FBI Drops Bombshell On China Hack Crew

FBI seal featuring stars and laurel leaves
FBI DROPS BOMBSHELL ON CHINA

The FBI says a China-backed crew quietly prowled U.S. government networks for years—and the tools they used were hiding in plain sight.

Story Snapshot

  • Justice Department and FBI seized hacking platforms tied to China-backed group QTFY.
  • Court filings and a defense advisory link QTFY to hits on key U.S. targets since 2018.
  • Targets included Justice, NASA, Federal Reserve, Senate, energy labs, and hospitals.
  • China’s embassy denies state ties and rejects the allegations as smears.

What U.S. Authorities Say They Seized, And Why It Matters

The Department of Justice and the Federal Bureau of Investigation said they seized internet platforms that China-backed hackers used to go after U.S. critical infrastructure and government agencies.

The announcement came on August 26, 2026, and framed the action as a cut to the attacker’s backbone. Court papers describe a long campaign that touched agencies most Americans assume are locked down.

Federal filings and reporting indicate the group, called QTFY, blended two services—often labeled QScan and QTRouter—to mask the source of traffic and probe for weak spots. Investigators say the platforms did more than cloak attacks. They scaled them.

The services allegedly let buyers rent cover and speed, like using an automated car wash for hacking. That “platform model” matters because it turns elite tradecraft into a commodity any customer can buy.

Who Got Hit, What Was Tried, And What Landed

Affidavits and agency notices point to attempts and intrusions involving the Department of Justice, the National Aeronautics and Space Administration, the Federal Reserve, and the United States Senate, among others.

Court documents describe successful 2024 compromises at three Department of Energy laboratories, the National Institutes of Health, the Department of Health and Human Services, and a U.S. security device maker.

The filings also say hospitals, power companies, telecom firms, financial institutions, and defense contractors were on the target list. One advisory adds scans of a U.S. state government, a water district, and an election system.

The Department of Defense advisory attributes QTFY to a Nanjing-based private company and says the tools helped hide attackers’ locations while targeting defense, communications, government, and higher education networks.

That lines up with a pattern Americans have seen for a decade: state goals pursued through a mix of official and private fronts.

The overlap muddies the chain of command but not the outcome. The victim still loses time, money, and trust. The grid, the clinic, or the lab still goes dark, or doubts its own data.

What China Says, And How To Weigh It

China’s embassy in Washington rejected the U.S. claims and said China opposes all cyberattacks, urging the United States to stop using cybersecurity to smear China.

A similar embassy statement in Singapore dismissed related allegations as baseless and said China neither endorses nor tolerates hacking.

Those denials are now standard in these cases. They deserve a hearing. They do not erase the affidavits, the seizures, or the technical advisories the U.S. released. On balance, the public record favors the U.S. case here, which names actors, tools, targets, and dates.

If someone keeps showing up at your fence line with bolt cutters and a moving truck, you add lights, dogs, and cameras. You also tell your neighbors what to watch for.

That is what the Justice Department, the Federal Bureau of Investigation, and the Department of Defense did this week: they tightened access, named the crew, and posted the photo at the town hall. This is not saber-rattling; it is basic risk control in a world where code crosses borders in milliseconds.

The Real Lesson For Agencies, States, And Businesses

Agencies and companies should assume that platform-style hacking is the new normal. You are not only defending against a lone genius.

You are defending against a service with support tickets and updates. Patch fast and verify. Turn on multi-factor authentication everywhere.

Lock down remote support tools; these get abused because they often sit near the crown jewels. Build a habit of rehearsing “assume breach” drills, like fire drills for networks. The drill exposes blind spots before an attacker does.

These are not culture-war fights. They are seatbelts and smoke alarms for a digital house. Washington can seize domains and name names. The rest of the work happens block by block, board by board, and budget by budget.

Sources:

nypost.com, cnbc.com, media.defense.gov, berndpulch.org, reuters.com, justice.gov