FBI seizes China-linked QTFY hacking platforms
The US Justice Department and FBI seized domains behind QScan and QTRouter, two hacking platforms run by a China state-linked group called QTFY. Officials say the group scanned for vulnerable systems and used hijacked routers and cameras to hide its tracks while targeting NASA, the Justice Department, the Federal Reserve, the Senate, power and telecom companies, hospitals, and defense contractors. On August 28 the DOJ corrected its initial announcement, clarifying that most of those named organizations were targets rather than confirmed victims; the confirmed breaches were three Energy Department labs, the NIH, an HHS agency and a security device maker, and a separate attempt against NASA reportedly failed.
- Started
- May 1, 2024
- Latest activity
- Sep 1, 2026
- Attributed to
- QTFY (China state-linked)Confirmed
- Where
- United States
- Sectors
- Government, Energy, Healthcare, Telecom, Defence, Finance +1
- Scale
- More than 300 organizations in the US and abroad. The DOJ's August 28 correction clarified that NASA, the Federal Reserve, the Senate
Current status
As of September 8, no credible source has reported new QTFY activity, new victims, or the return of QScan and QTRouter since the September 1 update.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Who is behind it
FBI San Diego officials additionally named the Nanjing-based company behind the platforms as Nanjing Xinjiuwei Network Technology Co., which they say provided hacking services to Chinese intelligence and military organizations.
Impact
Confirmed data theft and intrusions at three Energy Department national laboratories, the NIH, an HHS agency and a US security device manufacturer in September 2024. NASA, the Federal Reserve, the Senate, the Justice Department and other federal agencies were targeted over a multi-year campaign but the DOJ's own affidavit says only some were actually compromised; the attempted NASA breach reportedly failed because the software involved was already patched. Attempted intrusions into Senate, hospital and election systems in 2026 reportedly failed.
What to do
Organizations in critical infrastructure and defense should watch for advisories from CISA, the FBI and NSA about QTFY indicators of compromise.
Timeline
-
Sep 1, 2026
Recapping the case, FBI San Diego and DOJ officials, including US Attorney General Todd Blanche, reiterated that the seized QScan and QTRouter platforms were run through Nanjing Xinjiuwei Network Technology Co. to provide hacking services to Chinese intelligence and military organizations; no new victims or platform restoration were reported.
Containedtimesofsandiego.com -
Aug 28, 2026
The Justice Department issued a corrected press release acknowledging its August 26 statement wrongly described all named agencies as hacking victims; the underlying court affidavit shows the agencies were targeted but only some, including three DOE national laboratories, the NIH, an HHS agency and a security device manufacturer, were confirmed breached. A footnote in the affidavit says the attempted NASA intrusion failed because the targeted software had already been patched.
Containedyahoo.com -
Aug 27, 2026
The FBI and NSA published a joint cybersecurity advisory with indicators of compromise for QTFY, based on analysis of the group's malicious cyber activity.
Containedhstoday.us -
Aug 27, 2026
Chinese Foreign Ministry spokesperson Lin Jian rejected the US accusation at a press briefing, calling it a disinformation campaign and pointing to China's own earlier allegation of a US NSA cyberattack on its National Time Service Center.
Containedoutlookindia.com -
Aug 26, 2026
The Justice Department and FBI seized three domains that powered the QScan and QTRouter platforms, publicly attributing the operation to QTFY and a Nanjing-based company.
Containedmedia.defense.gov -
Jun 1, 2026
-
Mar 1, 2026
A National Mission Force advisory said QTFY scanned Senate and hospital-system networks in March but failed to gain access.
Activefoxnews.com -
May 1, 2024
QTFY exploited a recently disclosed Check Point vulnerability while scanning US power and telecommunications companies and began stealing data from organizations in the US and abroad.
Activefoxnews.com
Sources
- China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure media.defense.gov Aug 26, 2026 unverified
- China-linked hackers infiltrated US government networks before FBI takedown Fox News Aug 27, 2026
- Fed, NASA, DOJ targeted by Chinese state-sponsored hackers CNBC Aug 26, 2026
- DOJ blames China for string of hacks targeting federal agencies Politico Aug 26, 2026 unverified
- FBI shuts down China-linked hacking tools Cyber Security News Aug 21, 2026
- FBI shuts down China-linked hacking tools SecurityOnline Aug 27, 2026
- Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure justice.gov Aug 26, 2026
- China Rejects US 'State-Sponsored Hacking' Charge, Accuses Washington Of Double Standards Outlook India Aug 27, 2026
- FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure Wired Aug 26, 2026
- NSA, FBI Warn China-Linked QTFY Hackers Are Targeting U.S. Military and Critical Infrastructure Networks Homeland Security Today Aug 28, 2026 unverified
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations The Hacker News Aug 26, 2026
- US officials revise claims that government agencies were hacked by Chinese, now say they were targets Reuters via Yahoo News Aug 28, 2026
- DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims The Hacker News Aug 28, 2026
- Feds in San Diego seize domains to block China from hacking Times of San Diego / The Center Square Sep 1, 2026
- FBI San Diego investigation leads to seizure of Chinese hacking platforms San Diego Union-Tribune Aug 26, 2026
Related reports
- FBI shuts down China-linked hacking tools Aug 21, 2026