The Justice Department rewrote its own hacking announcement two days later

Victims became targets, and the department added a line explaining that the original had overstated its own affidavit.


Seal of Justice Department seen during press conference at US Attorney Office library announcing extradiction of Otoniel from Colombia

Seal of Justice Department

Image Credits Credit: lev radin via Shutterstock.com

The US Justice Department has quietly rewritten a press release that said Chinese hackers had claimed victims across the Senate, the Federal Reserve, NASA and half a dozen other federal bodies. The revised version says those organisations were targets, and that only some were actually compromised, as Reuters reported.

The original text went out on 26 August alongside a set of domain seizures. It listed the Senate, the Federal Reserve, NASA, the Department of Energy, the Justice Department itself, Health and Human Services, the National Institutes of Health, defence contractors, financial institutions and universities as having been among the hackers’ victims.

Two days later that word was gone. The agencies became “among the targets” of QTFY, the Chinese state-sponsored group named in the case, and the department added a line explaining itself.

“Edits have been made to ensure this press release accurately reflects the government’s allegations in the affidavit in support of the domain seizures,” the amended release said. In other words, the affidavit had never claimed what the press release claimed.

Being targeted by a state-sponsored group is close to routine for a federal agency, while being breached is a discrete event with consequences for the people whose data sat behind the door.

Corrections of this kind are rare in federal cyber announcements, which are usually drafted conservatively precisely because the difference between attempted and successful intrusion is the whole story. A public revision two days later suggests the original text ran ahead of what investigators had signed off on.

The underlying case is substantial regardless. QTFY has been running against US targets since at least 2018, and the affidavit does describe confirmed intrusions, just fewer of them than the first announcement implied.

Those confirmed breaches have dates attached. Investigators place intrusions at Department of Energy national laboratories, the NIH and Health and Human Services in September 2024, and successful data thefts from unnamed entities in May of the same year.

More recent attempts appear to have failed. Access efforts in March 2026 were unsuccessful, which suggests the campaign is continuing and that defences have improved somewhere along the line.

The operation behind the announcement involved most of the relevant American agencies. The FBI, the National Security Agency, US Cyber Command, the Justice Department and CISA all participated, and the visible output was the seizure of domains used in the campaign.

Domain seizures are the usual visible remedy in these cases. They take infrastructure away from an operator without requiring anyone to be arrested, which matters when the suspects are beyond the reach of an American court.

Nobody has explained how the error got into the release. No official was named in the correction, and the department has not said whether the wording was drafted from the affidavit or from a summary of it.

For European security teams, the practical value sits in the specifics rather than the framing. QTFY’s methods, timeline and target selection are the parts that transfer, and the same group’s techniques do not stop at a border.

Chinese espionage groups have been unusually visible in Europe this year. One has been raiding university mailboxes through a Roundcube flaw, and another turned a built-in Google Workspace feature into an exfiltration tool against medical and military research.

The correction also lands in a period when the United States has been loosening its own rules, having recently permitted private companies to run offensive cyber operations abroad. Attribution is becoming a more crowded business, and precision about who was breached is getting harder to take on trust.

The episode is also a reminder of how quickly an unqualified sentence travels. The original list circulated widely before the amendment appeared, and the corrected version will not reach most of the people who read the first one.

The seizures stand, but what changed is the claim about how far inside the intruders got, and it changed after the headlines had already been written.

Get the TNW newsletter

Get the most important tech news in your inbox each week.