US Charges Chinese Hackers With Infiltrating DOJ, NASA, Federal Reserve Since 2018
AM730 · 3 SOURCESabout 2 hours ago3 MIN

Summary
The US Department of Justice announced on August 26 that it had disrupted a sophisticated Chinese state-linked hacking operation that had been targeting American government agencies since 2018. Federal authorities seized two hacking platforms—QScan and QTRouter—that were operated by Nanjing Xinjiuwei Network Technology Co., Ltd., a company with documented ties to China's Ministry of State Security and People's Liberation Army. The DOJ initially reported that agencies including the Department of Justice, Senate, Federal Reserve, NASA, Department of Energy, and National Institutes of Health had been breached. However, on August 28, the DOJ issued a revised statement clarifying that these agencies were primarily targets, with only some actually experiencing successful intrusions. China's embassy in Washington rejected the allegations, accusing the US of using cybersecurity issues to tarnish China's reputation.
Key Points
- DOJ seized QScan and QTRouter domains operated by Nanjing Xinjiuwei Network Technology, a company with clients including China's Ministry of State Security and PLA
- Chinese hackers targeted Department of Justice, NASA, Federal Reserve, Senate, Department of Energy, HHS, NIH, and four undisclosed US and South Korean companies
- In September 2024, hackers successfully breached three unnamed Department of Energy laboratories, NIH, an HHS agency, and a US security equipment manufacturer
- DOJ revised its statement on August 28, clarifying that while agencies were targets, only some were actually breached—narrowing the scope of confirmed intrusions
- In May 2024, some attacks successfully stole data from defense contractors, financial institutions, and universities, while a March 2024 scan of Senate networks was partially unsuccessful
Why It Matters
This case represents one of the most extensive Chinese state-sponsored cyber espionage campaigns uncovered against US government infrastructure, demonstrating the persistent threat facing democratic institutions. The DOJ's subsequent narrowing of confirmed breaches highlights the complexity of attributing cyber intrusions and the challenges in accurately assessing the scope of foreign intelligence operations. China's sharp rebuttal—accusing the US of weaponizing cybersecurity concerns to stigmatize Chinese companies—underscores the escalating tensions in US-China relations over technology and espionage, with implications for global technology supply chains and international norms governing state behavior in cyberspace.
This case represents one of the most extensive Chinese state-sponsored cyber espionage campaigns uncovered against US government infrastructure, demonstrating the persistent threat facing democratic institutions. The DOJ's subsequent narrowing of confirmed breaches highlights the complexity of attributing cyber intrusions and the challenges in accurately assessing the scope of foreign intelligence operations. China's sharp rebuttal—accusing the US of weaponizing cybersecurity concerns to stigmatize Chinese companies—underscores the escalating tensions in US-China relations over technology and espionage, with implications for global technology supply chains and international norms governing state behavior in cyberspace.