# What happened
U.S. officials say they disrupted a China-linked hacking operation that carried out break-ins and attempted intrusions against multiple sensitive U.S. institutions. The Justice Department announced it had seized internet domains used by two offensive tools named QScan and QTRouter.
# Who the DOJ says ran the operation
Company as the operator of the two platforms. The affidavit states the firm's clients included China's civilian intelligence service, the Ministry of State Security, and the People's Liberation Army. The company did not provide a response to requests for comment outside normal business hours.
# Named victims and types of activity
The affidavit explicitly names the U.S. Department of Energy, Department of Health and Human Services, and the National Institutes of Health among victims. It also lists the Justice Department, NASA, the Federal Reserve and the U.S. Senate as targets or victims in the broader campaign. Four unnamed companies in the U.S. and South Korea were also cited.
Documented actions in the affidavit and advisory include:
- Attempts to exploit a NASA VPN vulnerability in August 2019. That attempt was unsuccessful.
- Intrusions in September 2024 at three Energy Department laboratories, NIH, an HHS agency, and a U.S. security-device manufacturer.
- Scanning and unsuccessful access attempts against the U.S. Senate and at least one U.S. hospital in March 2026.
The affidavit says the campaign has used tools developed by the firm to compromise critical infrastructure and sensitive networks since at least 2018, while noting some intrusion attempts failed.
# Official reactions
A spokesperson for the Chinese Embassy in Washington said they were not familiar with the specifics in the DOJ statement and reiterated that China opposes cyberattacks under the law. The embassy accused the U.S. of using cybersecurity issues to discredit China and criticized U.S. national-security actions that it described as discriminatory toward Chinese companies.
# Why this matters
The DOJ action aims to disrupt infrastructure—domains and platforms—that federal officials associate with a prolonged campaign targeting government agencies and private firms. The case illustrates a pattern of cross-sector activity over several years, including both successful data theft and repeated probing of high-value networks.
Law-enforcement seizure of infrastructure is a common tool to interrupt operations and prevent immediate reuse of tools and domains linked to intrusions.
# Short practical takeaways
- The seizure targets digital infrastructure (domains) used in the campaign rather than physical assets.
- Activity attributed to the operation spans at least eight years and includes both successful thefts and unsuccessful attempts on high-value targets.
- Multiple U.S. national-security and law-enforcement agencies participated in issuing warnings and the advisory tied to this disruption.