The Justice Department announced Wednesday that it had disrupted a Chinese state-sponsored hacking operation responsible for intrusions and attempts on sensitive U.S. government networks, including those at the Department of Justice, NASA, the Federal Reserve, and the Senate.

Court documents unsealed in federal court in California identified the group known as QTFY, linked to the China-based Nanjing Xinjiuwei Network Technology Company, as the operator of two platforms called QScan and QTRouter. The company provided services to clients including China’s Ministry of State Security and the People’s Liberation Army.

The affidavit stated that the hackers used the infrastructure to compromise critical networks in the United States and globally since at least 2018. Specific incidents included an unsuccessful attempt to access NASA networks in August 2019, intrusions at three unnamed Energy Department laboratories, the National Institutes of Health, an unnamed HHS agency, and a U.S. security device manufacturer in September 2024, and vulnerability scans targeting Senate networks in March 2026.

Additional targets encompassed hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. The level of access gained varied across victims, and not all attempts succeeded.

The DOJ and FBI seized the domains associated with the platforms to render them inoperable. Officials described the activity as part of a broader pattern of Chinese cyber operations against U.S. interests.

This latest action follows other reported Chinese-linked campaigns, such as Salt Typhoon, which compromised telecommunications networks and potentially accessed sensitive law enforcement data.