U.S. says it disrupted Chinese hacking operation targeting several government agencies
DOJ says domains tied to QScan and QTRouter were seized; infrastructure allegedly linked to Nanjing Xinjiuwei and used since at least 2018.

Washington announced that it has disrupted a Chinese-linked hacking operation responsible for intrusions into multiple U.S. government systems, including the Department of Justice, NASA, the Federal Reserve and the U.S. Senate. Authorities said they seized domains used by two malicious platforms known as "QScan" and "QTRouter."
Targets, alleged operator and timeline
The Department of Justice identified additional targets that included the Department of Energy, the Department of Health and Human Services, the National Institutes of Health and four unnamed companies located in the United States and South Korea. U.S. officials contend the platforms were operated by a company called Nanjing Xinjiuwei Network Technology, based in China.
Justice Department documents and statements assert that clients of Nanjing Xinjiuwei included China's civilian intelligence service — the Ministry of State Security — as well as elements of the Chinese military. According to the U.S. account, the group's infrastructure has been used to attack critical systems in the United States and around the world since at least 2018.
U.S. authorities did not provide operational details in the initial announcement about how the seizures were carried out or whether any arrests were made. Officials said the action focused on disrupting the infrastructure that enabled the intrusions.
The Chinese Embassy in Washington did not immediately respond to requests for comment. Beijing has broadly rejected allegations that it is behind state-directed hacking campaigns.
U.S. officials said the seizure of domains tied to QScan and QTRouter aims to limit the platforms' ability to be used for further intrusions while investigations continue.
Photo: press material from the event


