The Justice Department and FBI announced court-authorized domain seizures on August 26, 2026 that they say made two complementary China-nexus hacking platforms — QScan and QTRouter — inoperable. DOJ press release 26-972 names a PRC state-sponsored group QTFY, employed by China-based Nanjing Xinjiuwei Network Technology Company, as the operator. Paying customers, DOJ says, include the PRC Ministry of State Security and the People’s Liberation Army.
Among the victims of QTFY computer intrusion activity, DOJ lists NASA, the Federal Reserve, the Department of Energy, the Department of Justice, HHS, NIH, and the U.S. Senate. Reuters (via HuffPost) and UPI repeated the same disruption. The Justice Department posted the announcement the same day. Anadolu Agency reports three seized domains; this post does not republish alleged malware hostnames.
This is a platform disruption, not a how-to and not a named-org “data dump.” DOJ has not published a stolen-record count. It is not a duplicate of the federal agencies email-security listicle (score snapshot) or the FBI NCII PSA (social-account phishing).

Snapshot
| Field | Detail |
|---|---|
| Lead | DOJ OPA 26-972 (Aug 26, 2026) |
| Court | Affidavit unsealed, Southern District of California |
| Group | QTFY via Nanjing Xinjiuwei; customers include MSS and PLA |
| Platforms seized | QScan + QTRouter (hard-coded domains used for C2/auth) |
| Named victims | NASA, Federal Reserve, Energy, DOJ, HHS, NIH, U.S. Senate |
| CourtListener | RECAP not yet indexing "QScan" AND "QTRouter"; Texas federal 0 for "QTFY" (Aug 26) |
What DOJ says the platforms did
DOJ describes a two-part service, not a single emailed lure:
| Piece | Role (DOJ wording) |
|---|---|
| QScan | Scans and automatically infects thousands of IoT devices worldwide |
| QTRouter | Obfuscation network: compromised IoT, commercial proxies, leased VPS |
| Effect | Intrusion traffic can look local to the target, not PRC-origin |
| Seizure | Hard-coded domains were used for communication and authentication |
The Record adds FBI Assistant Director Brett Leatherman: devices in more than 130 countries; routers and cameras among the IoT classes; the firm also sells stolen data and hacking services. The Record says investigators followed the infrastructure from 2018 through a U.S. Senate attack this year — the affidavit, it reports, does not name senators or committees.
Lumen Black Lotus Labs published a matching “quartermaster” write-up the same day: The infrastructure quartermaster. DOJ says FBI and NSA also released a QTFY indicators advisory covering activity back to at least 2018. This post does not copy IoCs.

What is confirmed — and what is not
DOJ’s victim list is computer intrusion activity. It is not a public inventory of exfiltrated files.
| Claim | Status |
|---|---|
| Named U.S. agencies were QTFY intrusion victims | DOJ (Aug 26) |
| Hospitals, telecom, power, finance, defense contractors | The Record citing the affidavit (unnamed orgs) |
| Four unnamed companies in the U.S. and South Korea | Reuters via HuffPost |
| 2019 NASA Pulse Secure VPN attempt | The Record; Anadolu says it failed because NASA had already patched |
| Prior PRC disruptions (Mustang Panda PlugX, Flax Typhoon, Volt Typhoon) | DOJ (separate operations) |
Do not treat a patched 2019 NASA attempt as the whole NASA story — DOJ still lists NASA among intrusion victims. Do not invent a nationwide victim count.
MFA: YubiKey, Google Authenticator, PIV
QTFY hid behind other people’s devices. Phishing-resistant MFA on Login.gov and agency PIV still matters for the accounts those agencies expose to the public and to staff. Rechecked August 26, 2026.
| Portal | YubiKey / FIDO | Open TOTP | Grade |
|---|---|---|---|
| Login.gov | Yes (security key) | Yes (auth app) | Strong |
| NASA Guest | via Login.gov (guest help) | via Login.gov | Strong |
| NASA workforce | PIV (NPR 2810.1F) | Not documented | Strong |
| NASA NAS (HECC) | RSA SecurID (policy) | No | Partial |
YubiKey / Google Authenticator: Login.gov documents FIDO security keys and an authentication-app (open TOTP) path — Google Authenticator-class apps are the documented consumer option, plus PIV/CAC for eligible government emails. NASA Guest federates to Login.gov. Agency staff PIV/CAC is Strong hardware, not open TOTP. The NAS supercomputing facility still documents RSA SecurID for remote access — Partial, not YubiKey.
SMS/voice remains a weaker Login.gov option. Enroll a security key. Same rule as the MFA directory.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| YubiKey 5 / 5C NFC case | Keychain protection for the key | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP vault | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
EmailMeNow domain audits on August 26, 2026. 100% is the ideal. 0 of 11 reach it. These scores are public identity / transport / website posture on the real agency hosts. They do not measure whether QTFY still has access anywhere, and they do not validate a lookalike URL.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| NIH | nih.gov | 78% | −22 |
| Energy Department | energy.gov | 73% | −27 |
| HHS | hhs.gov | 71% | −29 |
| U.S. Senate | senate.gov | 68% | −32 |
| Justice Department | justice.gov | 66% | −34 |
| NASA | nasa.gov | 65% | −35 |
| FBI | fbi.gov | 64% | −36 |
| Federal Reserve | federalreserve.gov | 63% | −37 |
| Login.gov | login.gov | 63% | −37 |
| Lumen | lumen.com | 58% | −42 |
| NSA | nsa.gov | 55% | −45 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| nih.gov | 65% | 45% | 98% |
| energy.gov | 95% | 45% | 43% |
| hhs.gov | 90% | 70% | 37% |
| senate.gov | 95% | 45% | 37% |
| justice.gov | 80% | 45% | 40% |
| nasa.gov | 80% | 45% | 37% |
| fbi.gov | 75% | 45% | 40% |
| federalreserve.gov | 75% | 45% | 37% |
| login.gov | 65% | 100% | 40% |
| lumen.com | 65% | 15% | 37% |
| nsa.gov | 55% | 45% | 37% |
How to read this: NIH leads at 78% on a strong website score; Energy leads identity at 95% and still misses 100%. Login.gov is the only host here with 100% transport — and still 63% overall. NSA trails at 55%. The June federal agencies listicle used a different agency set and older scores (FBI 65% then vs 64% on this pass).
Audit links: nih.gov · energy.gov · hhs.gov · senate.gov · justice.gov · nasa.gov · fbi.gov · federalreserve.gov · login.gov · lumen.com · nsa.gov

Illustration only — scores are in the tables above, not in the artwork.
Website stack note
Passive website-tech probes on August 26, 2026:
| Domain | Stack signal |
|---|---|
| energy.gov | Drupal 8 (latest 11.4.5) |
| nih.gov | Drupal 10 (latest 11.4.5) |
| justice.gov | Drupal 11 behind 11.4.5 |
| nasa.gov | WordPress, version hidden; Sectigo TLS into Dec 11, 2026 |
| senate.gov | Stack undetected; jQuery 1.11.3 (pre-3.5 XSS-class fixes) |
| login.gov | Stack undetected; Let’s Encrypt TLS into Oct 4, 2026 (38d) |
| nsa.gov / hhs.gov | HTTP→HTTPS redirect not confirmed on probed hosts |
| federalreserve.gov, fbi.gov, lumen.com | No notable CMS aging flags in this pass |
Stack hygiene on a .gov homepage does not prove an IoT botnet is gone.
Blacklist and lookalike domains
Email blacklist checks (public DoH, August 26, 2026): nasa.gov, federalreserve.gov, energy.gov, justice.gov, hhs.gov, nih.gov, senate.gov, fbi.gov, nsa.gov, lumen.com, and login.gov were clear on mail/domain lists we can query. Federal Reserve, NIH, and FBI showed SPFBL notes on CDN/web IPs only — not counted as mail reputation hits. senate.gov had no MX in this pass.
DNS lookalike scans (EmailMeNow cybersquat engine — registered DNS signals only):
| Brand scanned | Checked | To review | BEC staging |
|---|---|---|---|
| nasa.gov | 80 | 12 | 0 |
| fbi.gov | 69 | 11 | 0 |
| justice.gov | 116 | 11 | 0 |
| senate.gov | 106 | 11 | 1 |
| federalreserve.gov | 201 | 10 | 2 |
High-interest registered names (investigate; not QTFY infrastructure):
| Lookalike | Technique | Note |
|---|---|---|
| senate.dev | tld-swap | BEC staging (NS, MX) |
| federalreserve.io | tld-swap | BEC staging (NS, MX) |
| federalreserve.org | tld-swap | BEC staging (NS, MX) |
| federalreserve.com | tld-swap | MX points at the real Fed mail host |
The scanner also flagged nsa.gov as an “omission” of nasa.gov — that is NSA, a different agency, not a NASA clone. Pair monitoring with Cybersquat Domain Monitoring.
CourtListener and weekly scan sources
CourtListener RECAP on August 26, 2026: 0 hits for "QScan" AND "QTRouter". Quoted "QTFY" is too noisy as a ticker-style string and returned 0 in Texas federal courts (txsd / txed / txnd / txwd). SDCA dockets filed in early August 2026 that matched a generic “seizure” query were unrelated account warrants — the QTFY affidavit is unsealed per DOJ but not yet in the RECAP index we queried.
| Source | Finding |
|---|---|
| DOJ / FBI | Primary — PR 26-972 + SDCA affidavit |
| Lumen Black Lotus Labs | Same-day quartermaster TTP write-up |
| Reuters / UPI / The Record | Corroboration; no stolen-record count |
| MERENA / DeXpose / GalaxyWarden | Not a leak-site listing |
| SEC Item 1.05 | Not applicable (federal agencies, not issuers) |
Related coverage
- Cybersecurity audit of major U.S. federal agencies
- MFA support directory — YubiKey, authenticator apps & passkeys
- FBI NCII / lookalike support phishing
- Beazley Q2 2026 — Login.gov Strong, Microsoft device-code
- FBI IC3 cyber alerts
- IBM Cost of a Data Breach 2026
Sources: DOJ OPA 26-972 (Aug 26, 2026); The Record; Reuters via HuffPost; UPI; Anadolu Agency; Lumen Black Lotus Labs; DOJ on X. Independent EmailMeNow domain audits, website-tech probes, blacklist checks, cybersquat scans, and CourtListener RECAP August 26, 2026. MFA grades reflect public documentation, not a private account enumeration.
Run a free audit at audit.emailmenow.com or contact EmailMeNow for phishing response aimed at the 100% ideal.