Six Years Inside the Federal Reserve
For six years, a China-linked hacking operation lived inside the Federal Reserve, NASA, the DOJ, and the U.S. Senate — and no one caught it. The FBI just announced it's "disrupted." They still haven't said what was taken.
Story Anchor
For six years, a Chinese state-sponsored hacking operation lived inside the Federal Reserve, NASA, the DOJ, and the U.S. Senate — and no one caught it. The FBI just announced it's "disrupted." They still haven't said what was taken.
The Pattern
The Pattern
The surface story: the DOJ and FBI seized the domains behind QTFY, a China-linked botnet that used hijacked smart devices to hide six years of intrusion into some of the most sensitive systems in the U.S. government.
The institutional pattern: announce the takedown loudly, bury the damage quietly. This is the fifth nearly identical announcement in three years — Volt Typhoon, Flax Typhoon, PlugX, Salt Typhoon, now QTFY — and every time, the public gets confident quotes and no accounting of what was actually lost.
Why it matters to you: these are the same institutions asking for your unquestioned trust in their competence, your data, and your tax dollars — while quietly admitting they didn't know they'd been compromised for years.
Consciousness Questions
- Why do we accept "disrupted" as a synonym for "safe"?
- What does it mean that the institutions who failed to notice the breach are the same ones now controlling how it's explained?
- If this happened to the Federal Reserve and NASA, what confidence should you have in smaller institutions you trust with less oversight?
- Who benefits from you feeling reassured instead of informed?
- What would it look like to hold an institution accountable for six years of silence, not just for the eventual announcement?
- How much of your trust in "official" narratives is really trust in the sequence they're told in?
- What's the difference between an institution being competent and an institution being good at announcing wins?
Community Context
“I assumed government systems were more secure than they actually are. The shock isn't the hack — it's the multi-year blind spot.”
“Accountability language like 'seized' and 'disrupted' gets treated as closure instead of the start of a real accounting.”
“This connects to a broader distrust — not partisan, but structural — in any institution's ability to self-report its own failures honestly.”
The pattern emerging: consciousness is catching up to the fact that "handled" and "explained" are not the same word.
Academy Pathways
Transformation Practice
Transformation Practice
Think of one institution — government, corporate, religious, or otherwise — that you've extended automatic trust to without examining its actual track record. Write down what "handled" has meant from that institution in the past, versus what "explained" would actually require. What's one place you could ask a real question instead of accepting reassurance?
Campaign Opportunity
Notice The Pattern — Institutional Accountability Watch
What's happening: Prodigal is tracking the recurring pattern of "disrupted, not explained" across government cybersecurity announcements — Volt Typhoon, Flax Typhoon, PlugX, Salt Typhoon, QTFY — to build a public record institutions can't quietly walk back.
Why it matters: Each "disrupted" announcement without a damage accounting lets the pattern repeat. Naming it publicly is the first accountability.
What you can do: Share this story with the specific pattern language attached (not just the headline), so the six-year gap stays part of the conversation instead of getting lost in the win narrative.
Continue Your Journey
Credits & Transparency
Methodology
Companion guide constructed from the published PBN story and cited public sources. Community responses reflect recurring patterns observed in the Prodigal community and are attributed as such, not fabricated as named individuals.
Sources referenced
- U.S. Department of Justice press release
- TechCrunch
- The Hacker News
- Nextgov/FCW
- Congress.gov CRS