Chinese-linked cyber attack on US government agencies 2026
One page that accretes the verified record as the story develops. Every fact keeps its date and its sources.
US revises statements suggesting Chinese hackers attacked agencies
A Chinese embassy spokesperson said the US uses cybersecurity to smear or discredit China.
An affidavit alleged that in September 2024, the hackers carried out computer intrusions at three DOE National Laboratories, NIH, an HHS agency, and a US security device manufacturer, referring to them as victims.
The revised Justice Department statement named the Senate, the Federal Reserve, NASA and other agencies as among the targets of QTFY, a Chinese state-sponsored hacking group.
“opposes the US overstretching the concept of national security and using it as a pretext to impose discriminatory restrictions on Chinese companies and will firmly safeguard the legitimate rights and interests of Chinese companies”
DOJ alleges Chinese hackers target NASA and key US agencies
The Justice Department alleges that Nanjing Xinjiuwei Network Technology Company offered hacking services to paying customers, including China's Ministry of State Security and People's Liberation Army.
The Justice Department obtained court authorization to seize domains used by QScan and QTRouter.
FBI Director Kash Patel said the tools were used by PRC cyber actors to hide the origin of their attacks.
Chinese state-sponsored hacker group targeted Fed, NASA, and DOJ
QTFY's paying customers include the People's Republic of China's Ministry of State Security and the People's Liberation Army.
The Federal Reserve, the U.S. Senate, the Department of Justice, NASA and other federal agencies were victims of computer intrusions by a Chinese state-sponsored hacking group.
The Energy Department, the Health and Human Services Department and the National Institutes of Health were also victims of computer intrusion by the platforms.
Chinese-linked hackers attack NASA, Senate, and US government agencies
In September 2024, hackers successfully breached networks at three Department of Energy laboratories, NIH, HHS, and a US security-device manufacturer.
The platforms were run by a China-based firm called the Nanjing Xinjiuwei Network Technology Company.
QScan was used to find and infect thousands of internet-connected devices, including routers and other network equipment, which were then incorporated into a network through QTRouter.