№238|04:41 PM ET
Independent reporting on technology, markets & policy
TechEchelon
№01 / Anchor·CYBERSECURITY

DOJ Disrupts Chinese State-Linked Hacking Operation Targeting NASA, Federal Reserve, and U.S. Senate

The Justice Department seized two hacking platforms tied to Chinese state-linked firm Nanjing Xinjiuwei Network Technology Co., disrupting an operation that targeted U.S. agencies including NASA, the Federal Reserve, and the Senate.

TE
TechEchelon Staff
AUG 26, 2026 · 03:02 PM ET · 2 MIN READ
via Wikipedia (United States Department of Justice)

The Department of Justice announced Wednesday that it disrupted a Chinese hacking operation that had targeted its own network along with several other sensitive U.S. government agencies, including NASA, the Federal Reserve, and the U.S. Senate.

The DOJ said in a statement that it seized two hacking platforms, identified as "QScan" and "QTRouter," that were operated by a state-run group employed by the Chinese-based firm Nanjing Xinjiuwei Network Technology Co.

The operation represents a significant escalation in the documented targeting of American institutional infrastructure by actors tied to the Chinese government, underscoring longstanding concerns among U.S. officials about foreign cyber intrusions into the most sensitive corners of federal government.

The announcement came as part of a broader effort by U.S. law enforcement to name, disrupt, and attribute hacking campaigns linked to Chinese state interests — a pattern of enforcement actions that has grown more frequent in recent years as tensions between Washington and Beijing over technology and national security have deepened.

The inclusion of the Federal Reserve among the targeted institutions signals that the operation extended beyond traditional intelligence or defense targets, reaching into financial infrastructure that U.S. authorities have long sought to protect from foreign access.

Targeting the U.S. Senate, meanwhile, raises questions about the potential exposure of legislative communications, personnel data, and ongoing policy deliberations to foreign collection efforts.

Officials did not immediately detail the full scope of what data, if any, was accessed during the operation, or how long the hacking platforms had been active before the seizures were carried out.

The disruption of QScan and QTRouter removes active infrastructure that investigators had linked to the campaign, though cybersecurity analysts note that state-linked groups frequently rebuild or retool after platform takedowns.

Wednesday's action adds to a growing list of publicized DOJ interventions against Chinese cyber actors, reflecting a sustained posture from U.S. prosecutors who have used indictments, sanctions, and infrastructure seizures in tandem to raise the cost of state-sponsored intrusions. How China's government responds — and whether the named firm or its personnel face any consequences within China — will be closely watched by officials and security researchers alike.

TE
━ ABOUT THE BYLINE
TechEchelon Staff

TechEchelon Staff bylines are produced collectively by the newsroom for short, breaking, and wire-style coverage. Longer-form reporting is published under the responsible reporter's name.

More from the Staff
● THE BRIEF · DAILY NEWSLETTER

Five stories every morning. Before the opening bell.

Written for readers who already know the basics — markets, AI, and the policy decisions that shape both.

Mon — Fri · 06:30 ET · Free

No spam · Unsubscribe anytime