China’s QTFY campaign against federal agencies, and what it means for you

NASA, the Federal Reserve and the Senate are on the list of targets. Nobody has said what was taken from any of them. Here is what the announcement actually establishes, and the one part of it that has something to do with the box in your hallway.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

On 26 August 2026 the Justice Department and the FBI seized the domains behind QScan and QTRouter, two platforms built by a Chinese state-sponsored group called QTFY, and broke both of them. Court documents name NASA, the Federal Reserve, the Departments of Energy, Justice and Health and Human Services, the National Institutes of Health and the US Senate among QTFY’s targets. No agency has said personal data was taken, and there is no notification, claims process or checker to look yourself up in. Two things are worth doing: if you work for or contract with one of those agencies, wait for your own agency rather than a headline; and if you own a router, camera or network drive, update it and restart it, because devices like those were what QScan conscripted to hide the traffic.

What the announcement says, point by point

The left column is what is in the Justice Department release and the joint FBI–NSA advisory of 26 August 2026. The right column is what it means, with nothing added that has not been published.

What was announcedWhat it means
Court-authorised seizure of the domains behind two platforms, QScan and QTRouter, announced on 26 August 2026.Both tools had those domains hard-coded for command traffic and authentication, so taking the domains away made the tools inoperable. What was seized is infrastructure. No arrests were announced alongside it.
The group is named QTFY and described as state-sponsored, employed by a company in Nanjing.A contractor model rather than a military unit. Court documents say QTFY sold hacking services to paying customers, and name the Ministry of State Security and the People’s Liberation Army among them.
Among QTFY’s targets: NASA, the Federal Reserve, the Departments of Energy, Justice and Health and Human Services, the National Institutes of Health, and the US Senate.The word in the release is “targets”. It does not say what was reached at each one, what was taken, or when, and officials have pointed out that not every attempted intrusion succeeds. Treat the list as who was aimed at.
QScan scanned the internet continuously and automatically compromised vulnerable internet-of-things devices at scale.Home routers, IP cameras, smart-home gear and network storage boxes, taken because they were reachable and unpatched. The people who own them were never the point.
QTRouter pooled those devices with commercial proxy services and leased virtual servers into an obfuscation network.Traffic arriving at a federal network looked like it came from an ordinary machine somewhere else, sometimes one local to the target, instead of from China. Hiding the origin was the product being sold.
The FBI and the NSA published a joint advisory with indicators of compromise covering activity going back to at least 2018.It is written for people who run networks, not for households. The part that applies to a home is the ordinary one: patch edge devices, restart them, and replace hardware that no longer gets updates.

Sources: the Justice Department press release of 26 August 2026 on the seizure of platforms operated by China state-sponsored hackers, and the joint cybersecurity advisory published the same day by the FBI, the NSA and the Cyber National Mission Force.

1. What was announced, in order

On 26 August 2026 the Justice Department and the FBI announced court-authorised domain seizures in the Southern District of California, aimed at two connected platforms called QScan and QTRouter. The unsealed documents attribute both to a People’s Republic of China state-sponsored group known as QTFY, employed by a Nanjing company, and describe a business rather than a raid: QTFY built the tooling and sold access to paying customers, said in the filings to include the Ministry of State Security and the People’s Liberation Army. QScan trawled the internet and compromised internet-of-things devices in bulk. QTRouter collected those devices, along with commercial proxy services and rented virtual servers, into a network whose only job was to make an intrusion look like it came from somewhere ordinary. Because the domains the seizure took were hard-coded into both tools for command traffic and authentication, removing them broke the tools. The same day, the FBI and NSA published a joint advisory with indicators of compromise going back to at least 2018.

2. The list of agencies, and what the release actually claims about it

NASA, the Federal Reserve, the Department of Energy, the Department of Justice, Health and Human Services, the National Institutes of Health and the US Senate are named as being among QTFY’s targets. That word is doing a lot of work, and the coverage has mostly dropped it. The release does not say what was reached inside any of those networks, what was copied, or when; officials have separately noted that not every attempt got where it was aimed. There is a real distinction between an obfuscation network built to hide intrusions and an established theft of personnel records, and only the first has been described in public. If that changes, the agencies concerned will be the ones to say so, because breach notification for federal employee data runs through the employing agency rather than through the press.

3. The part of this that reaches an ordinary house

It is not the espionage, it is the plumbing. QScan’s job was to find and take over devices at the edge of home and small-business networks: routers, IP cameras, smart-home hubs, network storage. Nothing on those devices was wanted. The devices themselves were the disguise, chosen because they sit online permanently, run software their owners never think about, and often still carry the password printed on the box. If yours was one of them, no letter is coming, because nobody knows whose they were. The maintenance that matters takes about fifteen minutes: install the firmware update through the manufacturer’s own app or admin page, change the administrator password if it is still the default, switch off remote administration and UPnP unless something you use needs them, and restart the device afterwards so anything living in memory goes with it. If the maker stopped issuing updates years ago, that is the piece of kit worth replacing rather than patching.

4. The messages that will follow this headline

A story with China, NASA and the Senate in it is a gift to anyone who sends fraudulent email for a living, and the follow-up is predictable: notes claiming your agency records were in the breach, offers of free credit monitoring “for affected federal employees”, urgent requests to confirm your details so your clearance file can be checked. None of that has any basis, because no agency has announced a loss of personal data and no claims process exists. Judge these by how they arrived rather than by how they read. Real notification for federal staff comes from the employing agency through channels you already use, and it never depends on you replying to confirm a Social Security number. Anything that arrives with a link and a deadline is worth forwarding to your security team and then deleting.

5. What a foreign service already has without hacking anyone

The uncomfortable part of a campaign like this is how little of it needs to be secret. Building a target list of people who work in and around federal agencies mostly does not require an intrusion at all: home addresses, phone numbers, relatives, previous addresses and current employer are published and sold by data-broker and people-search sites, legally, to whoever pays. That is what makes a spear-phishing message about your neighbourhood, your spouse or your last posting sound plausible, and it is available months before and years after any particular platform gets seized. It is also the only half of this story an individual has any control over.

6. What to watch over the next few months

Investigations of this size produce a long tail. Indicators published on 26 August will pull further victims out of network logs, and if any of that turns into personal-data notifications, they will arrive by post from the agency or its records administrator, not by email from a law firm. Keep whatever you do receive and note the date it came. Treat any message about compensation as fraud until an official process exists, since none does today. And if you want the general version of the response to a breach that does turn out to include your details, our post-breach guide sets out the order, and the notification-letter guide covers how to tell a genuine notice from the imitations that follow one.

See what is published about you without a hack

Your address, phone number, relatives and employer are sold openly by 499 broker and people-search sites. That is the profile a targeted message is built from, and it is the half of this you can act on. PersProtect finds where you are listed, files the removals and keeps checking that they stay down. The scan is free.

Check my exposure — free →
Common questions

The QTFY seizure, answered

Were NASA, the Federal Reserve and the Senate actually breached?

The Justice Department named them as targets of QTFY in the court documents unsealed on 26 August 2026, and it stopped there. It has not said what was reached inside any of them, what was copied, or over what period, and officials have been clear that an attempted intrusion is not the same as a successful one. Anything you read that puts a number on stolen records is going beyond the public record, because no such number has been published.

I work for one of those agencies. Do I need to do something today?

Not because of the news. If personal data about federal staff had been taken, the notification would come from your own agency or the office handling records for it, through official channels and usually by post, and it would carry an enrolment code for identity protection. Watch for that, and take anything that arrives before it as unverified. Your agency’s security team is also the right place to send a suspicious message, rather than a public claim site.

How would my home router have ended up in this?

QScan scanned the internet for devices exposed to it and exploited the ones running old firmware or default credentials, then handed them to QTRouter to be used as relays. Routers, IP cameras, network storage and smart-home hubs were the usual catch. There is no notification for this and no list to check yourself against, which is why the sensible response is maintenance rather than investigation.

Does rebooting the router fix it?

It helps and it is not the whole answer. A restart clears malware that only lives in memory, which is a common design on small devices, but it does nothing about the hole that let it in. Install the firmware update first, change the admin password from whatever it shipped with, turn off remote administration and UPnP if you do not need them, then restart. Hardware that no longer receives updates from its maker is the one case where replacing it is the actual fix.

Is my personal data on the dark web because of this?

Nothing in the announcement says personal records were taken from any agency, so there is no basis for that claim today. What is true regardless of this campaign is that the home address, phone number, relatives and employer of most working adults are already sold openly by data-broker and people-search sites. That is a separate problem from espionage, and it is the one an individual can actually do something about.

Where does official information about this come from?

The Justice Department’s press release of 26 August 2026 and the joint advisory published the same day by the FBI, the NSA and the Cyber National Mission Force. Both are on government sites you can reach by typing the address yourself. Anything about compensation, claims or “verifying whether you were affected” is not part of this: no claims process exists, because this was a seizure of hacking infrastructure rather than a consumer data breach.

Nobody needs to hack anything to find you

Your home address, phone number and relatives are already for sale. See which sites publish them right now — free, in about a minute.

Run my free exposure scan →