the news now

The world's news, cross-checked among reputable sources.

This is a new development in a story we have covered before · earlier coverage

U.S. Disrupts Chinese State-Sponsored Hacking Network Targeting Government Agencies

5 sources across 5 countries

Who reported this

  • South China Morning Post Hong Kong · Centre-right · Alibaba Group
  • Kyodo News Japan · Centre · Non-profit publisher cooperative
  • The Korea Herald South Korea · Centre-right · Herald Corporation (Yeongpoong Group)
  • The Register United Kingdom · Centre · Situation Publishing Ltd
  • WIRED United States · Centre-left · Conde Nast (Advance Publications)

What the colours mean

  • Left
  • Centre-left
  • Centre
  • Centre-right
  • Right
  • A hatched block means the outlet is affiliated with, or controlled by, a state.

Political lean describes where an outlet sits within the politics of its own country. It is never a position on a single global scale.

Political lean is comparable inside one country and not across them, which is why the bar groups by country first. Publicly funded broadcasters are not marked as state-linked.

The owner of each outlet is listed as a matter of record, not as a judgement about the outlet.

The United States Department of Justice and the FBI announced on Wednesday the disruption of a Chinese state-sponsored hacking operation that targeted critical U.S. infrastructure and sensitive government networks. Federal authorities seized internet domains used by two hacking platforms known as QScan and QTRouter. These tools were allegedly operated by a China-based firm called Nanjing Xinjiuwei Network Technology Company, which the U.S. government identifies as a contractor for the Ministry of State Security and the People's Liberation Army. The hacking group, identified as QTFY, has been active since at least 2018.

Victims of the campaign include NASA, the Federal Reserve, the U.S. Senate, the Department of Justice, the Department of Energy, the Department of Health and Human Services, and the National Institutes of Health. The operation also targeted hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. Some reports specify that the group successfully stole data from defense contractors and financial institutions in May 2024, while other attempts, such as a 2019 effort to breach NASA, were unsuccessful.

Technical details provided by the FBI and Lumen Technology indicate that the group used botnets of hacked internet-of-things devices and co-opted commercial proxy services to hide their activity. More recently, the group allegedly hijacked virtual private network services used by Chinese citizens to blend malicious traffic with benign user data. Attorney General Todd Blanche described the seizure as part of a series of operations to dismantle indiscriminate hacking sponsored by the People's Republic of China.

The Chinese embassy in Washington denied the allegations, stating that the Chinese government opposes all forms of cyberattacks. A spokesperson urged the U.S. to stop using cybersecurity issues to smear China and accused the U.S. of overstretching the concept of national security to restrict Chinese companies. The announcement comes approximately one month before a planned meeting between President Donald Trump and President Xi Jinping at the White House.

How each side framed it

Centre-left
This coverage focused heavily on the technical mechanisms of the proxy network and the role of private contractors as quartermasters for state intelligence.
Centre
These reports focused on the factual details of the seizure and the list of targeted agencies without adding significant analytical framing.
Centre-right
These reports emphasized the official U.S. government accusations while providing space for the Chinese embassy's denial and counter-accusations.

Sources

100% of the statements in this article were traced back to the source articles listed above.