BlockBriefe
Market

FBI Seizes Domains Used by China-Linked Hackers to Scan US Targets

Daniel Harper 26.08.2026

How the Hacking Network Operated

US federal agencies have dismantled a significant cyber infrastructure operated by a Chinese state-sponsored hacking group. The Federal Bureau of Investigation and the Department of Justice acted swiftly to shut down two primary hacking platforms. Officials seized three critical internet domains that served as the operational backbone for the network. This coordinated effort marks a major step in disrupting advanced persistent threats targeting American institutions.

The operation targeted a sophisticated network capable of scanning millions of US-based systems. By controlling these specific web addresses, the attackers could launch widespread reconnaissance missions. The seized domains allowed the group to identify vulnerabilities across government agencies, financial sectors, and private enterprises. This disruption aims to blind the hackers, forcing them to rebuild their digital foothold before launching new attacks.

The investigation revealed that the group used these platforms to conduct extensive network scanning. Their tools probed for open ports and unpatched software across the United States. Once vulnerabilities were identified, the hackers deployed malware to gain initial access. The infrastructure supported both offensive operations and long-term surveillance campaigns. Authorities noted that the network’s scale allowed it to monitor a vast array of potential targets simultaneously.

Why This Shutdown Matters for Cybersecurity

NASA and the Federal Reserve were among the prominent organizations compromised by this group. Hundreds of other entities, including defense contractors and healthcare providers, also fell victim to the intrusion. The hackers exploited misconfigured services and weak credentials to breach perimeters. Once inside, they moved laterally through internal networks to steal sensitive data. The seizure of the domains cuts off the primary command-and-control channels used by the intruders.

This action highlights the escalating intensity of US efforts to counter state-sponsored cyber threats. The government is increasingly moving beyond reactive measures to proactively dismantle attacker infrastructure. By seizing the domains, investigators hope to preserve evidence for future legal proceedings. The move also signals to other foreign adversaries that their digital assets are vulnerable to seizure.

Frequently Asked Questions

Experts suggest that while the immediate threat is reduced, the group will likely adapt. Attackers often maintain backup servers or alternative communication methods. However, losing the primary hubs forces a costly and time-consuming reconstruction process. This window of opportunity allows US defenders to patch exposed systems and strengthen their defenses. The collaboration between the FBI and DOJ demonstrates a unified approach to tackling complex cyber operations.

Which specific organizations were affected by this hacking campaign? NASA and the Federal Reserve were confirmed victims of the intrusion. Additionally, hundreds of other US organizations, including various government agencies and private companies, suffered breaches through the same network.

What did the FBI actually seize during the operation? Authorities seized three internet domains that hosted the core hacking platforms. These domains functioned as the central control points for the group’s scanning and attack tools.

Share:

More stories: