THE QUICK TAKE
  • According to DOJ filings, the Nanjing-based Xinjiuwei Network Technology Company ran two hacking platforms — QScan and QTRouter — on behalf of China's spy and military agencies.
  • Court documents confirm that zero-day exploits against Ivanti software let QTFY actors successfully breach three DOE National Laboratories and the NIH in September 2024.
  • A joint FBI, NSA, and US Cyber Command advisory says Senate and hospital vulnerability probes in March 2026 failed to produce actual access, despite what some headlines implied.

What the Gossip Mill Is Churning Out

Well, slap the mud off your boots and pull up a chair, because the digital barnyard just caught fire. On August 26, 2026, the Justice Department and the FBI announced they had lassoed the internet domains belonging to two hacking platforms — QScan and QTRouter — according to DOJ filings. The government says those platforms were the property of a Nanjing-based outfit called Xinjiuwei Network Technology Company, which allegedly ran a group known as QTFY. According to court documents, that group was not some bored teenagers in a basement; it was, the DOJ alleges, a for-hire cyber posse doing dirty work for the Chinese Ministry of State Security and the People's Liberation Army.

The alleged target list reads like somebody threw a dart at a Washington, D.C., visitor's guide and then kept throwing: NASA, the Federal Reserve, the Departments of Justice, Energy, and Health and Human Services, the National Institutes of Health, and the US Senate, according to DOJ filings and reporting by Al Jazeera, Time, CNN, and Cyber Magazine. Now, 'targeted' does not automatically mean 'ransacked,' and we will get to that distinction in a moment, because it matters more than knowing which end of the mule to feed.

What the Court Papers Actually Nail Down

Here is where the facts get as solid as a cast-iron skillet. According to unsealed court documents, QTFY actors exploited zero-day weaknesses in Ivanti Cloud Services Appliance software back in September 2024 and successfully worked their way into three Department of Energy National Laboratories, the National Institutes of Health, and an agency within Health and Human Services. Those are confirmed breaches, not rumors — the court filings say so, and multiple top-tier outlets including Time and Cyber Magazine corroborate the account.

The DOJ also alleges, in those same filings, that QTFY ran a two-tool hustle slicker than a coon in a henhouse: QScan would sweep the internet and quietly recruit thousands of unsuspecting devices into a shadow army, according to Al Jazeera and The National Desk. QTRouter then funneled the attack traffic through those hijacked machines so that any intrusion could look like it was originating from an innocent device somewhere else entirely — possibly right next door to the actual victim, the DOJ says. CNN independently reviewed Chinese job-recruitment websites and found that the Nanjing firm had recently posted listings seeking cybersecurity engineers with experience handling what the ads called large-scale penetration projects, according to CNN's own reporting.

What Remains as Murky as Pond Water

Hold your horses before you conclude that every agency on that target list got cleaned out like a smokehouse after a family reunion. A joint advisory issued by the FBI, the NSA, and US Cyber Command's Cyber National Mission Force — cited by Time and Al Jazeera — states that QTFY scanned the US Senate and an American hospital system for weaknesses in March 2026, and poked at an unidentified US election system in June 2026. Both of those specific access attempts reportedly came up empty. The Senate and the hospital were probed, not penetrated, according to that multi-agency advisory.

It is worth flagging that at least one news outlet's headline described hackers as having breached NASA and Senate networks — a framing that the underlying court documents do not fully support for those particular targets. NASA appeared repeatedly on QTFY's alleged radar, but court filings do not confirm a successful NASA breach. Separately, NASA's own Office of Inspector General flagged at around the same time that the agency's cybersecurity posture remains inadequate, according to NASA Watch — which is an uncomfortable coincidence even if the OIG report is its own separate matter. The full breadth of QTFY's activity may not yet be public, and the DOJ itself noted that seizing domains does not guarantee the group has lost all operational capability.

China Says: Y'all Got the Wrong Pig

Beijing is not exactly sending a fruit basket to the FBI field office. China's government flatly denied the allegations and urged the United States to stop weaponizing cybersecurity accusations to, as CNN and Cyber Magazine reported officials putting it, smear or discredit China. That is a denial as firm as a fence post in dry clay. The Nanjing company itself did not respond to media requests for comment, according to CNN. So you have got US court documents on one side of the fence and official Chinese government denial on the other, with independent technical corroboration from Lumen Technologies sitting somewhere in the middle pasture.

Our Analysis: What This Smells Like from the Porch

This is analysis, not established reporting, so dust off your skeptic hat. The for-hire model the DOJ describes — where a private Nanjing company allegedly sells intrusion services to Chinese state intelligence and military clients — is, if accurate, a clever way to put several layers of plausible deniability between Beijing's agencies and the fingerprints on a keyboard. It is like hiring a neighbor's cousin to paint your barn so nobody sees your truck parked outside. Independent technical corroboration from Lumen Technologies and the multi-agency advisory lends the DOJ's account more structural support than a typical government press release tends to carry on its own.

That said, domain seizures are more like padlocking the front gate than demolishing the whole farm. The DOJ's own caveat that this action does not guarantee the group's elimination is a rare and useful admission of the limits of the playbook. The concurrent NASA OIG report — independently noting the agency's persistent cybersecurity gaps — adds an uncomfortable layer of context: even failed intrusion attempts against a target with known defenses are worth taking seriously. Whether the full QTFY operation is now understood, or whether this is just the corner of the quilt that finally got pulled into the light, remains genuinely unknown.

Who is doing the hollering

These links show where the chatter came from. A link is attribution, not our endorsement or independent confirmation.

  1. US says Chinese-linked hackers attacked NASA, Senate, and gov't agenciesAl Jazeera · top tier
  2. U.S. Says Chinese Hackers Targeted Senate, NASA, Hospitals, and MoreTime · top tier
  3. US says Chinese hackers hit hospitals, NASA, Senate and moreCNN · top tier
  4. How China-Linked Hackers Targeted NASA, US DoJ and SenateCyber Magazine · specialist
  5. DOJ says China-linked hackers breached NASA, Federal Reserve and Senate networksThe National Desk · top tier
  6. OIG: NASA Cybersecurity Is Still LackingNASA Watch · specialist
Revision record

Last checked Sep 18, 2026, 9:07 AM EDT. Talk Around Town: Not all QTFY intrusion attempts were successful — court documents confirm breaches at DOE labs and NIH, but attempts against NASA and the US Senate are documented as failures. The full scope of the operation may not yet be public, and domain seizures do not guarantee elimination of the group's capability, per DOJ's own caveat.