NASA, the Federal Reserve, the Justice Department, the U.S. Senate and hundreds of other organizations all appeared in the same years-long cyber campaign. Some were scanned for weaknesses. Some faced attempted break-ins. Others had data stolen.
That difference matters.
The QTFY campaign is serious, but it does not mean every local company is a direct target. The practical warning is that automated tools are searching for ordinary security gaps at an enormous scale. For small business cybersecurity, one overlooked firewall, VPN or remote access tool can create an opening.
What Happened in the QTFY Cyber Campaign?
On August 26, 2026, the U.S. Department of Justice and FBI announced that they had seized domains used by two hacking platforms called QScan and QTRouter. Officials attributed them to QTFY, a group allegedly operated by a China-based technology company for Chinese government customers.
Federal officials said the group had targeted U.S. and international networks since at least 2018, reaching government, energy, healthcare, telecommunications, finance, education and defense organizations.
The campaign was not one massive attack that happened overnight. It was a long-running operation that repeatedly searched for exposed technology and quickly used newly discovered vulnerabilities.
A Simple Breakdown of the Reported Attacks
The joint advisory from the FBI, NSA and Cyber National Mission Force outlines years of activity:
- 2018 through 2021: QTFY activity reached the Department of Energy, NASA, the Federal Reserve, the Justice Department, Health and Human Services, election infrastructure, hospitals and private companies. Some attempts failed. Others involved vulnerabilities in VPNs, Microsoft Exchange, Citrix systems and web applications.
- May 2024: The group used QScan while targeting power and telecommunications companies through a vulnerability in Check Point security gateways. The federal advisory says data was stolen from more than 300 organizations worldwide, including defense contractors, financial institutions and universities.
- September 2024: QTFY reportedly used previously unknown vulnerabilities to conduct intrusions involving three Department of Energy laboratories, the National Institutes of Health, a Health and Human Services agency and a U.S. security device manufacturer.
- 2025 and 2026: Activity included exploiting a file-transfer vulnerability at a biotechnology company and targeting remote-support software at a state government. The group also scanned the U.S. Senate, a hospital system and an election system in 2026. Those three attempts were reported as unsuccessful.
This timeline is important because the words targeted, attempted and compromised are not interchangeable. A vulnerability scan does not automatically mean data was accessed. At the same time, the confirmed intrusions show that the operation was capable of moving beyond reconnaissance when it found the right opening.
How Did the Attacks Work?
QScan acted like an automated search engine for weaknesses. It examined websites, applications and connected devices, then checked them against potential exploits. On one day in 2024, it reportedly processed more than two million scanning and penetration-testing tasks.
QTRouter concealed malicious traffic through proxy services, rented servers and compromised devices. An attack could appear to come from an ordinary router or a location near the target instead of its true source.
Together, the platforms created a repeatable process: find exposed systems, test them for weaknesses, exploit vulnerable technology and conceal the activity among normal internet traffic.
What Does This Mean for SMBs Cybersecurity?
Most SMBs are not high-priority espionage targets. However, automated scanning does not stop to check a company’s size before testing an exposed device.
Small businesses use many of the same firewalls, VPNs, remote-support tools and website platforms found in larger organizations. If those systems are outdated or poorly configured, they can be discovered. A compromise could expose data, disrupt operations, affect a business partner or allow a device to disguise other attacks.
That is where the urgency lies. Effective small business cybersecurity is less about reacting to every headline and more about making sure routine protections are handled consistently.
What Should Businesses Do Now?
The federal advisory recommends practical steps that apply directly to small business cybersecurity:
- Update software and firmware, especially on firewalls, routers, VPNs and other internet-facing systems.
- Maintain a complete inventory of connected technology and replace devices that no longer receive security updates.
- Remove unused remote-access tools and review who has administrative privileges.
- Require multifactor authentication wherever possible.
- Separate critical business systems from guest networks, cameras and other connected devices.
- Monitor endpoints and network activity for unusual behavior.
- Maintain tested backups and a clear incident response plan.
How TotalBC Can Help
Small business cybersecurity becomes much stronger when every important task has an owner, a schedule and a way to verify that it was completed.
TotalBC helps businesses manage updates, secure network equipment, strengthen Microsoft 365 access, protect endpoints and email, monitor suspicious activity and maintain dependable backups. We can also review internet-facing systems, identify outdated technology and build a practical security plan based on your organization’s actual risk and budget.
The QTFY campaign should not create panic, but it should create action. If you are unsure what devices are exposed or whether critical updates are being completed, schedule a Network Health Check with TotalBC. A clear view of your network is the first step toward closing the gaps attackers are already searching for.