Justice Department Walks Back Claims That China Hacked NASA and Senate
The Department of Justice (DOJ) revised a press release that initially described NASA, the Federal Reserve, and the U.S. Senate as victims of a Chinese hacking operation, now saying they were targets rather than necessarily compromised.

The Justice Department and FBI announced Wednesday that they had seized domains used by QScan and QTRouter, two hacking platforms linked to the Chinese state-sponsored group QTFY, as part of a years-long espionage campaign targeting U.S. critical infrastructure.
The original release listed NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the U.S. Senate as targets.
Many read this language as confirmation that those agencies had been breached. By Friday, the department quietly revised the statement to clarify that the agencies were targeted, not necessarily hacked in a cyberattack.
QTFY’s Obfuscation Network Helped Hide Its Hacking Operations
According to the DOJ, QTFY, operated through the China-based Nanjing Xinjiuwei Network Technology Company, sells hacking services to Chinese government clients, including the Ministry of State Security and the People’s Liberation Army.
Its two platforms worked in tandem: QScan automatically infected thousands of internet-of-things devices worldwide, feeding them into QTRouter, a network of compromised devices and leased servers that let QTFY’s attacks appear to originate from outside China.
In some cases, the attacks even appeared to come from within the networks being targeted.
Attorney General Todd Blanche said malicious hackers “will be stopped and prosecuted,” while FBI Director Kash Patel credited FBI San Diego and the Bureau’s Cyber Division with disabling the platforms by seizing domains hard-coded into the malware.
The DOJ noted this was the fourth such technical operation against Chinese state-linked hacking infrastructure since 2023, following prior disruptions of the Volt Typhoon, Flax Typhoon, and Mustang Panda hacking groups.
This alleged incident added to the escalating tensions of IP theft between the U.S. and China.
Reuters Flags the Quiet Correction Two Days Later
Reuters reported Friday that U.S. officials corrected the earlier language, citing a gap between the DOJ’s press release and the court affidavit.
The August 26 release “described all agencies as victims,” while the affidavit said they were all targeted but only some were compromised.
Reuters could not determine which agencies were actually breached because the revised statement does not specify, unlike the confirmed OpenAI Hugging Face breach.
Al Jazeera’s follow-up coverage added that the affidavit dates QTFY’s targeting activity to at least 2018 and clarified that the Senate and Federal Reserve were not hacked.
Why a One-Word Distinction Actually Matters Here
The gap between “victim” and “target” is more than a technicality.
A federal agency being targeted by a nation-state hacking group is not unusual, while a confirmed breach is far more serious, implying data exposure, network compromise, or worse.
By initially blurring that distinction and correcting it two days later without a follow-up press conference, experts are likely to call that the DOJ allowed an inflated claim to circulate before clarifying it.
This does not take away from the achievement of dismantling QTFY’s network used to hide its attacks, as it’s a feat similar to other major efforts to disrupt malicious cyber infrastructure.
But it leaves the public record on China’s latest espionage campaign against U.S. critical infrastructure unclear, with reporters still waiting for the DOJ to say which of the seven federal targets, if any, were actually breached.
Source: US officials revise claims that government agencies were hacked by Chinese
![Top Tech Stories of 17th Week [2026]](https://www.nogentech.org/wp-content/uploads/2026/05/Top-Tech-Stories-of-17th-Week-2026-1-390x220.webp)


