ShowBiz & Sports Lifestyle

Hot

US says Chinese hackers broke into DOJ, NASA, Federal Reserve, Senate

US says Chinese hackers broke into DOJ, NASA, Federal Reserve, Senate

Josh Meyer, USA TODAYWed, August 26, 2026 at 3:16 PM UTC

177

WASHINGTON − U.S. officials said Aug. 26 that it ‌has disrupted a Chinese hacking operation that it believes is responsible for cyber break-ins at the departments of Justice and Energy as well as NASA, the ⁠Federal Reserve, the Senate and other sensitive U.S. government agencies.

In a statement, the Justice Department announced that it has seized internet domains used by two hacking ‌platforms, ⁠dubbed “QScan” and “QTRouter,” which it said were used in the penetration campaign by the Beijing government.

As described in court documents unsealed in the Southern District of California, hackers from a People’s Republic of China state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company, allegedly "created and operated" the two hacking platforms and used them to burrow into U.S. target networks and then cover their tracks.

Among the victims of QTFY's computer intrusion activity, the Justice Department documents alleged, are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health and the U.S. Senate.

In a statement to USA TODAY, the Chinese embassy in Washington said Beijing "firmly opposes and combats all forms of cyberattacks in accordance with the law. We urge the US side to stop using cybersecurity issues to smear or discredit China."

The embassy also said China "will firmly safeguard the legitimate rights and interests of Chinese companies" in response to any U.S. efforts to impose punitive restrictions on them based on accusations of hacking.

“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” Attorney General Todd Blanche said in a statement.

Blanche said federal law enforcement "investigated and disabled the PRC’s malicious software," in the latest in a series of technical operations to dismantle "indiscriminate hacking activities sponsored by the People’s Republic of China.”

FBI Director Kash Patel said the bureau played a key role in the disruption of "a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure."

In support of President Donald Trump’s Cyber Strategy for America, Patel said, "the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”

U.S. officials did not comment on the potential damage done by the cyber-spying effort and how long it was going on before being disrupted. Such damage assessments are traditionally deemed classified and not shared publicly due to security concerns.

According to court documents, QTFY offers computer hacking services to its paying customers, including China's Ministry of State Security and People’s Liberation Army, which has one of the world's most formidable hacking capabilities.

Michael Lebowitz, a former senior attorney in DOJ's National Security Division, told USA TODAY the decision to publicize the alleged Chinese hacking scheme "looks to me like a 'name-and-shame' campaign where the U.S. essentially publicly calls out foreign hackers to let them know that we're on to them."

"The U.S. often takes similar tactics when indicting foreign hackers" because it's unlikely those hackers would ever be brought to trial in the U.S., said Lebowitz, who is also a former senior legal adviser to U.S. Army Cyber Command.

QTFY's computer hacking services work together, with QScan scanning and automatically infecting thousands of “internet-of-things” (IoT) devices worldwide, the court documents allege. Those devices are then added to the QTRouter network of QTFY-controlled devices, with QTRouter also serving as an “obfuscation network” to conceal the Chinese government-linked origin of their computer intrusion activities.

Advertisement

The court-authorized seizures announced Aug. 26 made QScan and QTRouter inoperable, according to the court documents.

'Pervasive' and 'very sophisticated' hacking operations by China

“China's hacking activities are so pervasive, and they're able to operate at a scale that very few other countries around the world can match. And they're very sophisticated,” said Mieke Eoyang, a former deputy assistant secretary of Defense for Cyber Policy and now a visiting professor at Carnegie Mellon University in Pittsburgh. “But the U.S. is also very sophisticated, and we've seen over the past five to 10 years a real increase in focus by the Department of Justice and FBI on being able to go after these types of cyberattacks.”

Such Chinese attacks − and U.S. disruptions − have become a virtually routine cat-and-mouse game as Beijing has successfully penetrated U.S. critical infrastructure over the past decade, including financial institutions and power plants.

The U.S. Cybersecurity and Infrastructure Security Agency, or CISA, part of the Department of Homeland Security, has designated 16 critical infrastructure sectors whose assets, systems and networks − whether physical or virtual − are considered so vital that their incapacitation or destruction would have a debilitating effect on U.S. physical and economic security, including national public health and safety.

Microsoft warned in May 2023 that it had uncovered “stealthy and targeted malicious activity” by a state-sponsored hacking group known as Volt Typhoon that was targeting U.S. critical infrastructure organizations.

That Volt Typhoon campaign, one of many sustained Chinese hacking efforts, focused on espionage and information gathering, Microsoft said, and was “pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and the Asia region during future crises.”

Using cybercriminals to help camouflage China's malicious internet activity

The new DOJ announcement is significant because it acknowledges China’s use of cybercriminals to help camouflage its malicious activity on the internet, even as the Trump administration is enlisting the private sector to combat such activity, said Eoyang, who until January 2025 was the Pentagon’s top civilian overseeing U.S. military offensive cyber operations.

“We've long known that China has this ecosystem that's not just the government but involves the commercial side, too, of people selling services to their state security apparatus,” Eoyang told USA TODAY. “What's interesting is that the Trump administration recently is taking steps to move in that direction by authorizing private U.S. companies to engage in this type of behavior.”

President Donald Trump signed a national security memorandum on Aug. 12 titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime” that authorizes vetted private U.S. companies to conduct offensive cyber operations against foreign criminal groups under federal supervision.

“I think the jury's still out on whether or not this is a good thing” for the U.S. to do in response to pervasive hacking efforts by China, Russia, Iran and other government and nonstate entities, Eoyang said.

“It certainly makes it harder to call out China for this particular type of bad behavior when the U.S. authorizes it itself,” she said. “But it's also an admission that the volume of this type of activity happening on the internet is bigger than government's ability to get after it itself.”

Lebowitz said the Chinese government has been increasingly effective in sneaking malware and nefarious cyber tools into U.S. systems, especially since it has begun using "niche hacking services that add an extra layer of secrecy and obfuscation that makes detecting those threats so much harder."

"It's now a cat and mouse game to detect these threats before they can cause significant damage," he said.

And while Washington is using a whole-of-government approach to detecting Beijing's hacks, including forensic, intelligence and legal tools, the latest disruption, Lebowitz said, "is likely just the tip of the iceberg in terms of existing threats."

This article originally appeared on USA TODAY: US says Chinese hackers broke into DOJ, NASA, Federal Reserve, Senate

Original Article on Source

Source: “AOL Breaking”

We do not use cookies and do not collect personal data. Just news.