Chinese state-sponsored hackers roamed inside U.S. government networks — including NASA, the Department of Justice, the Federal Reserve, and the U.S. Senate — for nearly eight years before the FBI finally seized the domains enabling the intrusions this week. The same federal government that constructed a vast surveillance apparatus to monitor American citizens couldn't keep Beijing's cyber operatives out of its own house.

The DOJ and FBI announced Wednesday the seizure of three domains tied to the Chinese hacking group QTFY, which since 2018 had breached systems at NASA, NIH, DOJ, HHS, three Department of Energy National Laboratories, the Federal Reserve, and the Senate, according to an FBI affidavit. QTFY sold hacking tools called "QScan" and "QTRouter" through a Chinese front company, Nanjing Xinjiuwei Network Technology Co., to the People's Republic of China's Ministry of State Security and the People's Liberation Army.

The affidavit alleges the domains facilitated an international money laundering conspiracy. The hacking services infected thousands of devices globally, hitting a medical center in Ohio, financial groups in Michigan and South Korea, and an insurance agency in Missouri, according to the New York Post. CNBC reported that hospitals, telecommunications providers, power companies, financial institutions, and defense contractors were also targeted.

What the government won't say is what was actually taken. Both outlets note the DOJ declined to detail the damage. Eight years of access to the Federal Reserve, the Senate, and the Department of Justice itself — and the public gets no accounting of what Beijing saw, stole, or compromised. That silence speaks volumes.

Attorney General Todd Blanche promised results. "State-sponsored malicious hackers preying on America's critical infrastructure will be stopped and prosecuted," he said in a statement, adding on Fox News that the hackers also targeted hospital systems and health care centers. FBI Director Kash Patel called it "the latest technical operation against PRC-sponsored hacking" and tied it to President Trump's Cyber Strategy.

Fair enough. But the question nobody in Washington wants to answer is how this happened in the first place. The federal government spends billions on cybersecurity — the cybersecurity contract market is a sprawling industry populated by revolving-door officials who cycle between agencies and the defense contractors they later regulate. The same bureaucrats and consultants who failed to stop QTFY for eight years are the ones collecting paychecks to tell you the system works. Follow the money: every failed audit, every breached network, every seized domain after years of intrusion means another contract, another consulting fee, another appropriation request.

The Post highlighted Patel's language about "surging efforts to shape adversary behavior and defend the homeland in cyberspace." CNBC framed the story more clinically, listing the victim agencies and noting the court filings without pressing on the gap between the government's surveillance reach and its defensive competence. Neither outlet pressed on the contractor money trail.

Eight years. The People's Liberation Army had a key to the DOJ's own networks while that same DOJ was building cases and wiretapping Americans. The domain seizure is a start. The real question is who got rich failing to prevent it — and whether anyone in the cybersecurity-contractor complex will ever be held accountable.