FBI seizes Chinese botnet domains as DOJ affidavit names Senate, NASA, Federal Reserve among targets
The FBI on 26 August 2026 seized domains linked to a Chinese state-aligned botnet whose operators allegedly breached the Federal Reserve, NASA and the US Senate, according to a DOJ affidavit cited by TechCrunch and relayed by Telegram and X channels.

The FBI on 26 August 2026 seized internet domains tied to a Chinese state-aligned botnet that US investigators say was used to infiltrate and resell access to seven named federal entities, including the Federal Reserve, NASA, the Department of Justice itself, and the US Senate, according to a Department of Justice affidavit cited in court filings reported by TechCrunch.
The seizure makes public, for the first time, the breadth of a single hacking operation that allegedly monetised footholds inside the highest reaches of the US government. It also lands at a moment when Washington and Beijing have been trying to manage, rather than contain, their cyber competition.
What the affidavit says
According to a DOJ affidavit summarised by TechCrunch on 26 August 2026, Chinese hackers "targeted, and breached" the Department of Justice, the Department of Energy, the National Institutes of Health, the Department of Health and Human Services, NASA, the Federal Reserve and the Senate, then sold access to Beijing's intelligence service and military. The summary was relayed by the @disclosetv account on Telegram and X, and by the @megatron_ron Telegram channel, drawing on the same underlying court document.
A "botnet" is a network of internet-connected devices, often home routers and small-office equipment, that has been quietly commandeered by a single operator. The value to a state-aligned buyer is not the bandwidth but the geography: by routing traffic through compromised machines inside American networks, the operator can present as a trusted domestic user to the next target. The FBI's domain seizure is aimed at the command-and-control layer, the switchboard that tells those machines what to do next.
Scale of the alleged operation
The DOJ affidavit describes a customer base that is unusually broad for a single criminal vendor. Selling access to seven named federal entities, including the Federal Reserve, suggests a buyer list that extends beyond any one Chinese ministry. The dossier implies a marketplace: a clearing house where intelligence operators, military units, and possibly private contractors shop for footholds already inside American systems.
The botnet was used, the affidavit says, to "hack" NASA, the Justice Department and the Senate, according to TechCrunch's 26 August 2026 report. The Federal Reserve disclosure is the most economically loaded. A foothold inside the US central bank's network would be valuable to anyone trading on interest-rate decisions, payment-system routing, or stress-test data that moves markets before it moves policy.
What remains unclear
The court documents filed alongside the seizure do not specify, in the available source items, how long the intruders held access, which specific systems within each agency were touched, or whether classified networks were affected. The DOJ's public statement, as relayed by the cited channels, names the agencies but not the data. The available source items do not specify whether any of the seven agencies have confirmed the breach in their own public filings, or whether any data was exfiltrated.
The cited source items do not contain a public response from the Chinese government, the Ministry of Foreign Affairs, or any named Chinese ministry to either the seizure or the affidavit. Whether and when Beijing chooses to engage the story publicly is the next variable worth watching. Monexus analysis: with no first-party Chinese statement in the cited record, any reading of Beijing's posture is, for now, an inference rather than a sourced fact, and a default Chinese position in such cases has historically been to reject US criminal indictments of its nationals as politically motivated.
The pattern, in plain language
This is not a one-off intrusion. It is the visible edge of a longer contest over who controls the routing, the standards, and the trust assumptions of the global internet. Two structural facts sit beneath the day's headlines.
First, the supply side is industrialised. Building a botnet capable of supporting operations against the Senate and the Federal Reserve requires capital, talent, and patience on a scale that points to state backing rather than freelance criminals. The DOJ's public step so far is a domain seizure under warrant; the bureau has acted against infrastructure. The available source items do not specify whether named individuals have been indicted.
Second, the demand side is institutional. A vendor with seven federal entities on its client list is selling to a market, not a single buyer. Monexus assessment: that market, based on the affidavit's framing, includes the Chinese intelligence service and the Chinese military. The West's framing of "Chinese hacking" as a unitary threat understates the procurement problem: Beijing is not one customer but several, and they shop against each other. The corollary is that a takedown of one vendor does not necessarily dry up demand; it may simply reroute it to the next supplier.
Stakes
If the affidavit holds up, it sharpens the case for two policy tracks already on Washington's runway. One is the FBI's ongoing effort to dismantle the command infrastructure of state-aligned botnets before they can be resold to a second buyer; the 26 August domain seizure is a piece of that work. The other is the standing US-China cyber dialogue, whose contours the available source items do not specify.
The cost of getting it wrong is asymmetric. A foothold inside the Federal Reserve is a foothold inside the plumbing of dollar clearing, the system on which the US financial order rests. A foothold inside NASA is a foothold inside the technical record of US launch capability and scientific programmes. A foothold inside the Senate is leverage over the legislative branch itself.
Beijing's incentive, by contrast, is to keep these operations deniable and below the threshold of a kinetic response. The DOJ's choice, on this evidence, is a domain seizure rather than the public naming of individuals; the available source items do not specify whether indictments will follow. Both sides have reason, for now, to keep the temperature where it is.
How Monexus framed this vs the wire: TechCrunch led with the seizure and named the agencies. Monexus reads the affidavit as evidence of an institutionalised marketplace for federal footholds, a framing the cited wires do not yet articulate. The DOJ's official statement, as relayed by the cited channels, is the primary factual basis; the structural reading is this publication's.
Wire provenance
This editorial synthesis draws on the following public wire/social posts:
- https://techcrunch.com/2026/08/26/us-seizes-domains-of-chinese-botnet-used-to-hack-nasa-justice-department-and-the-senate/
- https://t.me/disclosetv/21783
- https://www.disclose.tv/id/el73z0rzwi/@disclosetv
- https://x.com/disclosetv/status/2092695405699989575
- https://t.me/megatron_ron/16596