30-YR FIXED6.71% +0.0515-YR FIXED6.04% +0.0610-YR TREASURY4.79% +0.0430-YR TREASURY5.27% +0.025-YR TREASURY4.55% +0.062-YR TREASURY4.39% +0.05FED FUNDS3.75% 0.00SOFR3.65% -0.01DOW53,062 +295S&P 5007,667 +35Freddie Mac · U.S. Treasury · Federal Reserve via FRED®30-YR FIXED6.71% +0.0515-YR FIXED6.04% +0.0610-YR TREASURY4.79% +0.0430-YR TREASURY5.27% +0.025-YR TREASURY4.55% +0.062-YR TREASURY4.39% +0.05FED FUNDS3.75% 0.00SOFR3.65% -0.01DOW53,062 +295S&P 5007,667 +35Freddie Mac · U.S. Treasury · Federal Reserve via FRED®
Thursday, September 3, 2026Bay Area Market: Coverage updated daily

DOJ, FBI say China-backed hackers breached Fed, other US agencies

Court docs tie QTFY group to multiagency cyber breaches

San Francisco Bay Area homes and neighborhoods
Curated News BriefBased on original reporting by HousingWire (August 26, 2026). The summary below is the Journal’s; the local analysis is original commentary by Omar Murillo.

According to HousingWire, the Department of Justice and FBI have taken action against what they say is a Chinese state-sponsored hacking group. The operation involved seizing internet domains that were being used by tools called QScan and QTRouter, which prosecutors allege were operated by a group named QTFY and connected to a company in Nanjing, China. By shutting down these domains, federal authorities have essentially disabled the malware platforms that the hackers were relying on.

These hacking tools were sophisticated operations designed to breach sensitive U.S. government networks and critical infrastructure. According to court documents unsealed in Southern California, the targets included major agencies like the Federal Reserve, NASA, the Department of Energy, and several other federal entities including the U.S. Senate. The tools worked by scanning and infecting thousands of internet-connected devices worldwide, which were then incorporated into a network that allowed the hackers to hide the true origin of their attacks.

What made QTRouter particularly useful to the hackers was that it functioned as what prosecutors call an "obfuscation network." Essentially, it masked where the cyberattacks were actually coming from by routing traffic through compromised devices scattered around the world, sometimes positioned near the targeted networks themselves. This made it look like attacks were originating from legitimate systems rather than from China. The DOJ and FBI believe QTFY offered these hacking services to customers including Chinese state security agencies and the People's Liberation Army.

Attorney General Todd Blanche characterized the action as part of a broader push to dismantle foreign-sponsored hacking campaigns threatening American infrastructure. The seizure was effective because the domains that authorities took over were hard-coded into both malware tools, meaning they were essential for the systems to communicate and function. Once those domains were gone, the platforms essentially stopped working.

What I am seeing locally here in the Bay Area is that cybersecurity concerns continue to affect how businesses and institutions operate, particularly when it comes to protecting sensitive data and maintaining trust. For real estate professionals and our clients, these kinds of breaches at federal agencies and critical infrastructure remind us how important it is to stay vigilant about protecting our own digital assets and personal information in every transaction we handle.