DOJ Seizes China‑Hacked Domains, Hits NASA, Senate, Fed
The U.S. Justice Department has seized a network of domains linked to Chinese state‑sponsored hackers that targeted NASA, the Senate, and the Federal Reserve. The FBI’s swift action underscores the growing threat of cyber‑espionage against critical infrastructure.
Unmasking the Digital Trojan Horse
On August 25, 2026, the U.S. Department of Justice announced the seizure of a swath of domain names that had been weaponized by Chinese state‑sponsored hackers. The domains, once the backbone of a sprawling espionage campaign, were used to infiltrate the systems of NASA, the U.S. Senate, the Federal Reserve, and other federal entities.
How the Attack Was Unveiled
The FBI’s Cyber Division traced a series of phishing emails and malicious code deployments back to a cluster of compromised domains. These domains, registered in Hong Kong and operated from servers in the People’s Republic of China, served as command‑and‑control hubs for the threat actors.
- Phishing emails masquerading as internal memos were distributed across federal networks.
- Malicious payloads embedded in seemingly innocuous PDFs opened backdoors into mission‑critical systems.
- Once inside, the attackers exfiltrated data and maintained persistence through stealthy lateral movement.
Impact on Federal Institutions
NAVAL, the Senate, and the Federal Reserve all reported breaches that spanned weeks. While the full extent of the data loss remains under investigation, preliminary findings indicate that:
- NASA’s satellite telemetry database was accessed and partially exfiltrated.
- Senate staff email accounts were compromised, enabling credential harvesting.
- Federal Reserve trading algorithms were monitored, raising concerns over financial market stability.
Legal and Technical Ramifications
The DOJ’s seizure of the domains is a rare, high‑profile example of the agency’s use of cyber‑law tools to dismantle infrastructure used by hostile actors. Under the Computer Fraud and Abuse Act, the DOJ can seize and redirect domains that facilitate illicit activity.
Technically, the seizure forces the attackers to abandon their command‑and‑control network, forcing a rapid shift to new infrastructure that is more difficult to detect. This move also signals to other threat actors that the U.S. is willing to take decisive action against digital espionage.
Broader Context: A Growing Threat Landscape
Over the past decade, Chinese state‑sponsored groups such as APT41, APT10, and the “Great Cannon” operation have been linked to a wide array of cyber‑espionage campaigns. The 2026 seizure is the latest in a series of U.S. actions aimed at curbing foreign influence operations.
Cybersecurity experts warn that domain seizure alone is not a silver bullet. Continuous monitoring, threat hunting, and robust incident response plans remain essential for protecting critical infrastructure.