NFA
NO FILTER AMERICA
Truth · Freedom · Accountability
Investigation

GHOST IN THE GRID

GHOST IN THE GRID
By No Filter America InvestigationsPublished: August 30, 2026Sources: UNITED STATES

Inside China's Eight-Year Cyber War on America's Power System

They Called It "Cyber-Positioning." For Eight Years, They Were Already Inside. Then the FBI Pulled the Plug.

On August 26, 2026, federal agents seized the digital infrastructure of a Chinese state-sponsored hacking network that had spent nearly a decade quietly working its way into America's power grid, its national laboratories, its hospitals, and its Senate. This is not a story about left and right. This is a story about what happens when the lights could go out — and who was standing at the switch.

Share This Investigation

If this investigation was useful, help others discover it by sharing.

Evidence & Documents (3)
Exhibit AOfficial Government Publication
Declaring a National Emergency to Secure the United States Bulk-Power System – The White HouseOpen Document
Exhibit BOfficial Government Publication
Cyber ThreatOpen Document
Exhibit CDOJ Records
Office of Public Affairs Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure United States Department of JusticeOpen Document
All facts in this report are sourced from the official DOJ press release (Office of Public Affairs, Press Release #26-972), the 36-page Joint Cybersecurity Advisory JCSA-20260826-01 co-authored by the FBI, NSA, and Cyber National Mission Force, and the full text of Executive Order 14420 as published by the White House. This is a national security story, not a partisan one — no left, no right, only the documented federal record. No filter.
01  ·  The Warning We Already Lived Through
The Lights Went Out Once Before.
New York City. July 13, 2019.

Seven years before the federal government would declare a national emergency over the security of the American power grid, New York City got a preview of what a large-scale power failure actually looks like. On the night of July 13, 2019, a transformer relay failure at a Consolidated Edison substation knocked out electricity across a large swath of Manhattan's West Side. It was not a cyberattack — it was a mechanical and equipment failure. But the images from that night are the most honest illustration available of exactly the scenario security officials now say foreign state hackers have spent years trying to engineer on purpose.

Subway stations went dark. Times Square's billboards went black. Tens of thousands of people were stranded in the summer heat, evacuated from hotels, guided by cell phone flashlights through unlit streets. It lasted for hours across multiple neighborhoods before power was restored. New York had the resources to recover quickly. The federal government's warning in 2026 is that a foreign adversary embedded inside the bulk-power system could trigger something far larger — and far harder to fix.

Dark subway station during 2019 NYC blackout
JULY 13, 2019 — NYC SUBWAY: An entrance to the C and E trains at the 50th Street Subway Station sits dimly lit during the citywide blackout. Photo: Michael Owens/AP. This outage was caused by an equipment failure — not a cyberattack — but it shows precisely the kind of disruption security officials warn a coordinated grid intrusion could cause.
Times Square billboards dark during 2019 blackout
JULY 13, 2019 — TIMES SQUARE: Times Square's famous billboards sit black as crowds fill the streets below. Photo: Thomas Urbain/AFP/Getty Images. The 2019 outage had a mechanical cause, but it remains the clearest real-world image of what officials now say foreign cyber actors have spent years positioning themselves to cause deliberately.
Crowds on dark street near Times Square during 2019 blackout
JULY 13, 2019: People walk along a dark street near Times Square during the blackout. Photo: Jeenah Moon/Reuters.
People evacuated outside hotel during 2019 NYC blackout
JULY 13, 2019: People are evacuated outside the Row NYC hotel as the blackout stretches into the night. Photo: Jeenah Moon/Reuters.
02  ·  The Discovery
Meet QTFY.
China's Hackers-for-Hire.

QTFY is the name federal investigators gave to a Chinese state-sponsored hacking group that had been operating since at least 2018. According to the joint FBI/NSA/Cyber National Mission Force advisory, QTFY is attributed to Nanjing Xinjiuwei Network Technology Co. (XJW) — a China-based "enabling company" that provides cyber operations services on behalf of the People's Republic of China. XJW maintained business relationships with units of China's Ministry of State Security and with larger private Chinese cyber-enabling firms specializing in critical infrastructure targeting.

According to the DOJ, QTFY "offers computer hacking services to its paying customers, including the PRC's Ministry of State Security and the People's Liberation Army." QTFY's own operatives include former members of the PLA. The group participated in China-based freelance hacker marketplaces — buying and selling exploits and network access like commodities — and took part in official Chinese "network attack and defense" exercises against Chinese critical infrastructure, using those exercises to sharpen the very tools later turned against the United States.

Flag of the People's Republic of China
BEIJING: The flag of the People's Republic of China. Federal investigators say the hacking group QTFY operated on behalf of China's Ministry of State Security and People's Liberation Army — state institutions that answer to the Chinese government.

QTFY did not act alone. The advisory documents its relationships with a web of Chinese entities across multiple provinces: Unit 0718, an MSS unit tied to the Salt Typhoon hacking campaign; Unit 9086, an MSS unit in Guangxi Province with past contracts to the cyber intrusion firm i-Soon; Bozhi Security Technology, which bid on power-system vulnerability projects for China's National University of Defense Technology; and Fujian Ares Network Technology, which won multiple military contracts for radio frequency hardware. This was not one rogue actor. It was a functioning ecosystem.

03  ·  Eight Years of Targets
NASA. The Fed. The Senate.
The Targeting Timeline.

The federal advisory lays out nearly a decade of documented QTFY activity against American systems — a slow, patient campaign of scanning, probing, and, in several confirmed cases, successful intrusion.

  • May 2018
    Vulnerability scanning of the U.S. Department of Energy (unsuccessful access attempt)
  • July 2019
    Vulnerability scanning of a U.S. election system (unsuccessful)
  • August 2019
    Exploited a Pulse Secure VPN vulnerability against the Department of Justice, the Federal Reserve, and NASA
  • August 2020
    Abuse complaint filed after a Pulse SSL VPN attack on a healthcare entity — the victim wrote: "Attacking healthcare in a pandemic is just wrong"
  • 2021
    Installed Remote Access Trojans on Taiwan's energy sector systems
  • June 2021
    Vulnerability scanning of a U.S. children's hospital (unsuccessful)
  • May 2024
    Used the QScan platform to scan U.S. power and telecommunications companies — exfiltrated data from over 300 organizations worldwide, including U.S. defense contractors, financial institutions, and universities
  • September 2024
    Used zero-day exploits against three U.S. Department of Energy National Laboratories, the National Institutes of Health, the Health Resources and Services Administration, and a U.S. security device manufacturer
  • March 2025
    Vulnerability scanning of a U.S. power company (unsuccessful)
  • February 2026
    Exploited a BeyondTrust vulnerability against a U.S. state government; also targeted a U.S. water district
  • March 2026
    Vulnerability scanning of the United States Senate and a U.S. hospital system (unsuccessful)
  • June 2026
    Used QScan for vulnerability scanning of a U.S. election system (unsuccessful)
  • August 26, 2026
    FBI and DOJ seize QScan and QTRouter — platforms rendered inoperable
04  ·  The Machine
130 Countries. One Invisible Network.
How QScan and QTRouter Worked.

QTFY's operation ran on two connected platforms. QScan was the reconnaissance and exploitation engine — a distributed scanning system so large that on a single day in 2024, it processed over two million scanning and penetration-testing tasks. It carried a library of more than 200 proof-of-concept exploits, actively hunting for weaknesses in power companies, telecommunications firms, defense contractors, universities, and local governments around the world.

QTRouter was the mask. It functioned as an obfuscation network — a web of compromised home routers, smart devices, commercial proxy servers, and leased virtual servers spanning more than 130 countries. By routing their traffic through thousands of hijacked devices that belonged to ordinary people and businesses with no idea they'd been conscripted, QTFY's hackers could make their attacks on American power companies appear to originate from almost anywhere except China.

Behind both platforms sat three botnet-management systems the FBI identified: "Proxy Platform Management," the "Proxy Pool Management System," and "QTBotnet" — a full-featured control system capable of launching distributed denial-of-service attacks and executing remote commands on thousands of hijacked devices simultaneously. The advisory notes that QTFY has also been "heavily researching and integrating AI into their processes over the last two years" — meaning the machine was getting smarter even as investigators closed in.

Power grid monitoring control room with large display wall
WHAT THEY WERE TARGETING: A power grid control room, the kind of facility federal investigators say QTFY spent years probing for weaknesses — where a compromised network could translate directly into control over the physical flow of electricity.
Second power grid monitoring room with operator at workstation
INSIDE THE NERVE CENTER: A grid operator monitors live transmission data. These are the systems the Executive Order 14420 rules are designed to protect from foreign-made equipment carrying hidden digital backdoors.
05  ·  The Takedown
August 26, 2026.
The FBI Pulls the Plug.

Court documents unsealed in the Southern District of California detailed how federal investigators obtained authorization to seize the domains QTFY relied on. Because those domains were hard-coded directly into both the QScan and QTRouter malware — used for essential functions like communication and authentication — the seizure didn't just disrupt the network. It made both platforms completely inoperable in a single stroke.

This was not an isolated action. The DOJ press release places it in a documented pattern of recent U.S. operations against Chinese state-sponsored hacking infrastructure: in 2023, the FBI disrupted a botnet used by the group Volt Typhoon; in 2024, it disabled a botnet of hundreds of thousands of devices tied to Flax Typhoon; in 2025, it removed PlugX surveillance malware from over 4,000 U.S. computers infected by Mustang Panda. QTFY is the latest name on that list.

"These tools were used by PRC cyber actors to hide the origin of their attacks. Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down."
— FBI Director Kash Patel — August 26, 2026
"State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise."
— Attorney General Todd Blanche
"These court-authorized seizures deny PRC-linked hackers access to tools they use to mount online attacks against our Nation's critical infrastructure."
— John A. Eisenberg, Assistant Attorney General for National Security
"We're taking the fight to PRC sponsored cybercriminals to protect the critical services Americans rely on every day."
— Adam Gordon, U.S. Attorney for the Southern District of California
06  ·  The Same Day
Executive Order 14420.
A National Emergency, Declared in Real Time.

Within hours of the FBI announcing the QTFY takedown, the President signed Executive Order 14420, formally declaring a national emergency to secure the United States bulk-power system. The order does not name China outright in every clause, but its language leaves little ambiguity — it targets equipment "designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of a Covered Foreign Entity," with officials confirming the primary focus is China.

The order prohibits the acquisition, importation, transfer, or installation of foreign-produced bulk-power equipment — transformers, grid-connected inverters, battery storage systems, circuit breakers, industrial control systems — wherever that equipment "poses an undue risk of sabotage, subversion, unauthorized access, malicious remote action, or supply disruption." It gives the Secretary of Energy 120 days to publish concrete rules identifying high-risk equipment already installed on American soil and to decide, case by case, whether it must be isolated, monitored, or physically removed.

Direct From the Executive Order
"Certain foreign actors are increasingly creating and exploiting vulnerabilities in the United States bulk-power system, which provides the electricity that supports our national defense, vital emergency services, critical infrastructure, and economy... such equipment might have digital backdoors built into their systems that allow a foreign country to access that equipment remotely."

— Executive Order 14420, Section 1, signed by President Donald J. Trump, August 26, 2026
07  ·  The Real Fear
"Cyber-Positioning."
Not Theft. Preparation.

Security officials draw a sharp distinction between what QTFY was doing and ordinary hacking. Most cyber espionage exists to steal something — data, intellectual property, secrets. What investigators describe finding inside America's power infrastructure is different. It's called "cyber-positioning": the patient, years-long process of gaining and maintaining quiet access to critical systems, not to take anything today, but to have the capability to act — to sabotage, to disable, to shut something down — at a moment of the adversary's choosing, likely during a future war or international crisis.

That is the scenario the images from New York's 2019 blackout illustrate so plainly. A transformer failure took out power to a fraction of one American city for a few hours, and it made national news, stranded thousands, and shut down Times Square. The federal government's warning in 2026 is about an adversary with the patience and the access to potentially do something far larger, far more coordinated, and far less accidental — and they've been building toward that access for the better part of a decade.

Power transmission towers glowing blue at dusk
THE BULK-POWER SYSTEM: The high-voltage transmission network — substations, transformers, control systems — is exactly what Executive Order 14420 is designed to protect, and exactly what federal investigators say QTFY spent years trying to reach.
08  ·  The Agencies
Who Fought This.
The Federal Response.
FBI San Diego Field Office
Led investigation and seizure operation — SAC Mark Remily
FBI Cyber Division
National technical operation — FBI Director Kash Patel
National Security Agency
Co-authored joint cybersecurity advisory JCSA-20260826-01
Cyber National Mission Force
Co-authored technical advisory and IOC data
DOJ National Security Division
AAG John A. Eisenberg — National Security Cyber Section led disruption effort
U.S. Attorney's Office, S.D. Cal.
Adam Gordon — obtained court-authorized domain seizures
Office of the Attorney General
Attorney General Todd Blanche — announced the action
Department of Energy
120-day mandate under EO 14420 to identify and mitigate high-risk grid equipment
NFA Editorial Note
This report is part of NFA's Special Investigation series — distinct from our ongoing domestic Political Violence documentation. There is no left-wing or right-wing angle to a foreign nation-state targeting America's power grid for eight years. This is an American story, and NFA reports it the same way we report everything else: sourced directly from the federal record, without filter, without agenda, without apology.
Share This Investigation

If this investigation was useful, help others discover it by sharing.

No Filter America
No Filter America
Truth · Freedom · Accountability
HomeSpecial InvestigationsCase FilesContact
© 2026 No Filter America. This report is published for public informational purposes only and is protected under the First Amendment.