US Seizes 3 Domains Exposing Chinese Hackers' Breach of NASA, Fed and Senate Networks
Updated
Updated · CNN · Aug 26
US Seizes 3 Domains Exposing Chinese Hackers' Breach of NASA, Fed and Senate Networks
3 articles · Updated · CNN · Aug 26
Summary
Three internet domains tied to Nanjing Xinjiuwei Network Technology were seized Wednesday as U.S. officials moved to disrupt an alleged Chinese espionage campaign hitting NASA, the Federal Reserve, the Justice and Energy departments, and the Senate.
U.S. investigators say Chinese military and intelligence services used the Nanjing firm’s infrastructure to hide inside routine consumer internet traffic, helping intruders reach military networks, hospitals, power companies and defense contractors.
Federal agencies plan to issue a technical advisory so victims can remove the hackers, though the full damage assessment remains unclear and is likely to stay classified for counterintelligence reasons.
The case extends years of U.S.-China cyber tensions after earlier allegations over telecom breaches in 2024 and intrusions into transportation, water and power systems in 2023; Beijing has routinely denied such claims.
Did seizing QTFY's hacking domains truly eliminate the threat, or simply force a dangerous cyber adversary deeper underground?
How did a private foreign tech firm silently infiltrate America's most secure federal agencies and critical hospitals?
With military-grade malware targeting vulnerable health systems, what hidden dangers still lurk inside our critical infrastructure?
The August 2026 QTFY Takedown: How U.S. Authorities Disrupted China’s AI-Driven Cyber-Espionage Network Targeting Federal Infrastructure
Overview
In August 2026, the DOJ and FBI took down the QTFY hacking group by seizing their QScan and QTRouter platforms, cutting off their control over a vast network of compromised devices. QTFY, supported by specialized Chinese contractors, had used automated tools to scan for and exploit vulnerabilities in SOHO routers and IoT devices, making their attacks hard to trace and allowing them to breach sensitive U.S. institutions like NASA and the Senate. This led to major national security risks, as attackers harvested data globally. The incident highlights how decentralized, AI-driven cyber operations and poor device oversight leave critical infrastructure exposed to persistent threats.