GovernmentAI-TechBusinessScienceSportsEntertainmentGeneral
Government

US seizes domains in Chinese hacking campaign against federal agencies

Court filings show state-linked group QTFY targeted the Federal Reserve, NASA, and the Senate across an eight-year intrusion effort.

US seizes domains in Chinese hacking campaign against federal agencies
The Robert F. Kennedy Department of Justice Building, whose department seized domains in a hacking campaign. Source: Wikipedia
Published28 Aug 2026, 17:33 Last updated4 Sep 2026, 10:06 Source
Show reference links Marks each sentence drawn from a source or a contributor

The Justice Department seized three internet domains linked to a Chinese state-sponsored hacking group that targeted federal agencies, congressional offices, and research institutions beginning in 2018.1

Court documents unsealed by federal prosecutors identify the intrusion group as QTFY.1 According to the filings, the group operated two complementary hacking platforms designed to penetrate and maintain access to sensitive institutional networks across the United States government.1

The target list detailed in the court filings spans economic, scientific, and legislative bodies. Federal prosecutors stated that QTFY directed its platforms against the Justice Department, NASA, the Federal Reserve, the Senate, the Department of Health and Human Services, the National Institutes of Health, and the Department of Energy.1

Targeting federal networks and research labs

The court records show that the operations also reached into national laboratories and defense contractors, pointing to an espionage effort focused on technological and strategic intelligence.1 The group maintained its infrastructure across multiple years, using the specialized platforms to sustain persistent access across target networks.

US seizes domains in Chinese hacking campaign against federal agencies
Headquarters of the Center for Strategic and International Studies, whose senior fellow Nikita Shah is quoted. Source: Powertripshow

The duration of the intrusions and the evidence of data extraction reflect standard intelligence gathering, said Nikita Shah, a senior fellow in the Intelligence, National Security, and Technology Program at the Center for Strategic and International Studies.1 Shah said in an interview that the campaign represents classic espionage while pointing to sustained risks around commercial and scientific property.1

Shah argued that such operations serve a dual purpose for Beijing. "It’s operations like this that enable China to get intellectual property theft that then converts into economic gain," Shah said.1

Infrastructure vulnerabilities and federal response

The seizure of the three domains disrupted a portion of the group's operational network, though the filings describe a broader infrastructure system designed to withstand individual disruptions. The sustained targeting of federal agencies demonstrates persistent exposures across government systems.

Court records indicate that China is maintaining a deliberate cyber posture, said Lauryn Williams, who served as director for strategy in the White House Office of the National Cyber Director under President Joe Biden.1 Williams said the disclosures reflect both the persistence of foreign operators and structural defense challenges facing federal networks.

Eisenhower Executive Office Building in Washington DC
The ornate Eisenhower Executive Office Building represents the federal agencies targeted by the Chinese hacking group. Source: Ibrahim Diallo (CC BY-SA 4.0)

"It both emphasizes that [China] is going to continue to find creative ways to target specific infrastructure and also, on the flip side, for the United States, that our infrastructure continues to be vulnerable," Williams said.1

Federal authorities targeted the group's command infrastructure to restrict its ability to coordinate ongoing operations across the compromised networks. The seized domains had functioned as digital nodes directing the two intrusion platforms used against target systems.

The affected agencies operate critical segments of national infrastructure, from financial policy oversight at the Federal Reserve to energy research and space systems at the Department of Energy and NASA. Federal filings show that QTFY targeted these environments systematically across the eight-year period documented by investigators.

Reporting note: this piece draws on reporting by Lauren Morganbesser published August 28, 2026, and federal court filings released by the Justice Department.

Source: Semafor, August 28, 2026

References

This article is based on 1 source, listed in the order they are cited.

  1. 1 LM Lauren Morganbesser announcement · 28 Aug 2026 China intensifies hacking campaign See the source