US Accuses Chinese Hackers Of Breaking Into NASA, Senate And Federal Reserve

Date:

The United States has moved to disrupt what it described as a China-linked hacking operation that targeted sensitive government agencies and private organisations, including the Justice Department, NASA, the Federal Reserve and the US Senate.

The US Department of Justice said on Wednesday that it had seized internet domains associated with two hacking platforms known as QScan and QTRouter. Investigators said the platforms were used to support a wider cyber campaign aimed at compromising networks in the US and other countries.

According to a Justice Department affidavit, victims also included the Department of Energy, the Department of Health and Human Services, the National Institutes of Health and four unidentified companies based in the US and South Korea. The hacking campaign reportedly involved both successful intrusions and unsuccessful attempts to penetrate targeted systems.

US authorities said the platforms were operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm whose reported customers included the Ministry of State Security, China’s civilian intelligence agency, and the People’s Liberation Army.

The company did not immediately respond to a request for comment. The Chinese Embassy in Washington, meanwhile, rejected the broader accusations, saying Beijing firmly opposes all forms of cyberattacks and deals with such activity according to the law.

A Chinese embassy spokesperson also accused Washington of using cybersecurity concerns to smear China and said the US was overstretching the concept of national security to justify discriminatory restrictions against Chinese companies.

US investigators said the hacking operation had been active since at least 2018, using tools developed by the attackers to search for weaknesses and gain access to critical infrastructure and other sensitive networks around the world.

Not every attempt was successful. According to the affidavit, hackers attempted to exploit a vulnerability in a virtual private network to access NASA networks in August 2019, but the effort failed.

The campaign continued in subsequent years, with investigators alleging that the hackers successfully infiltrated three unnamed Department of Energy laboratories, the NIH, an HHS agency and a US security-device manufacturer in September 2024.

A joint cybersecurity advisory issued by the FBI, National Security Agency and US Cyber Command’s Cyber National Mission Force detailed further activity. It said the hackers successfully stole data from unnamed defence contractors, financial institutions and universities in May 2024.

More recently, the attackers reportedly scanned networks for weaknesses and attempted to penetrate systems belonging to the US Senate and a hospital in March 2026. Those efforts were also unsuccessful, according to the affidavit.

The latest action highlights the growing concerns in Washington over cyber operations allegedly linked to Chinese interests. US authorities have repeatedly warned that Chinese-linked groups have targeted government networks, telecommunications companies, defence organisations and other sensitive sectors.

In March, the FBI informed Congress that suspicious cyber activity had affected certain agency networks connected to individuals under investigation. Public reports later attributed that intrusion to China-linked hackers.

Chinese-linked groups have also previously been accused of compromising networks belonging to committees in the US House of Representatives and major telecommunications companies.

Cybersecurity specialists say the operations often involve private companies working on behalf of Chinese government agencies, making it difficult to separate state activity from commercial hacking operations.

Dakota Cary, a China analyst with cybersecurity firm SentinelOne, said the number of companies providing specialised offensive cyber services in China had increased sharply over the past decade.

The US seizure of the QScan and QTRouter domains represents a further attempt by Washington to disrupt the infrastructure allegedly supporting these operations. It also comes as tensions between the US and China continue to extend into cyberspace, where both countries accuse the other of activities threatening national security and sensitive infrastructure.

Share post:

Popular

More like this
Related

BNM Fines Fintech Firm, Two Banks RM901,500 Over Sanctions Breaches

Bank Negara Malaysia (BNM) has imposed administrative monetary penalties...

Teen, 16, Dies After Suspected Choking During Sex

A 16-year-old girl has died in Sydney after reportedly...

PM Anwar Extends Condolences To Pahang Royal Family Following Death Of Tengku Puteri Seri Kemala

Prime Minister Datuk Seri Anwar Ibrahim has conveyed his...

Viral Indonesian Teacher Payslip Shows Just RM111 Salary, Sparks Online Debate

A salary slip allegedly belonging to an Indonesian teacher...