US disrupts Chinese hacking targeting federal agencies

Representational image. Photo: REUTERS
US announced on Wednesday that law enforcement has disrupted a massive Chinese hacking operation responsible for infiltrating and targeting several sensitive American government organizations.
The cyber campaign directed intrusions and unauthorized access attempts toward the Justice Department, NASA, the Federal Reserve, the Senate, and other critical federal departments.
To neutralize the threat, the Justice Department seized internet domains linked to two distinct hacking platforms named QScan and QTRouter. Investigators revealed that the actors utilized these platforms to execute their digital offensive.
According to a legal affidavit, the list of victims spans the US Department of Energy, the Department of Health and Human Services (HHS), and the National Institutes of Health (NIH). Additionally, the hackers targeted four unnamed commercial enterprises operating within the US and South Korea.
Chinese embassy hits back
In response to the accusations, a spokesperson for the Chinese Embassy in Washington sent an email saying officials were unfamiliar with the specific details in the DOJ’s announcement. However, the spokesperson emphasized that the “Chinese government firmly opposes and combats all forms of cyberattacks in accordance with the law.”
The spokesperson also criticized the American administration, asserting that the US exploits cybersecurity topics to “smear or discredit China.”
According to the representative, China “opposes the US overstretching the concept of national security and using it as a pretext to impose discriminatory restrictions on Chinese companies and will firmly safeguard the legitimate rights and interests of Chinese companies.”
Intelligence agency and military links
Justice Department identified a China-based enterprise, Nanjing Xinjiuwei Network Technology Company, as the operator of the malicious platforms.
Federal authorities noted that the company serves clients including the Ministry of State Security, which is China’s civilian intelligence agency, and the People’s Liberation Army, the nation’s military. Nanjing Xinjiuwei did not offer any immediate comment when contacted outside of regular business hours.
A timeline of cyber intrusions
The court affidavit detailed that the threat actors utilized custom-built tools to breach critical infrastructure and secure networks globally since at least 2018. However, the hackers did not succeed in every infiltration attempt.
For instance, in August 2019, they tried and failed to access NASA’s networks by exploiting a vulnerability in a virtual private network (VPN).
Later, in September 2024, the hackers successfully executed intrusions at three unnamed laboratories under the Energy Department, an unnamed agency within HHS, the NIH, and a US-based security device manufacturer.
A joint cybersecurity advisory published by the FBI, the NSA, and the Cyber National Mission Force of the US Cyber Command outlined numerous cyber operations over several years. These operations included the successful extraction of sensitive data from unnamed defense contractors, universities, and financial institutions in May 2024.
More recently, in March 2026, the operatives scanned for network vulnerabilities and made unsuccessful bids to compromise the networks of a US hospital and the US Senate.
A representative for NASA said the agency refrains from commenting on specific security incidents. Meanwhile, the Department of Health and Human Services directed all inquiries to the Justice Department, which chose not to respond to requests for additional specifics.
This cyber operation represents one of many Chinese-linked campaigns that have compromised sensitive private and government networks in the United States in recent years.
In March, the FBI notified Congress that hackers had successfully breached certain agency networks holding information on individuals under federal investigation, an incident that public reports later linked to China.
Moreover, investigators have tied Chinese-backed hackers to breaches of certain US House of Representatives committee networks and several major telecommunications corporations.
The rise of offensive contractors
Security analysts who track Chinese cyber warfare activities point out that private contractors frequently perform these high-profile intrusions on behalf of Chinese state agencies. Dakota Cary, a China analyst at the cybersecurity firm SentinelOne, highlighted this industry trend. Cary said, “Over the last decade, the number of companies offering niche offensive services has exploded.”
Source: Reuters (adapted)




