The Justice Department revised its hacking announcement two days afterward.
The US Justice Department has discreetly updated a press release that initially stated Chinese hackers had targeted various entities, including the Senate, the Federal Reserve, NASA, and several other federal organizations. The new version clarifies that these organizations were merely targets and that only a few were actually breached, as reported by Reuters.
The original announcement was released on August 26, coinciding with a series of domain seizures, and it named the Senate, the Federal Reserve, NASA, the Department of Energy, the Justice Department, Health and Human Services, the National Institutes of Health, defense contractors, financial institutions, and universities as victims of the hackers.
Two days later, this language was altered. The agencies were reclassified as “among the targets” of QTFY, the Chinese state-sponsored group identified in the case, along with an additional line for clarification. The revised release stated, “Edits have been made to ensure this press release accurately reflects the government’s allegations in the affidavit in support of the domain seizures,” indicating that the affidavit did not support the claims made in the initial press release.
Being targeted by a state-sponsored group is somewhat standard for federal agencies, while an actual breach represents a specific event that carries consequences for those whose data is involved. Corrections like this are uncommon in federal cyber announcements, which are typically crafted cautiously, as the distinction between attempted and successful intrusions is critical. The public revision two days later suggests that the initial statement exceeded what investigators had authorized.
Nonetheless, the foundation of the case remains significant. QTFY has been active against US targets since at least 2018, and the affidavit does detail confirmed breaches, though fewer than initially suggested.
Confirmed breaches are associated with particular dates. Investigators noted intrusions at Department of Energy national laboratories, the NIH, and Health and Human Services in September 2024, alongside successful data thefts from unspecified entities in May of the same year.
More recent access attempts appear to have been unsuccessful, with access efforts in March 2026 failing, indicating that the campaign continues and that defenses may have improved over time.
The operation behind the announcement included the involvement of several relevant American agencies: the FBI, the National Security Agency, US Cyber Command, the Justice Department, and CISA, leading to the seizure of domains linked to the campaign.
Domain seizures serve as the typical visible action in such cases. They remove infrastructure from an operator without needing arrests, which is significant when the suspects are not within the jurisdiction of an American court.
There has been no explanation for how the error occurred in the release. No official was cited in the correction, and the department has not clarified whether the original wording was based on the affidavit or a summary.
For European security teams, the practical implications lie in the specifics rather than the context. The methods, timeline, and targets of QTFY are key elements that are relevant globally, as the same group's techniques can cross borders.
Chinese espionage groups have been particularly active in Europe this year, with one exploiting a Roundcube vulnerability to access university mailboxes, and another manipulating a Google Workspace feature for data exfiltration against medical and military research.
The correction also comes during a time when the United States is relaxing its own regulations, recently allowing private companies to conduct offensive cyber operations abroad. Attribution is becoming increasingly complex, and accuracy regarding who was breached is harder to trust.
This incident highlights how quickly an ambiguous statement can spread. The original list gained significant circulation before the correction was issued, and the amended version will likely not reach many who read the initial announcement.
While the domain seizures remain, the aspect that changed relates to the extent of the intruders' access, a change that occurred after headlines were already published.
Other articles
The Justice Department revised its hacking announcement two days afterward.
A DOJ statement indicated that Chinese hackers had targeted the Senate, the Fed, and NASA. The updated version clarifies that they were targets, and only a portion of them were compromised.
