WASHINGTON — The United States has moved to disrupt what American authorities describe as a long-running China-based cyber-espionage operation that targeted sensitive government systems, critical infrastructure and private organisations, including networks connected to the Justice Department, NASA, the Federal Reserve and the U.S. Senate.
The U.S. Justice Department said Wednesday that it had seized internet domains associated with two hacking platforms identified as QScan and QTRouter, alleging that the systems formed part of an offensive cyber operation conducted by a China-based technology company.
The action provides a rare public look at the infrastructure that U.S. authorities say was used to conduct reconnaissance, identify vulnerable networks and pursue access to government and commercial systems over a period stretching back at least to 2018.
According to a Justice Department affidavit, the operation was not confined to one institution or one sector. Investigators linked the activity to attempted or successful intrusions involving U.S. government agencies, laboratories, financial institutions, universities, defence contractors and companies in the United States and South Korea.
The alleged targets included the U.S. Department of Energy, Department of Health and Human Services, National Institutes of Health, as well as four companies whose names were not disclosed.
The authorities’ description also points to a broader evolution in cyber-espionage: rather than relying exclusively on direct operations by government intelligence officers, sophisticated states can increasingly obtain offensive capabilities from specialist private-sector companies.
That model complicates attribution because the technical infrastructure and personnel conducting an intrusion may belong to a commercial organisation even when the alleged strategic beneficiary is a government agency.
US says China-based company supplied hacking capability
At the centre of the U.S. allegations is Nanjing Xinjiuwei Network Technology Company, a China-based firm that Justice Department investigators say operated QScan and QTRouter.
U.S. authorities allege that the company’s customers included China’s Ministry of State Security, the country’s civilian intelligence service, and the People’s Liberation Army, China’s military.
The allegations suggest that the platforms were not simply conventional cybersecurity products. Investigators say they were used to support operations capable of identifying weaknesses in internet-facing systems and attempting to gain access to networks.
Nanjing Xinjiuwei did not immediately respond to a request for comment outside normal business hours, according to the supplied report.
The Chinese government rejected the broader characterization of the allegations.
A spokesperson for the Chinese Embassy in Washington said officials were not familiar with the specific details contained in the Justice Department’s statement but maintained that Beijing opposes cyberattacks.
“The Chinese government firmly opposes and combats all forms of cyberattacks in accordance with the law,” the spokesperson said.
China also accused Washington of using cybersecurity allegations to portray China negatively and warned against what it described as an excessive expansion of national-security arguments.
The embassy said China opposes the United States using national security as a justification for discriminatory restrictions on Chinese companies and said Beijing would protect the legitimate rights and interests of Chinese businesses.
The competing statements illustrate the increasingly political dimension of cyber attribution. Washington argues that identifying and disrupting foreign cyber operations is necessary for national security, while Beijing has repeatedly rejected U.S. accusations of state-linked hacking and challenged what it views as the politicisation of cybersecurity.
The campaign stretches back years
The Justice Department affidavit indicates that the alleged activity was not a recent development.
Investigators say the hackers had been using their tools against critical infrastructure and other sensitive networks in the United States and elsewhere since at least 2018.
The length of the alleged campaign is important because it suggests that the operation was designed around persistent access and intelligence collection rather than a single disruptive cyberattack.
Cyber-espionage campaigns can remain active for years because attackers do not necessarily need to bring down the systems they enter. Their objective may instead be to quietly obtain information, map networks, identify valuable individuals or organisations, establish future access points or collect intelligence over an extended period.
The affidavit also makes clear that an attempted intrusion did not necessarily result in a successful compromise.
One example cited by investigators occurred in August 2019, when the hackers allegedly attempted to exploit a vulnerability in a virtual private network in an effort to gain access to NASA networks.
The attempt was unsuccessful.
That distinction matters because lists of organisations targeted by a cyber operation can otherwise create the impression that every named institution was successfully breached. In this case, U.S. authorities’ own account distinguishes between reconnaissance, attempted intrusions and confirmed compromises.
More recent attacks targeted US government networks
The alleged campaign continued into 2024 and 2026, according to the affidavit and a joint cybersecurity advisory issued by U.S. authorities.
In September 2024, investigators said the hackers carried out intrusions involving three unnamed Department of Energy laboratories, the National Institutes of Health, an unnamed agency within the Department of Health and Human Services and a U.S. manufacturer of security devices.
The operation also allegedly reached beyond government networks.
A joint advisory from the FBI, National Security Agency and U.S. Cyber Command’s Cyber National Mission Force described multiple activities attributed to the same broader campaign.
Among the incidents were successful thefts of data from unnamed defence contractors, financial institutions and universities in May 2024.
These targets are strategically significant.
Defence contractors can hold information related to military programmes and supply chains. Financial institutions contain commercially and economically sensitive information, while universities can possess valuable research and technical expertise.
The alleged targeting therefore appears to span multiple categories of information rather than focusing exclusively on government secrets.
Senate and hospital networks also probed
The alleged activity did not stop with the confirmed compromises described by U.S. investigators.
In March 2026, the hackers allegedly scanned for vulnerabilities and made unsuccessful attempts to access networks associated with the U.S. Senate and a U.S. hospital.
Again, the distinction between scanning, attempted access and confirmed compromise is critical.
Cyber attackers routinely scan the internet for vulnerable systems before deciding whether to pursue an intrusion. Such reconnaissance can generate enormous amounts of information about potential targets without necessarily resulting in a breach.
The Justice Department’s allegations therefore point to an operation that combined reconnaissance with targeted exploitation when opportunities arose.
That approach is consistent with a broader trend in state-linked cyber operations, in which attackers continuously search for weaknesses across large numbers of systems while concentrating resources on targets considered strategically valuable.
Federal Reserve and other sensitive institutions named
The U.S. government’s characterization of the campaign also places the Federal Reserve among the sensitive institutions affected by the operation described in the case.
The Federal Reserve occupies an especially sensitive position because of its role in the U.S. financial system and monetary policy.
A cyber intrusion involving financial infrastructure could potentially expose information with economic or strategic value even if it did not result in direct disruption of financial services.
The same principle applies to agencies such as NASA and the Justice Department. Their networks contain very different categories of information, but each can be strategically valuable to a foreign intelligence service.
NASA holds extensive scientific and technological information. The Justice Department possesses law-enforcement and investigative information, including data that can relate to national-security matters.
The targeting of institutions across such different sectors suggests that the alleged operation was broad enough to support multiple intelligence objectives.
NASA said it does not comment on specific incidents. The Department of Health and Human Services referred questions about the allegations to the Justice Department, while the Justice Department did not provide additional details in response to the requests described in the supplied report.
A growing role for private cyber contractors
One of the more consequential aspects of the case is the alleged relationship between Chinese government agencies and private companies capable of conducting sophisticated cyber operations.
Dakota Cary, a China analyst with cybersecurity company SentinelOne, said the number of Chinese companies offering specialised offensive cyber services has grown significantly during the past decade.
“Over the last decade, the number of companies offering niche offensive services has exploded,” Cary said.
That development matters because the modern cyber-espionage ecosystem is no longer necessarily divided into simple categories of government hackers versus independent criminals.
Governments can develop capabilities internally, contract private specialists, purchase commercial tools or combine all three approaches.
For intelligence agencies, outsourcing portions of an operation can provide access to specialist technical expertise without requiring every capability to be developed within the government itself.
For investigators, however, the arrangement can make attribution more difficult.
A private company may own the infrastructure, develop the software and employ the technical personnel, while a government organisation allegedly directs, funds or benefits from the activity.
China rejects the US characterization
Beijing’s response is likely to become an important part of the diplomatic fallout surrounding the case.
The Chinese Embassy did not accept the U.S. framing of the allegations and said Washington has used cybersecurity issues to “smear or discredit China.”
The embassy also objected to U.S. restrictions against Chinese companies that Washington considers security risks.
The dispute reflects a longstanding pattern in relations between Washington and Beijing. Both governments have accused the other of cyber activity, while disagreements over technology, telecommunications, artificial intelligence, semiconductor supply chains and national security have increasingly become intertwined.
For the United States, the seizure of domains represents an effort to disrupt the technical infrastructure supporting the alleged operation rather than simply issue a public accusation.
Taking control of or disabling domains can make it harder for operators to communicate with compromised systems or maintain parts of their infrastructure. However, such actions do not necessarily eliminate the people, capabilities or organisations behind a campaign.
The bigger cybersecurity picture
The case also arrives amid a broader series of U.S. concerns about China-linked cyber activity.
According to the supplied report, the FBI notified Congress in March that hackers had penetrated certain government networks involving people under FBI investigation, with subsequent public reporting attributing the compromise to China.
Chinese-linked actors have also been associated with the compromise of networks belonging to certain U.S. House of Representatives committees and with attacks affecting major telecommunications companies.
Taken together, these incidents illustrate why U.S. officials increasingly describe Chinese cyber activity as a national-security issue rather than a collection of isolated computer crimes.
Telecommunications networks can provide access to communications data. Government systems can expose investigative or administrative information. Defence networks can contain military-related intelligence, while universities and research organisations can hold commercially valuable scientific knowledge.
The potential value of cyber access therefore extends across virtually every major part of the economy and government.
Why the latest US action matters
The significance of the Justice Department operation extends beyond the seizure of two domains.
First, the case demonstrates that U.S. investigators are increasingly attempting to expose the commercial infrastructure they believe supports state-linked cyber operations.
Second, the alleged timeline—from 2018 through incidents reported as recently as 2026—illustrates the persistence of modern cyber-espionage campaigns.
Third, the case highlights the difficulty of protecting government networks when attackers can continuously scan for vulnerabilities and shift between targets.
Most importantly, the allegations demonstrate that cybersecurity threats increasingly operate across national boundaries and sectors. A campaign aimed at government intelligence may simultaneously probe laboratories, banks, universities, hospitals and private technology companies.
For Washington, disrupting the infrastructure behind such campaigns is therefore only one element of a much larger strategy. Network defenders must also close vulnerabilities, strengthen authentication, monitor unusual activity and improve intelligence-sharing between government and private-sector organisations.
The latest U.S. action does not establish that every organisation named in the investigation was successfully compromised. The Justice Department’s own account distinguishes between successful intrusions, attempted attacks and unsuccessful scanning or exploitation efforts.
What it does establish is that U.S. authorities regard the infrastructure operated by Nanjing Xinjiuwei and the alleged activity associated with QScan and QTRouter as sufficiently serious to warrant a federal disruption operation.
The episode adds another chapter to the increasingly contested cyber relationship between Washington and Beijing—and underscores a central reality of modern national security: the most consequential battles over sensitive information can take place silently, through networks, long before the public becomes aware that an attack was attempted.
US Accuses China-Linked Hackers of Targeting Justice Department, NASA, Federal Reserve and Senate



