DOJ Watch: Aug. 27, 2026 — FBI Seizes Chinese State Hacking Platforms as Fraud Settlements Top $620M

ByEduardo Bacci

August 27, 2026
Robert F. Kennedy Department of Justice Building in Washington, D.C.The Robert F. Kennedy Department of Justice Building in Washington, D.C. (Public domain photo via Wikimedia Commons)

The Investigative Journal’s daily review of federal enforcement actions. All charges described below are allegations unless a court has entered a conviction or judgment; defendants are presumed innocent until proven guilty. Settlement figures reflect resolutions of allegations only, with no determination of liability unless noted.

The Justice Department closed out a consequential three-day stretch this week, pairing a major cyber operation against infrastructure linked to Chinese state-sponsored hackers with a wave of False Claims Act resolutions that, by TIJ’s tally of the department’s own announcements, totals more than $620 million. The recoveries span Medicare Advantage billing, a Navy shipyard cleanup, federal contracting certifications, and employment practices at one of the nation’s largest professional services firms. Below are eight actions announced between Aug. 24 and Aug. 26 that merit attention.

FBI seizes hacking platforms tied to Chinese state-sponsored group; victims include the Fed, NASA, and the Senate

The department and the FBI announced court-authorized domain seizures on Aug. 26 that disabled two complementary hacking platforms, “QScan” and “QTRouter,” which prosecutors say were built and operated by a People’s Republic of China state-sponsored group known as “QTFY,” employed by Nanjing Xinjiuwei Network Technology Co. According to court documents unsealed in the Southern District of California, QTFY sold hacking services to customers including China’s Ministry of State Security and the People’s Liberation Army. The government’s list of intrusion victims is striking: NASA, the Federal Reserve, the Departments of Energy, Justice, and Health and Human Services, the National Institutes of Health, and the U.S. Senate.

Court filings describe a two-part system: QScan automatically infected internet-of-things devices worldwide, feeding them into QTRouter, an “obfuscation network” that made PRC-origin intrusions appear to come from computers outside China — sometimes local to the targeted networks. Because the seized domains were hard-coded into both malware families for communication and authentication, the department says the seizures rendered the platforms inoperable. The seizure affidavit is public, and the FBI and NSA released a joint cybersecurity advisory with indicators of compromise dating QTFY activity to at least 2018.

The operation extends a pattern of technical takedowns aimed at PRC-linked infrastructure — PlugX malware removal in 2025, the Flax Typhoon botnet in 2024, and Volt Typhoon in 2023. The significance here is the alleged commercial layer: a private Chinese company selling intrusion capability to state security services, a structure that complicates both attribution and deterrence.

The Villages Health System agrees to $541.5M Medicare Advantage settlement — with a self-disclosure twist

The Villages Health System LLC, a provider group serving Florida’s largest retirement community, agreed to a $541.5 million settlement resolving allegations that it submitted false diagnosis codes that inflated Medicare Advantage payments from 2020 through 2024. According to the department, the codes lacked adequate support in patient medical records or rested on improper record amendments, causing the Centers for Medicare & Medicaid Services to overpay Medicare Advantage plans run by Humana, UnitedHealthcare, and Florida Blue affiliates — which in turn paid The Villages Health more.

Notably, this case began with the provider itself: The Villages Health disclosed the invalid codes to the HHS inspector general in December 2024 under the agency’s self-disclosure protocol, then filed for Chapter 11 protection in July 2025 (In re Villages Health System, LLC, No. 6:25-bk-04156, Bankr. M.D. Fla.). The bankruptcy court approved the settlement Aug. 25, and the government publicly credited the company’s cooperation. Filings indicate the insurers are returning overpayments by deleting invalid codes or entering repayment agreements — the settlement agreement, and the companion agreements with United and Florida Blue, are posted.

The dollar figure places this among the largest Medicare Advantage risk-adjustment recoveries on record, and it lands amid sustained federal scrutiny of diagnosis-coding practices across the managed-care industry.

Tetra Tech pays $57M over falsified radiation testing at Hunters Point shipyard

Tetra Tech EC Inc. paid $57 million to resolve allegations that it fabricated work and falsified soil-testing data the Navy relied on to certify that the former Hunters Point Naval Shipyard in San Francisco was free of harmful radiation. The government alleged that under contracts spanning 2003 to 2014, the company instructed field technicians to discard samples from potentially contaminated locations and substitute “clean” soil, and that it manipulated scan records in its database.

The consolidated whistleblower cases (U.S. ex rel. Jahr v. Tetra Tech EC, Inc., No. 13-3835, N.D. Cal.) were brought by seven former employees and contractors, who will share approximately $11.97 million. The settlement follows a separate $40 million recovery under the Superfund statute entered in July 2025 — bringing total recoveries at the site to nearly $100 million. The shipyard’s remediation has been a decades-long flashpoint for the surrounding community, which was promised the parcel for redevelopment; records suggest the alleged data manipulation delayed that transfer and extended public health uncertainty.

Deloitte pays $21.5M in False Claims Act settlement over contractor anti-discrimination certifications

Five Deloitte entities agreed to pay $21.5 million to resolve allegations that, from 2017 onward, the firm falsely certified compliance with anti-discrimination provisions in its federal contracts while making hiring, promotion, staffing, and program-eligibility decisions with regard to race and sex. The government alleged Deloitte tracked progress toward demographic workforce goals in color-coded monthly reports, tied senior partner evaluations — and for a period, compensation for roughly 150 senior leaders — to those goals, and limited eligibility for certain leadership development programs by race and sex.

The settlement is the latest under the department’s Civil Rights Fraud Initiative, launched in May 2025, which treats alleged discrimination by federal contractors as a false certification issue under the False Claims Act. The whistleblower case (U.S. ex rel. American Alliance for Equal Rights v. Deloitte LLP, No. 4:25-cv-00458, N.D. Tex.) was brought by the American Alliance for Equal Rights, which receives $4.3 million of the recovery under the False Claims Act’s qui tam provisions. The claims are allegations only, and there has been no determination of liability. For federal contractors, the case signals that internal diversity metrics tied to personnel decisions now carry measurable FCA exposure.

Minnesota money-transmitter employee charged with laundering CJNG drug proceeds

A federal grand jury in Minnesota indicted Christopher A. Bravo Marin, 46, of Minneapolis, on a charge of conspiring to launder at least $750,000 in drug proceeds for the Cártel de Jalisco Nueva Generación. The indictment alleges that from February 2023 to February 2026, Bravo — an employee of a money transmitting business — used his insider knowledge of the firm’s compliance procedures to keep transfers just under $1,000, the threshold triggering identity verification, and invented sender names while routing funds to straw beneficiaries in Mexico designated by cartel members. Prosecutors say he was paid roughly $40 to $50 per laundered transfer.

The case, charged at one count of money laundering conspiracy with a 20-year maximum, is part of the Homeland Security Task Force initiative and reflects the department’s stated focus on the financial facilitators who move cartel revenue south. The alleged scheme’s mechanics — insider structuring below verification thresholds — point to a compliance gap that money-services businesses will likely face pressure to close. An indictment is merely an allegation; Bravo is presumed innocent.

DermTech to pay up to $5M over unreliable Medicare skin cancer tests

The bankrupt skin-cancer testing company formerly known as DermTech Inc. settled allegations that it billed Medicare for tests it knew had quality-control failures — including tests run with an unvalidated positive-control range for a key melanoma marker, and tests that lacked sufficient patient RNA yet still generated positive or negative results reported to patients. The government says the company neither retracted results nor adequately refunded Medicare when concerns surfaced. The United States received an allowed unsecured claim of just over $5 million in the company’s Delaware bankruptcy; a former employee who filed the whistleblower case (U.S. ex rel. Luong v. DermTech, Inc., No. 3:23-cv-01404, S.D. Cal.) receives 20% of any recovery.

The public-health dimension distinguishes this from routine billing cases: filings indicate results from tests with unverifiable accuracy reached patients and physicians making melanoma-related decisions. The settlement pertains to the bankrupt entity, not DermTech LLC, which purchased the assets in 2024.

Aryan Brotherhood associate convicted of double murder ordered from inside a state prison

A federal jury convicted Justin Gray, 40, of San Pedro, California, of two counts of murder in aid of racketeering for the 2020 execution-style killings of two men in Lomita, California. According to evidence at trial, Gray lured the victims from San Diego and shot both in the head on orders from Francis Clement, an Aryan Brotherhood member issuing directives from Kern Valley State Prison over perceived “disrespect.” Gray faces a mandatory life sentence, with sentencing set for Nov. 23 in the Eastern District of California.

The conviction extends a sprawling 21-defendant racketeering prosecution that has already produced convictions of senior Aryan Brotherhood figures, including Clement and John Stinson, with additional defendants awaiting trial into 2027. The case underscores a persistent enforcement problem the department has acknowledged for years: violent orders flowing from inside maximum-security custody to the street.

AiNET and former CEO pay $1.8M over data center certifications to the SEC

Maryland-based AiNET Corp. and former chief executive Deepak Jain agreed to pay $1.8 million to resolve allegations that they fraudulently induced an SEC data-center contract by certifying the facility met Tier III standards — and that an entity called “UpTime Council” had inspected it and rated it Tier IV. The government alleged UpTime Council was not an operating company and never inspected the facility. The claims are allegations only. The matter is a reminder that certification fraud in federal IT procurement remains an active enforcement lane, even at modest dollar values.

On TIJ’s radar

Three threads from this week’s actions warrant deeper reporting. First, the QTFY seizure raises unresolved questions about the contractor ecosystem behind Chinese state hacking — which other firms occupy Nanjing Xinjiuwei’s niche, and whether U.S. advisories have altered their operations. The affidavit and the FBI-NSA technical advisory are a starting map. Second, The Villages Health settlement — self-disclosed, bankruptcy-processed, and the insurers returning overpayments — offers an unusually documented window into how Medicare Advantage risk-adjustment inflation actually works at the provider level; the posted agreements with United and Florida Blue deserve a close read. Third, the Deloitte resolution will not be the last under the Civil Rights Fraud Initiative; which contractors have quietly amended their internal demographic-goal programs since May 2025 is a reportable question with public-contract stakes.

Editor’s note: This digest is compiled from Justice Department press releases and publicly filed court documents linked above. Criminal charges are accusations, not findings; all defendants are presumed innocent unless and until proven guilty. Civil settlements resolve allegations only and involve no determination of liability except where a court has so found. Individuals and entities named in this digest, or their counsel, are invited to contact The Investigative Journal with statements, corrections, or responses, which we will publish or append as warranted.

Sources

ByEduardo Bacci

Investigative journalist and founder of The Investigative Journal. Specializing in OSINT-driven reporting on corporate malfeasance, government accountability, and institutional corruption.