Federal officials on Wednesday announced they had disrupted a yearslong Chinese hacking campaign that compromised or targeted several U.S. institutions, including NASA, the Federal Reserve, and even the Senate.
The Justice Department said in a statement it had seized internet domains used by two hacking platforms, called “QScan” and “QTRouter,” that were created and operated by a Chinese state-sponsored group. The platforms were used to target U.S. critical infrastructure and other sensitive networks. FBI Director Kash Patelsaid tools were used by Chinese government actors “to hide the origin of their attacks.”
An attached affidavit from an FBI agent accused the state-sponsored group, referred to as “QTFY,” of targeting the Department of Energy, Department of Justice, Department of Health and Human Services, and the National Institutes of Health. The group also allegedly targeted networks “operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.”
The DOJ’s announcement did not specify if anybody had been charged or apprehended in relation to the hacking, and the extent of what has been compromised remains unclear. TIME has reached out to the DOJ for comment.
The group’s hacking activity, which dates back to 2018 according to the FBI, adds to an ongoing record of U.S. allegations of Chinese state-backed cyberespionage operations.
A spokesperson for the Chinese Embassy in Washington, D.C. pushed back against the accusations in a statement to TIME, insisting that China is a “firm defender” of cybersecurity.
“China firmly opposes the U.S. overstretching the concept of national security and using it as a pretext to impose discriminatory restrictions on Chinese companies and will firmly safeguard the legitimate rights and interests of Chinese companies,” the spokesperson said, urging the U.S. to stop using such issues to “smear or discredit” the country.
A yearslong hacking campaign
QTFY members, according to the DOJ affidavit, include former members of the People’s Liberation Army—China’s military forces—who used their PLA relationships “to obtain contracts and subcontracts supporting offensive cyber operations.” The QTFY actors were allegedly employed by the Nanjing Xinjiuwei Network Technology Company, which “conducts malicious cyber activities” for the Chinese government, per the FBI.
The affidavit stated that not all of the attempted intrusions had been successful.
In August 2019, the group failed in attempting to break into NASA’s server by exploiting a vulnerability in its virtual private network.
In September 2024, QTFY actors conducted computer intrusions at three unnamed laboratories of the Department of Energy, the NIH, an HHS agency, and another unnamed U.S. security device manufacturer.
Other efforts by the hacking group were detailed in a joint cybersecurity advisory authored by the FBI, the National Security Agency, and the U.S. Cyber Command’s Cyber National Mission Force.
According to the advisory, the group conducted a vulnerability scan of the U.S. Senate and an American hospital system in March 2026, and of an unidentified U.S. election system in June 2026. Both attempts to gain access to these networks failed.
Speaking to Fox News, Attorney General Todd Blanche said Wednesday that the operation has been happening for many years and is a “major national security issue” for the U.S., adding that the authorities have not only stopped the operation, but have also shared the information with the private sector to stop further attempts.
The 2026 Annual Threat Assessment from the Office of the Director of National Intelligence says China “is the most active and persistent cyber threat to U.S. Government, private-sector, and critical infrastructure networks.”
In 2023, the U.S. identified and disrupted operations by Chinese state-sponsored group Volt Typhoon to intrude into U.S. energy, transportation and water networks, to potentially sabotage operations during geopolitical crises. The following year, Chinese government-linked hackers were said to have targeted the phone communications of President Donald Trump and Vice President J.D. Vance, who were then running for office, as part of a larger cyber-espionage campaign.
The Justice Department’s latest announcement comes a month before Trump’s counterpart Xi Jinping is expected to head to the U.S. amid continuing disputes in trade and technology.
As to whether Trump should bring up the alleged hacking from China when Xi visits, Blanche said he would not tell the President what to discuss.
“This is something that we have talked about with our counterparts in China for many, many years. And we know that it’s happening. And they know that we know that it’s happening. And it has to stop,” he added.
