US Disrupts Chinese-Linked Hacking Operation Targeting NASA, Senate, and Government Agencies


This story, titled "US says Chinese-linked hackers attacked NASA, Senate, and gov’t agencies" First published on Al Jazeera English and was retrieved from its original source on August 26, 2026.
Our site bears no responsibility for its content. You can review the details of this story at its original source.
The United States and China flags are pictured at the Great Hall of the People prior to the state dinner of President Donald Trump and Chinese President Xi Jinping, May 14, 2026, in Beijing [Mark Schiefelbein/AP]. The United States announced it has successfully disrupted a China-affiliated hacking campaign that targeted sensitive US government bodies, including the US Department of Justice, NASA, the Federal Reserve, and the US Senate.
According to an announcement released on Wednesday by the Justice Department, the operation dismantled two distinct hacking platforms, QScan and QTRouter, which were utilized to breach internet-connected devices and conceal the origin of the attacks. Court documents indicate that this malicious infrastructure has been active since at least 2018, compromising critical infrastructure and sensitive networks both within the US and internationally.
Hackers made an unsuccessful attempt to access NASA networks in August 2019, followed by a successful breach in September 2024 affecting networks at three Department of Energy laboratories, the NIH, the HHS, and a US security-device manufacturer. Additional targets identified include the Federal Reserve, the US Senate, and four unnamed corporations located in the US and South Korea.
The Justice Department stated that the platforms were operated by the China-based Nanjing Xinjiuwei Network Technology Company. Its clients allegedly included China's civilian intelligence agency, the Ministry of State Security, and its military branch, the People's Liberation Army. Neither the Chinese embassy in Washington nor Nanjing Xinjiuwei provided a response to requests for comment submitted by the Reuters news agency.
Details from the announcement reveal that QScan was deployed to identify and infect thousands of internet-connected appliances, such as routers and network hardware. These compromised devices were subsequently integrated into a network through QTRouter. This infrastructure enabled the hackers to route their cyberattacks through computers and devices situated outside China, making hostile actions against US targets appear to originate from foreign devices or even locations in close geographic proximity to the intended victims.
While this recent enforcement action does not completely eliminate the group's overall operational capacity, the domain seizures effectively restrict access to the critical platforms. Richard Hummel, vice president at cybersecurity firm SecurityScorecard, noted to Al Jazeera that shifting the apparent origin of an intrusion to a local device rather than an overseas location delays detection and complicates attribution. He added that removing two platforms of that magnitude deprives the operators of significant daily capabilities.
This intervention forms part of a broader sequence of court-authorized actions directed against what Attorney General Todd Blanche characterized as indiscriminate, state-sponsored hacking activities originating from China. The investigation was spearheaded by the FBI’s Cyber Division, federal prosecutors in California, and the San Diego field office.
Over recent years, Chinese-linked hacking campaigns have successfully compromised numerous sensitive US government and private sector networks. In March, the FBI informed the US Congress that hackers had breached specific agency networks connected to individuals under FBI investigation, an incursion later attributed publicly to China. Furthermore, Chinese-linked threat actors have been associated with compromises affecting US House of Representatives committee networks and multiple major telecommunications companies.
Technology
Technology
Technology
Technology