Urgent.News

What's breaking now, across thousands of outlets.

Tech

Fed, NASA and DOJ among victims of Chinese state-sponsored hacker group: Court documents

Hackers targeted networks "operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors," a filing said.

The US Department of Justice has disrupted a Chinese state-sponsored hacking operation that targeted several sensitive US government agencies and companies. According to court documents, the hacking group, known as QTFY, was responsible for computer intrusion activity at the Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, NIH, NASA, and US Senate.

The hacking platforms, QScan and QTRouter, were used to compromise US critical infrastructure since 2018, and were allegedly operated by Nanjing Xinjiuwei Network Technology Company, a China-based firm. The company's clients included China's Ministry of State Security, the country's civilian intelligence agency, and the People's Liberation Army.

The targeted networks included those operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. The US Justice Department seized domains associated with QScan and QTRouter as part of efforts to disrupt the alleged hacking campaign, which also targeted companies in the US and South Korea.

Brief written by urgent.news from CNBC, Tom's Hardware, CNBC World, Live Mint, Techmeme — 5 reports on this story. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at cnbc.com →

More in Tech

Environment Variables Done Right (and Safe)

The Problem with Hardcoding We've all been there: you need an API key, a database URL, or a secret token. The quickest fix is to paste it right into the code. It works, but it's a ticking time bomb.

  • Environment variables store configuration values outside source code
  • Access via process.env in Node.js, os.environ in Python, os.Getenv in Go
  • Never commit .env files to version control

More from Wednesday 26 August →