Back to Home
Technology

Washington seizes domains and accuses Chinese group of targeting US institutions

US authorities seized internet domains they said were used by a Chinese state-backed group to target government agencies and critical infrastructure, including NASA and the Federal Reserve. Beijing rejected the allegations as disinformation in the latest episode of mutual accusations over hacking and cyberespionage operations.

•3 min

Listen to this article

An automatically generated audio version.

0:00
0:00
Servers and networking equipment sit on a table in a data centre, with Chinese and US flags displayed between them.

US authorities announced the seizure of internet domains they said were used by a Chinese state-backed hacking group to target government institutions and critical infrastructure in the United States. Beijing rejected the allegations as “disinformation.”

Domains linked to two online platforms

The US Justice Department said in a statement issued Wednesday that the seizure was carried out under court orders and covered domains used by the Q Scan and Q Router platforms. It said the targets included NASA, the Federal Reserve, the Senate, and the departments of Energy, Justice, and Health and Human Services, as well as the National Institutes of Health.

The department said unsealed court documents in the Southern District of California attributed the creation and operation of the two platforms to a group known as QTFY, which it said was state-sponsored by China and operated on behalf of Nanjing Xingyue Network Technology, a company based in China.

According to the US account, the group exploited software vulnerabilities to attack government agencies, power companies and hospital systems. It also operated a global network of compromised devices, or a botnet, to carry out its campaigns. The information was attributed to Brett Leatherman, a senior FBI cybersecurity official, citing The Wall Street Journal.

Beijing accuses Washington of distorting facts

China’s Foreign Ministry rejected the allegations and accused the United States of “reversing and distorting facts.” Ministry spokesman Lin Jian said at a news conference that Beijing opposed what he described as the repeated smearing of China under the pretext of cybersecurity concerns.

Washington must abandon “double standards and political manipulation.”

Lin accused the United States of conducting hacking and surveillance on a global scale. The source did not include a US response to the Chinese allegations.

A record of mutual cyber accusations

The case follows a series of incidents in which Washington and Beijing exchanged accusations of cyberespionage. In September 2025, a special congressional committee accused hackers linked to the Chinese Communist Party of impersonating Representative John Moolenaar and sending malicious messages to steal data on trade negotiations between the two countries.

In 2025, Beijing accused the US National Security Agency of attacking the National Time Service Center to access sensitive information. In 2024, Washington attributed an attack on Treasury Department systems that targeted workstations and unclassified documents to a China-backed entity.

The United States also accused the Salt Typhoon group in 2024 of breaching telecommunications networks and stealing user data. In 2023, it accused the Volt Typhoon group of targeting the telecommunications, transportation and energy sectors, with a focus on Guam, and attributed the hacking of US government email accounts and theft of information related to China policy to Chinese hackers.

Report on Chinese satellite used by Iran

Separately, the Financial Times reported in April that Iran had secretly used a Chinese satellite to monitor US military sites in the Middle East. Citing leaked Iranian military documents, data, images and orbital analyses, the report said the Islamic Revolutionary Guard Corps’ air force had obtained the TEE-01B satellite, built and launched by China’s Earth Eye company in late 2024.