DOJ seizes 2 platforms used by China-supported hackers

Photo: Abderrahmane Habibi / Pexels

By New Way News Newsroom, National Desk — Published August 27, 2026

Table of Contents

The Department of Justice has taken down two digital platforms allegedly used by Chinese government-backed hackers to infiltrate U.S. federal agencies and critical infrastructure. The seizure represents one of the most aggressive federal responses yet to persistent cyber threats emanating from Beijing. According to multiple reports, the DOJ and FBI coordinated to seize domains tied to sophisticated hacking tools that had been targeting American government systems.

The platforms in question enabled what security experts describe as advanced persistent threat operations. Federal authorities shut down these China-sponsored hacking tools after determining they posed an ongoing risk to national security. The action signals a more proactive stance by the federal government in combating state-sponsored cyber intrusions.

This enforcement action comes amid escalating tensions over digital espionage between Washington and Beijing. The seized platforms reportedly facilitated unauthorized access to sensitive federal networks, raising alarm bells across defense and intelligence communities about the vulnerability of critical government infrastructure.

Key Takeaways

  • The Department of Justice and FBI seized two platforms used by China-backed hackers targeting U.S. federal agencies
  • The hacking tools were specifically designed to infiltrate government systems and critical infrastructure
  • This represents a coordinated federal response involving multiple law enforcement and intelligence agencies
  • The platforms seized were domains tied to sophisticated Chinese state-sponsored cyber operations
  • Federal authorities characterized the threat as targeting national security and government operations
  • The action demonstrates increased U.S. willingness to directly disrupt foreign cyber capabilities

The Background & Context

Chinese state-sponsored hacking has been a persistent concern for American security officials for more than a decade. Unlike opportunistic cybercriminals seeking financial gain, these operations typically pursue long-term intelligence gathering and strategic advantage. The tools seized by federal authorities represent the infrastructure that enables such campaigns.

Hacking platforms of this nature function as command-and-control systems. They allow operators to maintain persistent access to compromised networks, exfiltrate data, and deploy additional malicious software. When the federal government seizes platforms used by foreign intelligence services, it disrupts ongoing operations and forces adversaries to rebuild their capabilities from scratch.

The targeting of federal agencies is particularly concerning. Government networks contain classified information, personnel records, and operational details that foreign intelligence services prize highly. Previous Chinese cyber operations have compromised millions of federal employee records and stolen terabytes of sensitive data from defense contractors and research institutions.

Domain seizures require coordination between law enforcement, intelligence agencies, and sometimes private sector partners. The FBI typically works with domain registrars and hosting providers to take control of malicious infrastructure. This technical operation is paired with legal authority, usually obtained through sealed warrants that demonstrate probable cause the domains were used in criminal activity.

The timing of this action is significant. It comes as the United States faces what many security professionals describe as an unprecedented volume and sophistication of cyber threats from nation-state actors. China, Russia, Iran, and North Korea all maintain robust offensive cyber programs targeting American interests. The decision to publicly announce domain seizures sends a message about attribution and consequences.

Why This Matters

For ordinary Americans, the abstract concept of “cyber threats” can feel distant from daily life. But the reality is far more immediate. Federal agencies that were targeted manage everything from Social Security benefits to veterans’ healthcare, from agricultural subsidies to disaster relief. When these systems are compromised, the potential for disruption extends to millions of citizens who depend on government services.

The defense implications are equally serious. Hackers targeting federal networks often seek information about military capabilities, weapons systems, and strategic planning. Successful intrusions can compromise operational security and give adversaries insights that undermine American military advantage. Taxpayers invest hundreds of billions annually in defense; protecting that investment requires securing the digital infrastructure where much defense work now occurs.

There’s also an economic dimension. Chinese cyber espionage has long targeted American intellectual property, trade secrets, and proprietary research. When hacking tools successfully penetrate federal research agencies or grant-making institutions, they can access cutting-edge scientific work funded by public dollars. This represents both a national security concern and an economic competitiveness issue.

The Supreme Court and federal judiciary have increasingly grappled with questions about government authority in cyberspace. Domain seizures raise complex jurisdictional questions when infrastructure is hosted overseas or involves international actors. The legal frameworks governing these operations continue to evolve, setting precedents that will shape how democracies respond to authoritarian cyber aggression.

Perhaps most fundamentally, this matters because it tests whether open democratic societies can effectively defend themselves against closed authoritarian regimes that face no domestic accountability for aggressive cyber operations. The outcome of that contest will help determine the balance of power in the 21st century.

Reactions & Analysis

The Department of Justice has made cyber threats from nation-state actors a top priority in recent years. Federal prosecutors have brought numerous indictments against Chinese military and intelligence officers for hacking operations, though extradition remains unlikely. These cases serve partly as deterrence and partly as public attribution that names and shames specific individuals and units.

The FBI’s role in these operations extends beyond traditional law enforcement. The bureau now functions as a hybrid domestic intelligence and cyber defense organization, working closely with the Cybersecurity and Infrastructure Security Agency and National Security Agency to identify and disrupt threats. This interagency cooperation is essential because no single agency possesses all the technical capabilities, legal authorities, and intelligence needed to counter sophisticated state actors.

Security researchers who track Chinese hacking groups likely provided critical intelligence that enabled this seizure. Private cybersecurity firms often detect intrusions before government agencies do, creating a partnership model where threat intelligence flows between sectors. The domains seized probably appeared in threat reports that detailed their use in specific campaigns against federal targets.

Congressional oversight committees have pressed executive branch agencies to take more aggressive action against foreign cyber threats. Lawmakers from both parties have expressed frustration that adversaries face insufficient consequences for digital intrusions. This seizure may partially address those concerns, though critics argue much more needs to be done to impose costs on hostile nations.

China has historically denied involvement in cyber espionage against the United States, characterizing such accusations as politically motivated. Beijing typically responds to these actions by claiming it too is a victim of cyber attacks and calling for international cooperation on cybersecurity. The diplomatic dance around cyber operations remains delicate, as both nations maintain extensive digital espionage capabilities.

What Happens Next

Domain seizures are tactical victories, not strategic solutions. The hackers who relied on these platforms will likely rebuild their infrastructure using different domains and hosting providers. The cat-and-mouse game of offensive cyber operations and defensive responses will continue. However, disruption imposes costs and forces adversaries to expend resources rebuilding what was lost.

Federal agencies targeted in these operations now face the painstaking work of forensic investigation. Security teams must determine the full scope of compromise: what data was accessed, what systems were affected, and whether any backdoors remain. This process can take months or years, and agencies may never know the complete extent of what was stolen.

Expect additional indictments and sanctions targeting individuals and organizations involved in these hacking operations. The Justice Department has shown willingness to name specific Chinese military units and intelligence officers in charging documents. While these individuals will likely never stand trial in American courts, the public attribution serves important diplomatic and deterrent purposes.

Congress may use this incident to push for additional cybersecurity funding and authorities. Legislation mandating faster threat information sharing between agencies, stronger security standards for federal contractors, and enhanced penalties for cyber intrusions could gain momentum. The challenge will be balancing security needs against privacy concerns and bureaucratic efficiency.

The broader U.S.-China relationship will continue to feature cyber operations as a major point of contention. Trade negotiations, diplomatic engagement, and military-to-military contacts all occur in the shadow of ongoing digital espionage. Whether the two nations can establish meaningful norms around acceptable cyber behavior remains an open question with profound implications for global stability.

Frequently Asked Questions

What exactly did the DOJ seize in this operation?

The Department of Justice seized control of two digital platforms—specifically domain names—that Chinese government-backed hackers were using to conduct cyber operations against U.S. federal agencies. These domains functioned as infrastructure that enabled hackers to maintain access to compromised systems and carry out espionage activities. By seizing the domains, federal authorities disrupted the hackers’ ability to use these specific tools.

How does a domain seizure actually stop hackers?

When law enforcement seizes a domain, they take control of the web address away from the malicious actors. This breaks the connection between the hackers and any systems they had compromised using that domain. Infected computers can no longer communicate with the hackers’ command-and-control servers. While sophisticated attackers can establish new infrastructure, the seizure forces them to rebuild their operations and alerts defenders that their networks may be compromised.

Were any specific federal agencies named as victims?

The available reports indicate that federal agencies were targeted but do not specify which particular departments or agencies were affected. Government cybersecurity incidents often remain classified or are disclosed with limited detail to avoid revealing the full extent of compromise to adversaries. Federal authorities typically balance public transparency against operational security concerns when announcing these actions.

Can individual Americans be affected by hacks targeting federal agencies?

Yes, absolutely. Federal agencies maintain vast databases of personal information on citizens, including Social Security numbers, tax records, security clearances, and health information for veterans and federal employees. When these agencies are compromised, that personal data can be stolen and potentially used for identity theft, espionage recruitment, or other malicious purposes. Previous Chinese hacks of federal systems compromised personal information on millions of Americans.

The seizure of these hacking platforms marks a significant moment in the ongoing digital conflict between the United States and China. While two domains may seem like a small victory in a vast cyber landscape, each disruption matters. It demonstrates federal resolve, imposes costs on adversaries, and buys time for defenders to strengthen their systems. The fight to secure America’s digital infrastructure continues, one seized domain at a time.

Sources

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Recent

Weekly Wrap

Trending

You may also like...

RELATED ARTICLES