Key Highlights
- The U.S. Department of Justice seized more than $560,000 in cryptocurrency allegedly intended for Hamas’s military wing, the Al Qassam Brigades.
- Federal authorities dismantled an online fundraising and recruitment network that used encrypted messaging channels and cryptocurrency wallets to collect donations.
- The operation also targeted web servers, domain names, and communications infrastructure used to facilitate the fundraising activities.
The U.S. Department of Justice announced on September 1 the disruption of an online fundraising and recruitment network operated by Harakat al-Muqawama al-Islamiyya (Hamas), a designated Foreign Terrorist Organization, seizing over $560k in crypto.
According to the official announcement, federal law enforcement authorities seized more than $560,000 in cryptocurrency intended for Hamas’s military wing, the Al Qassam Brigades. In addition to confiscating digital asset wallets, the operation seized communications infrastructure, web servers, and domain names utilized by the group to collect funds and communicate with supporters globally.
Infiltration of encryption infrastructure and domain seizures
According to court filings, the illicit financing scheme operated through an encrypted messaging channel that directed prospective donors to a dedicated website. The platform utilized a rotating series of cryptocurrency wallet addresses to accept public contributions outside the traditional banking sector.
Investigators executed three court-authorized cryptocurrency seizure warrants on March 25, June 25, and October 10, 2025. By utilizing information provided by confidential human sources, federal agents traced and intercepted digital asset transfers moving into addresses controlled by the Al Qassam Brigades.
Simultaneously, the FBI’s Albuquerque Field Office seized web servers and domain names controlling the primary website AlQassam.ps. The capture of the web infrastructure allowed agents to intercept incoming digital asset donations in real time.
Through these operations, federal authorities obtained records regarding thousands of individuals who contacted Hamas online to offer financial support via cryptocurrency and conventional payment methods. Officials confirmed that the collected donor data will be integrated into ongoing federal counterterrorism investigations.
The case is being investigated by the FBI Albuquerque Field Office in coordination with the FBI Counterterrorism Division, Cyber Division, and New York Field Office. Prosecution is being led by the U.S. Attorney’s Office for the District of Columbia and the National Security Division’s National Security Cyber Section.
Federal law enforcement actions against network infrastructure
The enforcement action against Hamas’s digital funding rails follows a separate federal operation targeting malicious cyber infrastructure used against U.S. state entities.
On August 26, 2026, the Justice Department and the FBI executed court-authorized domain seizures against two illicit cyber platforms, QScan and QTRouter. Unsealed court filings in the U.S. District Court for the Southern District of California identified the platforms as products developed by QTFY, an entity affiliated with the China-based commercial firm Nanjing Xinjiuwei Network Technology Company.
Federal prosecutors categorized QTFY as a commercial hacking network that supplied technical exploitation services to external entities, including China’s Ministry of State Security (MSS) and the People’s Liberation Army (PLA).
Court filings detailed that intrusion activities facilitated through QScan and QTRouter targeted multiple federal institutions and critical infrastructure sectors. Compromised targets included the National Aeronautics and Space Administration (NASA), the Federal Reserve, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, the U.S. Senate, and the Department of Justice itself.
Also Read: Securitize & VARA Sign MoU to Advance Dubai Tokenization
