/

August 27, 2026

China Targeted NASA and the Federal Reserve — Using Hijacked Devices Like Yours

The headlines this week were the kind that grab everyone’s attention: U.S. officials announced that a state-sponsored hacking operation linked to China had targeted some of the most sensitive institutions in the country — NASA, the Federal Reserve, the U.S. Senate, the Department of Justice, and several federal agencies, among others. It sounds like something from a spy thriller, and understandably it’s dominating the news. But buried inside this dramatic story is a detail that matters enormously to ordinary small businesses — and it has nothing to do with being a government agency.

Here’s the part worth your attention: the attackers didn’t launch their operations directly from their own computers. They hijacked thousands of everyday internet-connected devices — ordinary routers and network equipment belonging to regular people and businesses — and used them as disposable stepping stones to carry out and disguise their attacks. In other words, the infrastructure used to go after NASA and the Federal Reserve may well have included hacked equipment sitting in small offices, homes, and businesses that had no idea they were involved. That’s the thread we want to pull on today, because it’s the part of this story that’s actually about you. And there’s good news woven through it, too.

A quick word on how we’re covering this

This story involves national governments and geopolitics, and we’re going to stay firmly in our lane: we’re a technology and security firm, not political commentators. We’ll report what U.S. officials actually stated — because that’s the factual record here, laid out in court documents and an official Justice Department announcement — and then focus entirely on the practical security lesson for regular businesses. We hold no geopolitical position and we’re not here to opine on international affairs. What we care about is helping you understand what a story like this means for your business, which turns out to be quite a lot.

What was actually announced

Let’s separate the substance from the noise. According to the U.S. Justice Department and FBI, authorities moved to disrupt a long-running cyber-espionage operation by seizing internet domains tied to two hacking platforms (referred to in the announcement as “QScan” and “QTRouter”). Officials said these platforms had been used to break into internet-connected devices and route attacks through them, and that the campaign had targeted U.S. critical infrastructure and sensitive networks. Court documents named a range of alleged targets, including NASA, the Federal Reserve, the U.S. Senate, and the Departments of Justice, Energy, and Health and Human Services, with the activity said to stretch back years.

Two things are worth emphasizing for perspective. First, this was announced as a law-enforcement success — the authorities took action to dismantle the operation’s infrastructure, not merely to report a loss. Second, and importantly for the rest of us, the officials described the actual mechanics of how the operation worked. And that’s where the small-business lesson lives.

The mechanic that matters: your devices as someone else’s weapon

Per the announcement, one of the platforms was used to find and infect thousands of internet-connected devices — routers and other network gear — which were then linked together into a network the attackers could route their operations through. This is a technique worth understanding, because it’s extraordinarily common and it directly involves the kind of equipment your business almost certainly owns.

The reason attackers do this is simple. When a sophisticated group wants to break into a high-value target, launching straight from their own systems would point right back at them and would be easy to block. So instead, they first take over a large collection of innocent, poorly-secured devices scattered around the world, and they bounce their attacks through those. To the victim, the attack appears to come from a random router in some ordinary business or home — not from the real culprit. Those hijacked devices become both a disguise and a launching pad. The owners, meanwhile, typically have no clue their equipment is being used this way; the device keeps working normally while quietly moonlighting as part of an attack network.

The uncomfortable truth for every small business: to a global attacker, your under-protected router, firewall, or camera isn’t valuable for the data on it — it’s valuable as a tool. A device sitting in your office, still using its factory password or running years-old software, is exactly the kind of thing these operations hunt for and quietly conscript. You don’t have to be an interesting target yourself to become part of an attack on someone who is. Your equipment can be turned into a weapon aimed at others — and you’d likely never know.

Why “we’re too small to be targeted” misses the point entirely

This is where the usual small-business assumption breaks down. Plenty of owners reason, “Nobody’s going to bother hacking us — we’re too small, we’ve got nothing worth stealing.” Set aside for a moment that this is already risky thinking. This story shows why it misses the mark on a different level entirely: you don’t have to be the target to be a victim.

These operations aren’t only hunting for valuable data on the devices they infect. They’re hunting for devices they can use — and a small business’s internet equipment is perfect for the job precisely because it’s often less protected and less monitored than a big company’s. Your router doesn’t need to hold state secrets to be useful; it just needs to be reachable and poorly secured. So the relevant question isn’t “are we important enough for anyone to attack?” It’s “is any of our internet-connected equipment weak enough to be conscripted into an attack on someone else?” For a great many businesses, the honest answer is yes — and they’d have no idea.

Beyond the reputational strangeness of having your equipment involved in someone else’s crime, there’s a direct self-interest angle too. A device compromised enough to be used against others is, by definition, a device an attacker already controls — which means it’s also a potential doorway into your network, your data, and your business. The same weakness that makes your router useful to them as a weapon makes you vulnerable as a victim. It cuts both ways.

The reassuring part: the fixes are ordinary and effective

Here’s the genuinely good news, and it’s the throughline of nearly every one of these stories. The devices that get conscripted into these attack networks are, overwhelmingly, the ones left in a weak state: default passwords never changed, firmware never updated, remote access left open when it didn’t need to be. Nation-state resources or not, these operations largely feast on basic, fixable neglect. Which means the same unglamorous fundamentals that protect you from everyday threats also keep your equipment from being drafted into extraordinary ones. Concretely:

  • Change the default passwords on everything. Every router, firewall, camera, and network device ships with a factory-set password that attackers already know. Changing these to something strong is the single most important step, and it closes the most common door of all.
  • Keep your devices’ software updated. Routers and network equipment receive security updates (firmware) that fix the very holes these operations exploit. Devices running years-old software are prime targets. If a device is so old it no longer receives updates, it’s time to replace it.
  • Close off remote access you don’t need. Many devices allow themselves to be reached and managed from across the internet, which is exactly what attackers look for. If your business doesn’t need that, turning it off dramatically shrinks your exposure.
  • Know what you actually have. You can’t secure equipment you’ve forgotten about — the old router in the closet, the security camera nobody thinks about, the networked device a vendor installed years ago. Simply knowing every internet-connected device in your business is the foundation for protecting them.

Worth asking about your own business: When was the last time anyone changed the passwords on your router and other network devices from their factory defaults? * Is the software on that equipment current, or has it not been touched since it was installed? * Can any of your devices be reached and managed from the open internet — and do they need to be? * And could you even list every internet-connected device on your network right now? If these questions are hard to answer, your equipment may be more exposed than you’d like.

The real takeaway

It’s easy to read a headline about China targeting NASA and the Federal Reserve and conclude it has nothing to do with your small business. This story quietly proves the opposite. The way these operations actually work — by hijacking thousands of ordinary, weakly-secured internet devices to use as camouflage and launching pads — means the equipment in everyday offices and homes is part of the story whether the owners know it or not. You don’t have to be a spy agency’s target to have your own router quietly enlisted in the effort.

The encouraging flip side is that keeping your business out of that picture doesn’t require anything exotic. It requires the same basic device hygiene that protects you from everything else: strong passwords instead of factory defaults, current software instead of years-old firmware, closed doors instead of open ones, and simply knowing what you have. That’s precisely what our environment review is built to check. We inventory the internet-connected devices across your business, find the ones sitting exposed with default passwords or outdated software, and help you lock them down — so your equipment can’t be quietly conscripted into someone else’s attack, and can’t become the doorway into your own. When a story like this breaks, the businesses that can shrug it off are simply the ones that took care of the basics. Let’s make sure yours is one of them.

Sources: U.S. Department of Justice and FBI announcement and unsealed court filings (August 26, 2026); Reuters; CNN; CNBC; Al Jazeera; U.S. News & World Report, August 2026. Attribution described here reflects the stated findings of U.S. officials; the Chinese government has generally denied involvement in such activity. Specific technical indicators are omitted in favor of awareness-level guidance. This article takes no geopolitical position and focuses on the security lessons for small businesses.

From the same category