The U.S. Justice Department revised its statements regarding a Chinese state-sponsored hacking operation, clarifying that several government agencies were targets rather than confirmed victims of the breach.
The department edited an August 26 press release that originally listed NASA, the Federal Reserve, the U.S. Senate, the Department of Energy, the Department of Justice, the Department of Health and Human Services, and the National Institutes of Health as victims. The updated version now describes these agencies as among the targets of QTFY, a People's Republic of China state-sponsored group.
According to a note on the Justice Department page, the revision was made to ensure the press release accurately reflects the government's allegations in the affidavit supporting domain seizures.
Confirmed Intrusions
The supporting affidavit indicates that only some entities experienced confirmed compromises. Documented breaches occurred in September 2024 at three Department of Energy national laboratories, the National Institutes of Health, a Health and Human Services agency, and a U.S. security device manufacturer.
An attempted breach of NASA was unsuccessful because the agency had previously patched the targeted software.
Scope of Cyber-Espionage Campaign
The distinction between targets and confirmed victims reduces the number of validated breaches attributed to the ongoing Chinese cyber-espionage effort against U.S. critical infrastructure and sensitive networks.


