Drooid Logo
Back to story perspectives

Full Breakdown

U.S. DOJ Revises Statement on Chinese Cyber Espionage: Agencies Were Targets, Not Confirmed Victims

8/29/2026, 4:23:43 AM

Core Event – Revised Claim on Agency Status

On August 28, the Department of Justice (DOJ) issued a revised press release stating that the U.S. Senate, the Federal Reserve, NASA and several other federal entities were “among the targets of QTFY,” a Chinese state-sponsored hacking group identified during a recent domain-seizure operation. The earlier release had described those agencies as “victims.” “Edits have been made to ensure this press release accurately reflects the government’s allegations in the affidavit in support of the domain seizures.” — The DOJ

Background & Context – QTFY Campaign and Domain Seizure

The FBI affidavit describes a multi-year Chinese cyber-espionage effort that began at least in 2018 and targeted federal networks, including NASA, the Federal Reserve, the Department of Energy, the Department of Justice, HHS, NIH and the Senate. An attempted breach of NASA was thwarted after the agency patched the software.

In 2024 the group carried out intrusions at three DOE national laboratories, NIH, an HHS agency and a security-device manufacturer, labeling those entities as “victims.” A joint advisory later listed data thefts from unnamed defense contractors, financial institutions and universities in 2024, and unsuccessful attempts to access the Senate’s network and a hospital network in 2026.

The DOJ and FBI also announced the seizure of domains used to support two QTFY platforms—QScan and QTRouter—both of which facilitate scanning, infection and obfuscation of compromised devices.

Data & Statistics – Agencies Identified as Targets

  • U.S. Senate – target
  • Federal Reserve – target
  • NASA – target (attempted breach unsuccessful)
  • Department of Energy – target; three national laboratories listed as victims in 2024
  • Department of Justice – target
  • Department of Health and Human Services – target; an HHS agency listed as a victim in 2024
  • National Institutes of Health – target; listed as a victim in 2024

The affidavit does not specify confirmed compromises beyond the NASA patching incident.

Official Statements & Responses

  • “Edits have been made to ensure this press release accurately reflects the government’s allegations in the affidavit in support of the domain seizures.” — The DOJ
  • Attorney General Todd Blanche: “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
  • FBI Director Kash Patel: “These tools were used by PRC cyber actors to hide the origin of their attacks.”

Conflicting Reports & Gaps

  • The revised claim that the agencies were merely “targets” contrasts with earlier statements that they were “victims.”
  • The DOJ, FBI and CISA did not respond to media inquiries seeking clarification on which agencies were definitively compromised.
  • The affidavit confirms NASA’s breach attempt was unsuccessful, but provides no outcome for the other listed agencies, leaving the extent of actual data exfiltration unclear.

The revision narrows the scope of confirmed breaches while earlier public records still reflect assertions of successful intrusions, underscoring the need for further clarification from U.S. authorities.