Technology
FBI seizes domains used by China-linked hacking group after U.S. government breaches
Federal authorities seized core infrastructure from a China-based cyber operation that compromised government agencies, defense contractors, and energy labs.
The short version
- The Justice Department and FBI seized three domains powering platforms operated by a China-linked hacking group known as QTFY.
- Unsealed records reveal the group compromised networks across three U.S. Department of Energy labs, the NIH, an HHS agency, and stole data from over 300 organizations.
- Federal officials stated the domain seizures crippled the group's core scanning and identity-masking platforms, QScan and QTRouter.
Key facts
- The FBI and Department of Justice seized three domains that supported QTFY's main operational platforms, QScan and QTRouter.[Fox News]
- Federal affidavits state QTFY operated via a China-based company that sold offensive cyber services to China's Ministry of State Security and the People's Liberation Army.[Fox News]
- The group breached three Department of Energy national laboratories, the National Institutes of Health, and the Health Resources and Services Administration by exploiting Ivanti software flaws.[Fox News]
- QTFY extracted data from more than 300 entities globally, including U.S. defense contractors, financial institutions, and universities.[Fox News]
- QTFY targeted NASA, the Justice Department, the Federal Reserve, Senate networks, and election systems, though several attempts failed due to existing system patches.[Fox News]
What remains uncertain
- Government advisories did not reveal what specific data was accessed or stolen from the affected U.S. government agencies and energy labs.[Fox News]
- It remains unknown how long the hackers maintained undetected access within federal networks or whether their intrusions caused operational disruptions.[Fox News]
Sources
- China-linked hackers infiltrated US government networks before FBI takedownFox News - Politics