Drooid Logo
Back to story perspectives

Full Breakdown

U.S. Disrupts Chinese Hacking Operation Targeting Federal Agencies

8/27/2026, 8:46:19 AM

Core Event

On August 26, U.S. authorities announced that they had disrupted a Chinese hacking campaign that had infiltrated multiple high-profile government entities. The Justice Department reported the seizure of domains linked to two hacking platforms, “QScan” and “QTRouter,” which were used to gain unauthorized access to the Justice Department, NASA, the Federal Reserve, the U.S. Senate and other sensitive agencies.

Background & Context

The operation is attributed to a China-based firm, Nanjing Xinjiuwei Network Technology Company. According to an affidavit released by the Justice Department, the firm’s clients included China’s civilian intelligence agency, the Ministry of State Security, and the People’s Liberation Army. State-sponsored cyber-espionage campaigns have been a recurring feature of Sino-U.S. relations, with previous incidents involving theft of intellectual property and attempts to compromise governmental networks.

Data & Statistics

  • Targeted agencies: Justice Department, NASA, Federal Reserve, U.S. Senate, Department of Energy, Department of Health and Human Services, National Institutes of Health.
  • Additional victims: Four unnamed companies located in the United States and South Korea.
  • Hacking platforms seized: “QScan” and “QTRouter.”

Official Statements & Responses

The Justice Department said the seized domains were integral to the campaign and that the operation had been successfully disrupted. It identified Nanjing Xinjiuwei Network Technology Company as the operator of the platforms and linked the firm to China’s Ministry of State Security and the People’s Liberation Army. No further comment was provided by the CIA, the White House or Chinese officials in the immediate aftermath.

Conflicting Reports & Gaps

No alternative accounts of the breach have been published. Details such as the exact timeline of the intrusions, the specific data accessed, and the identities of the four unnamed corporate victims remain undisclosed.

What’s Next

U.S. officials indicated that investigations will continue to assess the full scope of the intrusion and to determine additional remedial actions. No specific deadlines or further public statements have been scheduled.