US seizes Chinese hacking platforms as allies toughen up
The US Justice Department and FBI announced on 26 August that they had seized internet domains supporting two hacking platforms operated by a Chinese company, disabling tools used to break into networks at NASA, the Federal Reserve, the US Senate and four federal departments. A joint advisory published the same day by the FBI, the National Security Agency and the Cyber National Mission Force dates the group’s first recorded scanning of an American federal network to May 2018, and its intrusion at the Justice Department, the Federal Reserve and NASA to August 2019, through a vulnerability in Pulse Secure virtual private network software.
That interval between the activity and its disclosure is the most instructive part of the announcement. Cyber operations are routinely described as the next rung on the escalation ladder between NATO members and Russia and China. The documents released this week describe something else: a campaign running for the better part of a decade, and a Western response that has changed substantially in the past six months.
The contractor behind the state
Court documents unsealed in the Southern District of California say the platforms — QScan and QTRouter — were built and run by a group calling itself QTFY, employed by Nanjing Xinjiuwei Network Technology Company. The Justice Department says QTFY sold hacking services to customers including China’s Ministry of State Security and the People’s Liberation Army. The joint advisory adds that the company was founded in 2018, holds business relationships with MSS units, and that QTFY’s personnel include former PLA members. QScan ran a distributed scanning and penetration-testing system which, on a single day in 2024, processed more than two million tasks, drawing on a library of over 200 exploits.
Lumen Technologies’ Black Lotus Labs, which tracked the infrastructure for a year and which sells network security services commercially, describes the operation as a “quartermaster”: a supplier packaging reconnaissance, proxy routing and concealment into a service other operators could rent. Rather than compromising thousands of devices itself, the researchers say, it bought high-tier subscriptions to commercial Chinese proxy services and blended its traffic with ordinary consumer use. Its telemetry showed profiling of research universities in the United States, the United Kingdom and the Asia-Pacific, and of European infrastructure and judicial networks.
Attorney General Todd Blanche said federal law enforcement had investigated and disabled the software, calling it the latest in a series of technical operations against hacking sponsored by China. Beijing has consistently rejected such allegations. Accounts of its response to this case differ: US News reported that the Chinese embassy in Washington did not immediately return a request for comment, while the Korea Times reported that Beijing rejected the allegations.
Europe has been sanctioning the same model
The enabler-company structure is not confined to American targets. On 16 March the Council of the European Union sanctioned two Chinese firms: Integrity Technology Group, which the Council links to the compromise of more than 65,000 devices across six member states between 2022 and 2023, and Anxun Information Technology, also known as i-Soon, for hacking services directed at critical infrastructure and core state functions. Two of Anxun’s co-founders were listed individually. An Iranian company was sanctioned in the same round.
Neither the March listings nor Wednesday’s seizures were framed as responses to any single incident. Both describe activity accumulated over years.
What changed this year was the answer
The shift is in the policy announced. On 6 March the White House published President Trump’s Cyber Strategy for America, a seven-page document whose first pillar commits to deploying “the full suite of U.S. government defensive and offensive cyber operations” and states that the administration will not confine its responses to the cyber realm. FBI Director Kash Patel cited the strategy directly in Wednesday’s announcement.
NATO went in the same direction four months later. On 13 July the North Atlantic Council issued a statement condemning Russian cyber activity, saying allies had strengthened the framework for integrating cyber effects into the alliance’s operations and were prepared to respond at a time and in a manner of their choosing. The same day, the EU sanctioned nine individuals and four entities, and the United Kingdom sanctioned 24, over Russian cyber and hybrid operations.
Set against that, the Ankara Summit Declaration of 8 July is notably restrained. The six-paragraph text mentions cyber once, as an asset complementing nuclear, conventional and missile-defence capabilities, refers to hybrid threats in general terms, and does not mention China. NATO’s standing position, agreed at the 2021 Brussels summit and unchanged, is that significant cumulative malicious cyber activity might in certain circumstances be treated as an armed attack triggering Article 5, decided case by case.
At the Munich Cyber Security Conference in February, NATO Deputy Secretary General Radmila Shekerinska told delegates the alliance needed to invest more and impose costs on those seeking harm, and that the objective had to be the ability to strike back. She noted that allies had agreed at The Hague to raise spending to 5% of GDP within a decade, with 1.5 percentage points earmarked for resilience including cybersecurity. British parliamentarians have warned that the indirect component could allow existing activity to be repackaged rather than new capability delivered.
Where escalation is demonstrable
One incident supports the escalation argument more directly than the espionage campaigns do. On 29 December 2025, according to CERT Polska, coordinated attacks hit more than 30 Polish wind and photovoltaic farms, a manufacturing company and a large combined heat and power plant supplying heat to almost half a million people, during a period of low temperatures. The national CERT described the objective as purely destructive, comparing it to arson, and said the attacks damaged firmware and deleted system files rather than stealing data. Electricity generation continued and the heat supply was not cut.
Attribution is contested. CERT Polska found a high degree of overlap with infrastructure used by the cluster known variously as Static Tundra, Berserk Bear, Ghost Blizzard and Dragonfly, and said this was the first publicly described destructive activity attributed to it. The security firm Dragos attributed the activity to a group it calls ELECTRUM, which it says overlaps with Sandworm, the GRU’s destructive-operations unit. Those are different Russian services.
Who is ahead depends on what is measured
The public benchmark most often cited is the International Institute for Strategic Studies’ net assessment, which placed the United States alone in its top tier and China, Russia, the United Kingdom, France, Israel, Canada and Australia in the second. That study’s first volume was published in 2021 and its second in 2023; it predates the campaigns described this week.
The most recent official US judgement is narrower. Presenting the 2026 Annual Threat Assessment in March, then-Director of National Intelligence Tulsi Gabbard told the Senate Intelligence Committee that China and Russia present the most persistent and active cyber threats and continue their research and development. The assessment does not rank capability. The Cyber Strategy asserts that America’s cyber operators and tools are the best in the world — a claim by an interested party, not an independent finding.
Defensive indicators are easier to read and less flattering. The UK National Cyber Security Centre’s Annual Review 2025 recorded 429 incidents requiring its support in the year to August 2025, of which 204 were nationally significant, against 89 the year before, and 18 were highly significant, against 12.
Kremlin adviser Andrei Fedorov told the BBC this week that Russia’s options in response to British support for Ukraine included what he called a technical reaction, possibly a hacker attack from an unofficial source. That is a warning from an individual adviser, not a statement of Russian policy. It is also, on the evidence of the past decade, a description of what is already happening.