DOJ, FBI disrupt China-linked hacking network targeting US agencies and infrastructure since 2018
WASHINGTON, DC: The Justice Department and FBI on Wednesday, August 26, said that a China-linked hacking group carried out a years-long campaign targeting US government networks, hospitals, energy facilities and financial institutions.
The federal agencies announced the seizure of websites allegedly used by the group, known as QTFY, to conduct the cyberattacks. According to a federal affidavit and a cybersecurity advisory, the campaign began in 2018 and included attempted breaches of NASA, the US Senate, and multiple federal agencies such as the Department of Energy and the Department of Health and Human Services.
DOJ says hackers built access to US networks over several years
According to the court documents cited in the federal affidavit, QTFY’s operations apparently involved two hacking services known as QScan and QTRouter, which work in conjunction. Investigators allege that the company provided hacking services to Chinese government customers, including the Ministry of State Security and the People’s Liberation Army.
The operation was seemingly designed to first locate vulnerable internet-connected systems and then help hackers hide their activity. QScan was used to scan networks for weaknesses and attempt intrusions, while QTRouter routed the attackers’ activity through compromised devices and other infrastructure, making it harder to determine that the activity originated in China.
🚨Justice Department and @FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure
— U.S. Department of Justice (@TheJusticeDept) August 26, 2026
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security…
The campaign allegedly targeted both government and private-sector networks. Federal investigators have identified hospitals, telecommunications providers, power companies, financial institutions and defense contractors among the targets.
Some attacks were unsuccessful. In 2019, for instance, QTFY allegedly attempted to access NASA servers but failed because the vulnerability it sought to exploit had already been fixed. The group also attempted to identify weaknesses in US election systems in 2019 and then again in June this year, but investigators said those attempts did not result in access.
The @FBI, @NSAGov and @US_CYBERCOM have issued a Joint Cybersecurity Advisory to warn organizations about cyber threat activity by the China-linked hacking group QTFY.
— FBI Cyber Division (@FBICyberDiv) August 26, 2026
Since 2018, QTFY has developed malicious tooling, traded malware and exploits within freelance hacking… pic.twitter.com/vX7zlq5jol
However, the group was apparently able to successfully install malware in Taiwanese energy systems in 2021 and exploited a common vulnerability to gain access to government systems in an unnamed US state and a large US retailer.
China rejects US allegations as cyber tensions persist
The latest allegations add to a series of US accusations involving Chinese-linked cyber operations against government and critical infrastructure networks.
In 2023, US officials and cybersecurity experts claimed that the Chinese hacking group Volt Typhoon had allegedly been attacking organizations on the US mainland and at military bases in Guam since 2021, including communications, transportation and IT companies.
In 2024, another China-linked group, Salt Typhoon, was accused of breaching US telecommunications networks and the mobile devices of several US officials, including then-presidential candidate Donald Trump and his running mate, JD Vance.
Chinese officials have repeatedly denied responsibility for state-backed hacking operations. In response to the latest allegations, a spokesperson for the Chinese Embassy in Washington said Beijing “firmly opposes and combats all forms of cyberattacks in accordance with the law.” The spokesperson added, “We urge the U.S. side to stop using cybersecurity issues to smear or discredit China.”
The allegations come ahead of Chinese President Xi Jinping’s planned visit to Washington in September this year. Trump in May said that he had discussed Chinese-linked cyberattacks with Xi after his recent trip to China, while also acknowledging that the is spying “like hell” on them in response.