World

US says Chinese-linked hackers attacked NASA, Senate, and gov’t agencies

Al Jazeera · 2026-08-26

AI SUMMARY

• What happened: The US government disrupted a hacking operation linked to China that targeted sensitive agencies, including NASA and the Senate, dismantling two platforms used for cyberattacks. • Why it matters: This operation highlights ongoing cyber threats from state-sponsored hacking groups, emphasizing the need for enhanced cybersecurity measures to protect critical infrastructure and sensitive information. • What to watch next: Monitor developments in US-China cyber relations and any potential retaliatory measures or further investigations into Chinese hacking activities.

**Title: US Disrupts Chinese-Linked Hacking Operation Targeting Government Agencies**

**Date: August 26, 2026**

The United States government has announced the disruption of a hacking operation linked to China that targeted several sensitive government entities, including the Department of Justice, NASA, the Federal Reserve, and the US Senate. This operation, revealed in a statement from the Justice Department, involved the dismantling of two hacking platforms known as QScan and QTRouter.

According to the Justice Department, these platforms were utilized to infiltrate internet-connected devices and obscure the origins of cyberattacks. The hacking infrastructure had reportedly been in use since at least 2018, compromising critical infrastructure and sensitive networks in the US and beyond.

The announcement highlighted that the hackers had previously attempted to breach NASA’s networks in August 2019 but were unsuccessful. However, they managed to successfully infiltrate networks at three Department of Energy laboratories, the National Institutes of Health (NIH), the Department of Health and Human Services (HHS), and a US security-device manufacturer in September 2024.

In addition to the aforementioned government agencies, the Federal Reserve and four unnamed companies in the US and South Korea were also identified as targets of the hacking campaign.

The Justice Department's investigation revealed that the hacking platforms were operated by a China-based firm, Nanjing Xinjiuwei Network Technology Company. This company reportedly had connections with various Chinese state entities, including the Ministry of State Security and the People’s Liberation Army.

Neither the Chinese embassy in Washington nor Nanjing Xinjiuwei responded to inquiries regarding the allegations.

QScan was specifically designed to locate and infect thousands of internet-connected devices, such as routers and other network equipment. Once compromised, these devices were integrated into a network through QTRouter, enabling the hackers to route their attacks through computers and devices located outside of China. This tactic allowed them to disguise the origin of their attacks, making it appear as though they were emanating from within the target's vicinity rather than from overseas.

Richard Hummel, a vice president at cybersecurity firm SecurityScorecard, explained the implications of this disruption. He noted that when an attack appears to originate from a nearby device, it complicates the attribution process, thereby providing the hackers with additional time to execute their plans. The seizure of these platforms significantly impacts the hackers' operational capabilities, as it removes critical tools they relied on for their activities.

This operation is part of a broader initiative targeting what Attorney General Todd Blanche described as "indiscriminate hacking activities" sponsored by China. The investigation was led by the FBI’s Cyber Division, along with federal prosecutors in California and the San Diego field office.

Chinese-linked hacking campaigns have become increasingly prevalent, with numerous sensitive US government and private networks compromised in recent years. In March, the FBI informed Congress that certain agency networks had been breached, with subsequent reports attributing the compromise to Chinese hackers. Additionally, there have been instances of hacking incidents involving US House of Representatives committee networks and major telecommunications companies.

The recent actions taken by the US government underscore ongoing concerns regarding cyber threats posed by state-sponsored hacking groups and the need for robust cybersecurity measures to protect sensitive information and infrastructure. As the landscape of cyber warfare continues to evolve, the US remains vigilant in its efforts to safeguard its digital assets against foreign adversaries.

Source: Al Jazeera
RELATED NEWS

More Stories

All News
World

Meta agrees to $17B settlement in landmark child-safety case

• What happened: Meta has agreed to a $17.1 billion settlement with multiple U.S. states over allegations that Facebook and Instagram harmed young users and mis...

World

Video: Survivors recount moment flash floods hit Nepal

• What happened: Survivors of devastating flash floods in Nepal are sharing their experiences as rescue efforts continue, with hundreds still missing and many h...

World

UNRWA chief: Israel seeks to eliminate agency and Palestinian refugee issue

• What happened: UNRWA chief Christian Saunders accused Israel of attempting to eliminate the agency and the Palestinian refugee issue, citing the recent seizur...

World

Palestinians demand return of 1,700 bodies held by Israel

• What happened: Hundreds of Palestinians held vigils across the occupied West Bank demanding the return of over 1,700 bodies currently held by Israeli authorit...

World

Nigeria launches hunt for hundreds of kidnapped mosque worshippers

• What happened: Nigeria has launched a large-scale operation to locate and rescue an estimated 600 worshippers kidnapped from a mosque in northern Niger State ...

World

What’s behind the SDF’s deal with Damascus?

• What happened: The Kurdish-led Syrian Democratic Forces (SDF) have officially dissolved and merged with the Syrian army following a deal with the government o...