Drooid Logo
Back to story perspectives

Full Breakdown

U.S. Justice Department Revises Claim on Chinese Hackers: Agencies Were Targets, Not Confirmed Victims

8/29/2026, 11:32:28 AM

Revised Core Statement

On Friday, the U.S. Department of Justice issued an edited press release stating that the U.S. Senate, the Federal Reserve, NASA and other entities were “among the targets of QTFY,” a Chinese state-sponsored hacking group. The earlier version, released on August 26, had described the same agencies as “victims.” The revision narrows the scope of confirmed breaches, indicating that only some of the listed agencies were actually compromised.

Background & Context

QTFY is identified in an FBI affidavit as a China-backed operation that runs a large-scale botnet of compromised IoT devices. The botnet, operated by Nanjing Xinjiuwei Network Tech, provided “obfuscation networks” (QScan and QTRouter) that hide malicious traffic. The Justice Department and FBI seized the botnet’s command-and-control domains in a coordinated operation, rendering the infrastructure inoperable. The campaign is part of a years-long cyber-espionage effort targeting U.S. government agencies, defense contractors and other sensitive networks.

Timeline

  • August 26 – Original DOJ release labeled the Senate, Federal Reserve, NASA and others as victims.
  • Friday (date not specified) – DOJ issues revised statement clarifying agencies were “targets.”
  • September 2024 – FBI affidavit alleges intrusions at three DOE national laboratories, the National Institutes of Health, an HHS agency and a U.S. security-device manufacturer, calling them “victims.”
  • May 2024 – Joint advisory from the FBI, NSA and U.S. Cyber Command lists successful data thefts from unnamed defense contractors, financial institutions and universities.
  • March 2026 – Advisory notes unsuccessful attempts to access the U.S. Senate network and a hospital.

Data & Statistics

  • Agencies targeted since at least 2018 include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, HHS, NIH and the U.S. Senate.
  • The September 2024 intrusions involved four entities classified as “victims.”
  • The May 2024 advisory cites multiple successful data thefts from defense and financial sectors, without specific numbers.

Official Statements & Responses

The DOJ note emphasizes that the affidavit distinguishes “targets” from “compromised” agencies. The FBI affidavit confirms that the attempted breach of NASA was thwarted by timely patching. Attorney General Todd Blanche said, “Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.” FBI Director Kash Patel added, “These tools were used by PRC cyber actors to hide the origin of their attacks.”

The Chinese Embassy in Washington did not respond to a Reuters request for comment.

Conflicting Reports & Gaps

Initial reporting on August 26 described the agencies as victims, a characterization later corrected by the DOJ. Some outlets (e.g., ITPro) continue to assert that the agencies were breached, citing the Justice Department and FBI as confirming successful intrusions. The discrepancy between “targets” and “victims” remains unresolved, and the affidavit does not disclose which listed agencies were actually compromised beyond the NASA patching note.

What’s Next

U.S. authorities indicate that the domain seizures have disabled the QTFY botnet, but investigations into the full extent of any data exfiltration or lingering vulnerabilities are ongoing. No specific future hearings or deadlines are provided in the sources.