks and major telecommunications companies.
The recent actions taken by the US government underscore ongoing concerns regarding cyber threats posed by state-sponsored hacking groups and the need for robust cybersecurity measures to protect sensitive information and infrastructure. As the landscape of cyber warfare continues to evolve, the US remains vigilant in its efforts to safeguard its digital assets against foreign adversaries.