WASHINGTON — Chinese state-backed hackers broke into a wide range of US government computer systems, including networks tied to NASA and the US Senate, before federal authorities moved to shut down web domains connected to the alleged cyber operation.
The Justice Department and FBI said Wednesday that they had seized three internet domains associated with QTFY, a Chinese state-sponsored hacking group accused of using the sites “to compromise critical infrastructure and other sensitive networks,” according to an FBI affidavit.
In the affidavit, an FBI special agent said QTFY had successfully penetrated networks since 2018 at NASA, the National Institutes of Health, the Justice Department, the Department of Health and Human Services, three Department of Energy national laboratories, the Federal Reserve and the Senate.
Federal investigators also alleged that the domains tied to the hacking group helped support an international money laundering conspiracy.
Attorney General Todd Blanche told Fox News that the hackers were not limiting their efforts to government targets, saying they were also going after “hospital systems and health care centers.”
The newly unsealed documents indicate the Chinese hackers accessed government systems between 2018 and 2026, though they offer limited information about what the intruders sought or whether the breaches caused measurable damage.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” Blanche said in a statement.
“Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
QTFY sold access to its computer hacking services — known as “QScan” and “QTRouter” — to the Chinese Ministry of State Security and the People’s Liberation Army via a private company called Nanjing Xinjiuwei Network Technology Co.
The services were able to infect thousands of devices across the globe. The affidavit cites in particular a medical center in Ohio, financial groups in Michigan and South Korea and an insurance agency in Missouri.
“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” added FBI Director Kash Patel in a statement.
“These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down,” Patel said.
“Today’s action is just the latest technical operation against PRC-sponsored hacking – and in support of President Trump’s Cyber Strategy for America, the FBI is surging efforts to shape adversary behavior and defend the homeland in cyberspace.”