FBI: China-backed hacking network targeted US hospital systems

Advertisement

The FBI and Justice Department seized internet domains used by a China state-sponsored hacking network that breached hospital systems, power companies and federal agencies, according to an affidavit unsealed Aug. 26 in the Southern District of California.

The group, known as QTFY, ran a global botnet of hacked devices to disguise its intrusions, Brett Leatherman, the FBI’s top cyber official, told The Wall Street Journal. Mr. Leatherman said the actors had been observed targeting “our largest power companies, largest hospital systems” as well as U.S. election systems.

The affidavit names NASA, the Federal Reserve, the Department of Energy, the Justice Department, HHS, NIH and, in 2026, the U.S. Senate as federal victims. It states QTFY’s other targeted networks include those of hospitals, telecommunications providers, power companies, financial institutions and defense contractors, dating to at least 2018.

Court filings describe an August 2020 incident in which an unnamed Ohio facility, identified only as “Medical Center 1,” reported that QTFY was exploiting a Pulse Secure VPN vulnerability, CVE-2019-11510 — the same flaw used against NASA in August 2019. The hospital’s complaint, relayed by Hostwinds — whose IP address the attacker was using — to the hackers, stated: “Attacking healthcare in a pandemic is just wrong.”

Prosecutors tied QTFY to Nanjing Xinjiuwei Network Technology Company, which they say sold hacking services to China’s Ministry of State Security and People’s Liberation Army. The seizure follows three prior U.S. disruptions of Chinese state-sponsored botnet infrastructure since 2023 and adds to mounting evidence that hospitals remain a persistent target for state-linked network intrusions exploiting unpatched VPN and remote-access systems.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement