Chinese state-sponsored hackers spent eight years inside some of the most secure networks in the United States — and nobody caught them.
Court documents unsealed Wednesday in California federal court revealed that a hacking group called QTFY, employed by a Chinese technology company with ties to China’s Ministry of State Security and People’s Liberation Army, conducted sustained computer intrusions against the Federal Reserve, the Department of Justice, NASA, the U.S. Senate, the Department of Energy, the National Institutes of Health, hospitals, telecom providers, power companies, and defense contractors.
The hacking began in 2018. It ran continuously through 2026. The Justice Department seized two hacking platforms used in the campaign — QScan and QTRouter — but did not disclose what the hackers actually accessed or took from any of the named targets.
How the Attack Worked
QTFY did not attack its targets directly. It built infrastructure designed to be invisible.
QScan automatically infected thousands of ordinary internet-connected devices — home routers, security cameras, smart home hardware — and conscripted them into a network called QTRouter. That network, layered with commercial proxy services and leased servers spread across multiple countries, routed all malicious traffic through devices that appeared to be in the United States or elsewhere, masking any connection to China.
The result was a distributed attack infrastructure that looked, from inside a target’s network, like ordinary internet traffic. The Federal Reserve, NASA, and the DOJ were all running their security operations against an adversary they could not see clearly for the better part of a decade.
The campaign was not limited to government targets. Hospitals, power companies, telecom providers, and defense contractors were all identified as victims in the court filings — a target list that reflects the full scope of critical American infrastructure QTFY had access to during those eight years.
This Is Not the First Time
Wednesday’s announcement is the latest in a series of disclosures about Chinese state-sponsored hacking of American institutions.
In 2023, U.S. officials accused China of hacking military transportation networks, water treatment plants, and power infrastructure — not to collect intelligence but to pre-position for potential sabotage. In 2024, U.S. phone companies spent months rooting out Chinese infiltration of American telecommunications networks that had reached presidential candidates.
In a separately disclosed case this summer, John Harold Rogers, a former senior adviser to the Federal Reserve Board of Governors, was sentenced to 38 months in prison for making false statements to investigators about sharing restricted information about Federal Reserve monetary policy with Chinese intelligence operatives.
A Chinese spy inside the Fed sharing monetary policy information. A Chinese hacking group inside the Fed’s networks. Both at the same time. For years.
The DOJ’s statement Wednesday made no mention of what QTFY actually obtained from any of its targets. The access has been confirmed. The damage has not been disclosed.
The Question Every Retirement Saver Should Ask
The Federal Reserve has more cybersecurity resources than virtually any private institution in the country. It operates under federal security mandates, employs dedicated security professionals, and answers to congressional oversight. None of that kept QTFY out for eight years.
Your bank is not the Federal Reserve. Your brokerage account is not NASA. The platform holding your 401(k) is not the Department of Justice.
Every dollar in your retirement account exists as a digital entry in a database somewhere. Every transaction is a communication between computers. Every account is accessible through credentials. Wednesday’s court documents confirm that sophisticated state-sponsored hackers can maintain undetected access to the highest-security digital networks in the United States for years at a time.
That does not mean your bank has been hacked. It means the assumption that digital financial systems are categorically secure is one the DOJ’s own filings no longer support.
What Cannot Be Reached
Physical gold held in an insured, audited depository does not exist in any database. It cannot be accessed through a compromised credential or a corrupted router. There is no firmware to exploit, no network connection to hijack, no server to breach.
An ounce of gold stored at Delaware Depository under a client’s account name requires a physical act to move — logged, audited, and insured. QScan and QTRouter cannot reach it. No hacking infrastructure built in Nanjing can touch it.
The primary reasons to hold physical gold in a retirement account are purchasing power preservation, inflation protection, and diversification outside the dollar system. Wednesday’s announcement adds a separate dimension to that case — one that has nothing to do with inflation and everything to do with where the risk in an entirely digital financial life actually sits.
A precious metals IRA holds physical gold and silver inside a tax-advantaged retirement account using funds already in a 401(k) or traditional IRA, without triggering a taxable event during the rollover. It does not replace the digital financial system. It provides a portion of retirement wealth that exists entirely outside it.
The hackers were inside the Federal Reserve for eight years. What they took, the DOJ has not said. What physical gold in a vault cannot give them — regardless of how long they are inside any network — does not require a firewall to be true.
The Federal Reserve Got Hacked for 8 Years – Is Your Bank Next?
Chinese state-sponsored hackers spent eight years inside some of the most secure networks in the United States, and nobody caught them. What they took has not been disclosed.
Chinese state-sponsored hackers spent eight years inside some of the most secure networks in the United States — and nobody caught them.
Court documents unsealed Wednesday in California federal court revealed that a hacking group called QTFY, employed by a Chinese technology company with ties to China’s Ministry of State Security and People’s Liberation Army, conducted sustained computer intrusions against the Federal Reserve, the Department of Justice, NASA, the U.S. Senate, the Department of Energy, the National Institutes of Health, hospitals, telecom providers, power companies, and defense contractors.
The hacking began in 2018. It ran continuously through 2026. The Justice Department seized two hacking platforms used in the campaign — QScan and QTRouter — but did not disclose what the hackers actually accessed or took from any of the named targets.
How the Attack Worked
QTFY did not attack its targets directly. It built infrastructure designed to be invisible.
QScan automatically infected thousands of ordinary internet-connected devices — home routers, security cameras, smart home hardware — and conscripted them into a network called QTRouter. That network, layered with commercial proxy services and leased servers spread across multiple countries, routed all malicious traffic through devices that appeared to be in the United States or elsewhere, masking any connection to China.
The result was a distributed attack infrastructure that looked, from inside a target’s network, like ordinary internet traffic. The Federal Reserve, NASA, and the DOJ were all running their security operations against an adversary they could not see clearly for the better part of a decade.
The campaign was not limited to government targets. Hospitals, power companies, telecom providers, and defense contractors were all identified as victims in the court filings — a target list that reflects the full scope of critical American infrastructure QTFY had access to during those eight years.
This Is Not the First Time
Wednesday’s announcement is the latest in a series of disclosures about Chinese state-sponsored hacking of American institutions.
In 2023, U.S. officials accused China of hacking military transportation networks, water treatment plants, and power infrastructure — not to collect intelligence but to pre-position for potential sabotage. In 2024, U.S. phone companies spent months rooting out Chinese infiltration of American telecommunications networks that had reached presidential candidates.
In a separately disclosed case this summer, John Harold Rogers, a former senior adviser to the Federal Reserve Board of Governors, was sentenced to 38 months in prison for making false statements to investigators about sharing restricted information about Federal Reserve monetary policy with Chinese intelligence operatives.
A Chinese spy inside the Fed sharing monetary policy information. A Chinese hacking group inside the Fed’s networks. Both at the same time. For years.
The DOJ’s statement Wednesday made no mention of what QTFY actually obtained from any of its targets. The access has been confirmed. The damage has not been disclosed.
The Question Every Retirement Saver Should Ask
The Federal Reserve has more cybersecurity resources than virtually any private institution in the country. It operates under federal security mandates, employs dedicated security professionals, and answers to congressional oversight. None of that kept QTFY out for eight years.
Your bank is not the Federal Reserve. Your brokerage account is not NASA. The platform holding your 401(k) is not the Department of Justice.
Every dollar in your retirement account exists as a digital entry in a database somewhere. Every transaction is a communication between computers. Every account is accessible through credentials. Wednesday’s court documents confirm that sophisticated state-sponsored hackers can maintain undetected access to the highest-security digital networks in the United States for years at a time.
That does not mean your bank has been hacked. It means the assumption that digital financial systems are categorically secure is one the DOJ’s own filings no longer support.
What Cannot Be Reached
Physical gold held in an insured, audited depository does not exist in any database. It cannot be accessed through a compromised credential or a corrupted router. There is no firmware to exploit, no network connection to hijack, no server to breach.
An ounce of gold stored at Delaware Depository under a client’s account name requires a physical act to move — logged, audited, and insured. QScan and QTRouter cannot reach it. No hacking infrastructure built in Nanjing can touch it.
The primary reasons to hold physical gold in a retirement account are purchasing power preservation, inflation protection, and diversification outside the dollar system. Wednesday’s announcement adds a separate dimension to that case — one that has nothing to do with inflation and everything to do with where the risk in an entirely digital financial life actually sits.
A precious metals IRA holds physical gold and silver inside a tax-advantaged retirement account using funds already in a 401(k) or traditional IRA, without triggering a taxable event during the rollover. It does not replace the digital financial system. It provides a portion of retirement wealth that exists entirely outside it.
The hackers were inside the Federal Reserve for eight years. What they took, the DOJ has not said. What physical gold in a vault cannot give them — regardless of how long they are inside any network — does not require a firewall to be true.
Shield Your Retirement With Our FREE Wealth Preservation Guide
Related Market News
More analysis on gold, inflation, and the forces reshaping global wealth — from the Priority Gold research desk.
Bonds Just Hit 5% – Your Retirement Should Pay Attention
Most Americans with retirement accounts have been told the same thing for decades. Keep some money in stocks for growth. Keep some in bonds for safety. When stocks go down, bonds go up. That balance is what protects you.
A Former CIA Adviser Just Called $10,000 Gold – Trump Agreed
Jim Rickards expects $10,000 gold before the end of 2026—a bold forecast recently shared by Donald Trump. Here is the analysis behind the claim.
Gold IRA Required Minimum Distributions: Everything You Need to Know
RMDs are a predictable obligation, but satisfying one from an account holding physical metal works differently than selling a stock. Here is the timing, the math, and the strategies.