Washington Unveils Eight-Year Chinese Cyber Intrusion Spanning NASA, the Senate, and Critical Infrastructure
Sandego.net – On Wednesday, senior US government officials pulled back the curtain on what they describe as a sprawling Chinese cyber-espionage operation that ran from 2018 through 2026, touching some of the most sensitive institutions in American public life. The campaign, they say, reached into NASA, the Federal Reserve, the Department of Justice, the Department of Energy, and the US Senate itself, while also probing military networks, hospital systems, power utilities, and defense contractors.
The disclosure marks one of the broadest public admissions yet that foreign actors have maintained persistent footholds inside networks considered foundational to national security and economic stability. Officials framed the revelation not as a single incident but as the culmination of a prolonged counterintelligence effort to map and dismantle an operation they characterized as unusually layered in its deception.
How the Intrusion Worked
According to an affidavit filed by an FBI agent in support of court-ordered domain seizures, the hackers were linked to China’s military and intelligence apparatus. Rather than operating openly, they allegedly routed their activity through a commercial technology firm based in Nanjing, using its infrastructure to blend their traffic into ordinary internet flows and to obscure the origin of their probes. The affidavit describes a systematic process of profiling target networks, establishing footholds, and then moving laterally to extract data or position themselves for future operations.
The document distinguishes between organizations that were merely “targeted” and those confirmed as “victims” — meaning successful break-ins had occurred. Among the confirmed victims were three unnamed Department of Energy national laboratories, the National Institutes of Health, and an agency within the Department of Health and Human Services. The Department of Justice, the Federal Reserve, NASA, and the Senate were listed among entities that were targeted, though the affidavit does not confirm whether every one of those targets was fully compromised.
The Nanjing Firm at the Center
The commercial vehicle at the heart of the operation is Nanjing Xinjiuwei Network Technology Company, established in 2018 in the eastern Chinese city of Nanjing. Chinese business records show the firm had 17 employees as of last year. Court filings indicate that among its staff were former members of the People’s Liberation Army, who, per the affidavit, leveraged their PLA connections to secure contracts and subcontracts that supported offensive cyber operations.
US officials said China’s military and its Ministry of State Security directed the company’s services to mask intrusions within the noise of everyday internet traffic. A review of Chinese job-recruitment platforms revealed that the firm had recently posted openings for cybersecurity engineers specifically tasked with “large-scale penetration projects,” suggesting the operation was still being scaled up even as US investigators closed in.
Domain Seizures and the Advisory
To prevent further exploitation, the Department of Justice moved on Wednesday to seize three internet domains tied to the Nanjing company. Separately, federal agencies announced plans to publish a technical advisory detailing the hackers’ methods, giving victim organizations a playbook for identifying and ejecting residual intruders from their own systems.
The full extent of damage remains uncertain. Counterintelligence assessments of what was taken, how long access persisted, and whether any data was exfiltrated to Chinese handlers are expected to stay classified for the foreseeable future.
Beijing’s Response
A spokesperson for the Chinese Embassy in Washington offered a brief statement when asked for comment:
“The Chinese government firmly opposes and combats all forms of cyberattacks in accordance with the law. We urge the US side to stop using cybersecurity issues to smear or discredit China.”
The embassy did not address the specific allegations about the Nanjing firm or the named federal agencies.
A Pattern of Escalating Tension
Wednesday’s announcement lands amid a years-long cycle of accusations and denials over Chinese activity inside American digital infrastructure. In 2023, US officials publicly accused Beijing of probing military transportation networks, water treatment plants, and power companies — targets they argued had no legitimate intelligence value unless the goal was to sabotage a potential US response to a Chinese invasion of Taiwan. China rejected those claims. In 2024, months of scrutiny focused on alleged Chinese infiltration of telecom networks, with then-presidential candidate Donald Trump and running mate JD Vance identified among those whose communications were at risk.
Cybersecurity has functioned as a persistent pressure point in the bilateral relationship, flaring each time a high-profile intrusion surfaces and receding only partially until the next episode.
Political Stakes Ahead of a Xi Visit
The timing of the disclosure is notable: Chinese President Xi Jinping is scheduled to visit the United States next month. Asked on Fox News whether President Trump would raise the latest hacking allegations directly with Xi, Attorney General Blanche declined to preview the conversation:
“I’m not going to tell President Trump what he needs to talk to the leadership about in China.”
She added, with pointed emphasis:
“This is something that we have talked about with our counterparts in China for many, many years. And we know that it’s happening. And they know that we know that it’s happening. And it has to stop.”
What Comes Next
The FBI, alongside what officials described as America’s signals-intelligence apparatus — widely understood to be the National Security Agency — spent months, possibly years, peeling apart the deception architecture that allowed the Nanjing-linked operation to persist undetected. The domain seizures and forthcoming advisory are procedural steps, but the deeper question for affected agencies will be whether residual access points remain in their networks and how quickly they can be neutralized. Until the classified counterintelligence review is complete, the true scope of what was read, copied, or altered inside those institutions will remain unknown to the public.
Related Reading
Frequently Asked Questions
What is US says Chinese hackers hit hospitals?
US says Chinese hackers hit hospitals is the main topic of this guide. The article explains the context, practical details, and next steps readers should understand.
Why does US says Chinese hackers hit hospitals matter?
US says Chinese hackers hit hospitals matters because readers are looking for a useful answer, not just a short summary. Good content should match search intent and help them decide what to do next.

