Chinese Hackers Broke Into NASA, Federal Reserve, DOJ & Senate: FBI Announces

The United States Department of Justice has on Wednesday announced US authorities thwarted a major state-sponsored hack which saw a temporary intrusion into NASA, the Federal Reserve, Senate, the DOJ, Department of Energy, and the Department of Health and Human services, along with four unnamed companies in the US and South Korea.

“Today we announced the disruption of a global botnet and hacking platform used by Chinese state-sponsored hackers to target U.S. critical infrastructure,” said FBI Director Kash Patel.

“These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down,” he added.

Domains utilized by two hacking platforms identified as “QScan” and “QTRouter” were seized by the DOJ in the large scale counter-cyberespionage operation.

Describing a pervasive botnet which was ultimately believed to be backed by Chinese state actors, The Wall Street Journal details that the “goal was to blend in with legitimate networking traffic, making the hacking activity hard to trace, federal officials say.”

“The group exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies and hospital systems, and operated a worldwide network of hacked devices—known as a botnet—to conduct its hacking campaigns, according to Brett Leatherman, the Federal Bureau of Investigation’s top cyber official,” WSJ continues.

As for the specific allegation that this had state backing, the DOJ press release states:

People’s Republic of China (PRC) state-sponsored group known as “QTFY,” employed by China-based Nanjing Xinjiuwei Network Technology Company, created and operated QScan and QTRouter.

The DOJ announcement additionally outlines efforts at concealment and ‘plausible deniability’ in the following:

QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers. QTRouter then serves as an “obfuscation network” – meaning it allows QTFY and other malicious cyber actors to conceal the PRC-origin of their computer intrusion activities because the malicious communications appear to originate from computers (such as those compromised by QScan) that are outside of the PRC and may even be local to the targeted networks. Because the seized domains were hard-coded into both the QScan and QTRouter malware and used for essential tasks such as communication and authentication, the court-authorized seizures made QScan and QTRouter inoperable. 

Neither Beijing’s foreign ministry nor the Chinese embassy in Washington have officially responded to the allegations, and as has been the pattern in the past is likely to reject the US charge altogether.

Earlier this year Google was among those warning of imminent stepped-up Chinese and Russian targeting of US defense companies. 

Google’s prior report seemed to preview some of the techniques on display in this latest hack. The report cited observations of “more China-nexus cyber espionage missions directly targeting defense and aerospace industry than from any other state-sponsored actors over the last two years.”

Keep reading

German Spy Agency Sends Scouts to Gamescom 2026, Looking To Hire Gamers As Secret Agents: THE TELEGRAPH

BND wants hackers capable of waging cyberwar on Russia.

The newly beefed-up German foreign intelligence service is trying to get a leg up on its Russian foes by tapping a younger, radically different class of agents: gamers.

The BND has launched a recruitment drive for game enthusiasts, eying a ‘new generation of tech-savvy secret agents.’

The Telegraph reported:

“The Telegraph understands that agents from the Bundesnachrichtendienst (BND), the German equivalent of Britain’s MI6, will attend the world’s largest video game festival to recruit young spies.

BND officials said there was a ‘significant overlap’ between the skills possessed by gaming fans and those the agency needs to retaliate against Russian hackers targeting critical infrastructure in Germany.”

This is not the first time the BND has tackled gamers, because the exact same drive was enacted last year.

“The recruiting operation, at Gamescom 2026 in Cologne, is part of a historic rearmament drive in Germany that seeks to turn the once-toothless BND into a rival of MI6 and Mossad.

An intelligence source said gamers at the festival who fit the BND’s profile would be invited to take a five-step challenge that tests their aptitude for cyber-security and hacking.”

Keep reading

US Government Warns: Hackers Attacking Vulnerable Water Systems With AI Help

Several U.S. government agencies have said that cyber actors are attempting to hack into devices made by industrial systems company Siemens that are used to monitor water and other critical infrastructure systems.

In an advisory published on Wednesday, the FBI, National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and other U.S. agencies informed “owners and operators of industrial control systems” that there is an “active cyber threat to Siemens S7 Series PLCs,” or programmable logic controllers—an industrial automation system.

Unnamed “threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools,” the advisory said.

It added that the hackers use services to find PLCs connected to the internet that run what the agencies said is “outdated software” or are “otherwise poorly protected.”

“The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities,” the advisory reads.

“This is not a theoretical risk—it is an active threat.”

The agencies further warned that “exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.”

Organizations using Siemens systems are encouraged to apply relevant security updates, isolate devices and systems from the internet where possible, implement strong security protocols, and strengthen monitoring for potential malicious activity, according to the advisory.

“These mitigations are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, as the asset owners may not realize that their systems are exposed and at risk,” they added.

The advisory did not provide the name of a specific group, country, or actor that may be involved in attempting to hack the Siemens systems. Nor did it name companies that may have been targeted by the threat actors.

The warning ‌comes amid U.S. cyber incidents ⁠targeting local water systems in several states in recent weeks. The FBI said earlier this month that from July 27 to July 30, water and wastewater utility companies in seven states reported security-related incidents.

In July, CISA and other agencies said Iran-linked hackers have targeted PLCs made by Rockwell Automation, Schneider Electric, Siemens, and potentially others.

A cybersecurity risk organization, Encrygma, said on Wednesday that a group linked to Iran’s Islamic Revolutionary Guard Corps, known as the CyberAv3ngers, has attacked water systems in the United States and displayed political messaging. CISA linked the group to cyberattacks on PLCs in late 2024.

Since February, the United States and Iran have traded strikes as the Trump administration has demanded that Tehran give up its nuclear program and reopen the Strait of Hormuz, a crucial waterway that allows for the transportation of significant amounts of the world’s traded oil.

Other agencies that were involved in the release of Wednesday’s advisory included the Department of Energy and the Environmental Protection Agency.

The NSA, FBI, CISA, and other U.S. agencies have long said that the Chinese regime, Iran, North Korea, and Russia have engaged in malicious cyber activity against U.S. infrastructure networks, collecting intelligence and engaging in cyber espionage.

Keep reading

Cyberattack Cripples California City’s 911 System, Forces Emergency Shutdown

A Northern California city of roughly 30,000 residents was forced to shut down its entire computer network Friday after a cyberattack knocked out its 911 system, the latest sign of how vulnerable American municipalities remain to digital assaults.

Suisun City, located about 45 miles from San Francisco, declared a state of emergency Saturday after malicious software infiltrated its network shortly before 6 p.m. Friday, the California Post reported.

“Officials shut down the entire network to stop the threat from spreading and protect evidence for a federal investigation,” the outlet reported.

City officials scrambled to prevent the outage from endangering residents, rerouting 911 calls through the Solano County dispatch center. Police and fire personnel remained active and able to respond to calls for service despite the loss of the city’s own systems.

The breach reached well beyond emergency dispatch.

City services including building permits and other municipal records were rendered inaccessible, and residents were unable to pay bills online while the network remained offline.

The Suisun City Council voted unanimously to pull the plug on the network and declare a state of emergency during a special meeting Saturday morning, an extraordinary step that underscores the severity of the threat local officials believed they were facing.

The incident lands amid heightened concern over foreign cyber threats to American infrastructure since the outbreak of the Iran war.

U.S. authorities issued an “urgent warning” in April that hackers linked to Iran’s Islamic Revolutionary Guard Corps were actively working to disrupt critical American computer networks, a threat national security officials have long cautioned could extend to local governments with limited cybersecurity resources.

It remains unclear whether the Suisun City attack is connected to Iran-backed hacking operations.

Investigators are still working to determine how the malicious software breached the network and who is responsible, according to news reports.

City officials have not said when full network functionality is expected to be restored.

Keep reading

California City Pulls Plug on It’s Computer System After Cyberattack

A northern California city of 30,000 people had to disconnect its entire computer network after a cyberattack, idling the municipality’s 911 emergency line for police and fire dispatch.

Officials in the city of Suisun City, located about 45 miles from San Francisco, had to find a workaround for emergency calls and did by forwarding 911 calls to a county dispatch center.

The city declared a state of emergency Saturday after malicious software invaded its computer network and system shortly before 6 p.m. Friday, according to the California Post.

“Officials shut down the entire network to stop the threat from spreading and protect evidence for a federal investigation,” the Post reported.

Despite the attack, Suisun City officials say they found a work around to prevent residents from being put in immediate danger during emergencies.

First responders remain active and dispatched, with city emergency operators routing calls through he Solano County dispatch center.

That way police and fire personnel are able to respond to calls for service,

The attack also disrupted non-emergency city services, including access to municipal records such as building permits and idled residents ability to pay bills online.

The complete shutdown came after the city council voted unanimously to pull the plug and declare a state of emergency at a special meeting Saturday morning.

Cybersecurity for municipalities and infrastructure systems have been in the news during the Iran war after U.S. authorities earlier this year issued an “urgent warning” that hackers backed by the Islamic Revolutionary Guard Corps (IRGC) in Iran were attempting to disrupt American computer networks.

Investigators are still at work in an effort to determine how the malicious software got inside the network and who was behind the attack, according to news reports.

Keep reading

More than 600,000 voter files ripped off Arizona site in 2020 by hacker, but DOJ didn’t prosecute

Arizona’s largest county suffered a significant breach of its election data in the days before the 2020 presidential election when a self-described hacker foiled security and obtained 633,000 voter registration files but the Biden Justice Department and local prosecutors declined to bring charges even after the FBI got the suspect to confess, according to declassified documents made public Thursday by the White House.

The scraping of Maricopa County’s voter registration files was the most flagged security incident in a cyberintrusion log kept by U.S. spy agencies in the days around the Nov. 3, 2020 election, and it caused an extensive FBI investigation that led agents to a home in Fountain Hills, Ariz., the memos show.

The man the FBI confronted admitted he wrote a computer script to exploit the county voter systems security and scraped the files, which included 930 with “sensitive voter information like domestic violence victims, judges and law enforcement officers,” according to the FBI case files declassified and made public by President Donald Trump’s White House Government Transparency Task Force.

FBI Director Kash Patel sent a letter to that task force this week stating the bureau spent “significant resources” but could not get the U.S. Attorney’s Office in Phoenix, the Arizona Attorney General’s Office, the Maricopa County Arizona Attorney’s Office or the Pinal County, Arizona Attorney’s Office to bring charges despite an admission from the alleged hacker.

FBI_Letter.pdf

The U.S. Attorney’s Office declined to prosecute the alleged hacker on July 12, 2021, under the Biden Administration, according to the FBI. The newly released memos do not state when the other prosecutorial agencies made similar decisions not to bring charges,  but the full case was officially closed in 2023.  

Just one day before the Nov. 3 election, the Maricopa County Recorder’s Office submitted a tip through the Arizona Counterterrorism Intelligence Center that there had been “an attempt to scrape voter registration information,” according to one FBI summary. 

FBI_Opening_Doc.pdf

According to that memo, an unidentified intruder gained access to voter registration data on the recorder’s website by using a “Powershell script” that exploited a weakness in security. More than 633,000 voter records were exfiltrated between Oct. 21, 2020, and Nov. 2, 2020, the memos state.

Keep reading

“Nothing Is 100%”: CZ Warns Bitcoin Holders After $89 Million Coldcard Wallet Exploit

A third wave of thefts against Bitcoin wallets built on flawed Coldcard firmware ran through Saturday morning, lifting observed losses to roughly 1,367 BTC – close to $89 million – drained from 4,585 addresses since Thursday.

As Cyberkendra.com reports, the size is not the interesting part. The third wave is the first one designed to be hard to follow, and that shift tells self-custody holders more about what happens next than any dollar figure does.

Galaxy Research published the wave-three findings early Sunday. Between 12:23 UTC on July 31 and 06:42 UTC on August 1, across blocks 960,396 to 960,471, another 207.73 BTC left 1,912 addresses. That is roughly a tenth of a coin per victim.

Wave one, which opened at 01:10 UTC on July 30 and closed 41 minutes later, took 1,082.65 BTC from 1,195 addresses — nearly a full coin each.

Wave two, on July 31, collected just 76.16 BTC from 1,478 addresses.

Median losses tell the same story more bluntly: 0.270 BTC in wave one, 0.010 in wave two, 0.013 in wave three. The operator is now emptying wallets worth a few thousand dollars apiece and still finding enough of them to spend ten hours sweeping.

Waves one and two were easy to map because the attacker made them easy.

Both funneled coins through a handful of shared collector addresses into P2WPKH holding wallets (pay-to-witness-public-key-hash — plain single-key SegWit outputs, fully visible on chain).

Wave three abandoned that.

Each victim’s coins went to their own destination, and the proceeds now sit in 293 separate P2WSH vaults (pay-to-witness-script-hash, a format that keeps its spending conditions hidden until the first time the coins move). The sweeper also batched an average of 6.37 victims per transaction, where wave one took exactly one at a time, and scanned only the default derivation path instead of testing several branches per seed. Even the fee constant changed — 30 sat/vB in wave one, 50 and 10 in wave two, roughly 200 then exactly 10 in wave three.

That is either the same crew rebuilding after being enumerated in public, or a second crew grinding the same broken key space on its own.

The falling average haul suggests the profitable end of the vulnerable key space is picked over. That is cold comfort. Wave three’s median take of 0.013 BTC is the clearest evidence yet that no balance is now small enough to be beneath the scanner’s notice — and the sweeping had not stopped three days in.

Keep reading

Trump: Minnesota’s ‘gross incompetence’ — not Iran — behind water system hacks

President Donald Trump says Minnesota is to blame for a recent cyber-attack against the state’s water system.

While speaking on Friday at his cabinet’s historic Camp David meeting, President Trump called the North Star State’s leadership grossly incompetent after the breach reportedly affected over 30-water systems.

“We heard in ⁠Minnesota there was a cyberattack, ​and they blame it on Iran. ​I don’t think so,” Trump said. 

“I think I blame it on ​Minnesota because they’re grossly incompetent,” he continued.

“I think the governor is behind it,” he said of Minnesota Governor Tim Walz (D-Minn.). “I don’t think there was an Iranian cyberattack.”

His statements follow a New York Times report citing federal investigators who concluded that the cyber incident was likely carried out by Iranian threat actors.

“The tradecraft used, and the absence of a ransom demand, had led analysts to tentatively conclude that it was the work of Iranian hackers,” the Times reports. 

The Federal Bureau of Investigation (FBI) is continuing its investigation into the breach, which authorities say might have affected utilities across at least six other states as well.

Keep reading

MFA Was Supposed to Save Us. Hackers Found a Way Around Human Nature Instead.

For years, cybersecurity experts preached the same gospel. Use a strong password. Don’t reuse it. Turn on multi-factor authentication. The public eventually listened. Banks encouraged it. Social media platforms required it. Employers rolled it out. Even people who still struggle to find the right app on their phone learned that approving a login request was simply part of modern life.

Then the criminals adapted. One of the biggest cybersecurity stories this month revealed an uncomfortable truth about today’s online threats. Hackers are increasingly abandoning attempts to break multi-factor authentication. Instead, they’re simply waiting for people to complete it for them.

It’s a remarkably effective scam because it exploits something technology has never been very good at defending: human trust. The fake login page looks real. The text message appears legitimate. The authentication request pops up exactly as users expect. The victim enters their password, approves the prompt, and unknowingly grants attackers full access.

The security worked perfectly. The person didn’t. That’s why this latest wave of attacks should concern everyone, not just IT departments.

America is still catching up to cybersecurity basics while cybercriminals are already operating several chapters ahead. Millions of people only recently became comfortable using MFA. They don’t necessarily understand what it’s doing. They simply know they’ve been told it’s safer.

That knowledge gap has become an opportunity. Older Americans have become especially attractive targets. They bank online, manage retirement accounts digitally, schedule doctor appointments through patient portals, and increasingly rely on smartphones for everyday life. Many learned these habits out of necessity rather than curiosity, making them more vulnerable to sophisticated social engineering attacks designed to look routine.

Criminals know exactly who they’re looking for. This is no longer the stereotype of a teenager in a basement writing viruses for fun. Today’s cybercrime industry operates like a multinational business. It studies psychology, customer behavior, and user habits with the same precision legitimate companies use to improve marketing campaigns.

The objective isn’t always to outsmart the software. It’s to outsmart the person sitting behind the keyboard. Even Washington is acknowledging the stakes are getting higher. The Trump administration recently announced a new initiative to aggressively identify cybersecurity vulnerabilities tied to artificial intelligence before hostile actors can exploit them. If the federal government believes emerging technology demands an entirely new level of vigilance, it’s hard to argue that everyday consumers are somehow insulated from the same risks. If anything, they’re more exposed. 

Keep reading

CISA: Windows BlueHammer flaw now exploited by ransomware gangs

CISA confirmed on Monday that ransomware gangs have begun exploiting a high-severity Microsoft Defender privilege escalation vulnerability that has previously been abused in zero-day attacks.

Dubbed BlueHammer, the security flaw (CVE-2026-33825) was leaked by a security researcher known as “Nightmare Eclipse” in early April, together with proof-of-concept exploit code, in protest at how the Microsoft Security Response Center (MSRC) handles the disclosure process.

“Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally,” Microsoft explains in a security advisory.

Will Dormann, principal vulnerability analyst at Tharros, told BleepingComputer in April that while the issue is not easy to exploit, it gives local attackers access to the Security Account Manager (SAM) database, which contains password hashes for local accounts.

With this access, they can escalate to SYSTEM privileges and potentially take complete control of the targeted system.

“At that point, [the attackers] basically own the system, and can do things like spawn a SYSTEM-privileged shell,” Dormann said.

Keep reading