US Corrects Statement on Chinese Hacking Campaign, Clarifies Agencies Were Targeted Not All Compromised
Quick Look
US officials revised a Justice Department statement to clarify that while Chinese hackers targeted agencies like the Senate, Federal Reserve, and NASA, only some were confirmed compromised, narrowing the scope of confirmed breaches in a years-long cyber-espionage campaign.
AI-generated summary
Why It Matters
The Justice Department initially stated several US government agencies were victims of Chinese hackers but later corrected the statement to clarify they were only among the targets, not all compromised, based on an FBI affidavit detailing a years-long cyber-espionage campaign since at least 2018.
United States officials have corrected earlier statements that several government agencies were attacked by Chinese hackers, now saying instead that the organisations were only among the hackers’ targets.
In a newly edited statement on Friday, the US Department of Justice said that the Senate, the Federal Reserve, NASA and other agencies were “among the targets of QTFY”, a Chinese state-sponsored hacking group.
A previous version of the statement said the government agencies had been among the hackers’ victims.
A note at the bottom of the newly revised statement says: “Edits have been made to ensure this press release accurately reflects the government’s allegations in the affidavit in support of the domain seizures.”
The Justice Department said on Friday it made a correction to the news release because the August 26 release “described all agencies as victims whereas the government’s affidavit made clear that all were targeted but only some were compromised”.
The distinction matters because it narrows the scope of confirmed breaches.
The Justice Department has accused Chinese actors of a years-long cyber-espionage campaign against US government agencies, defence contractors and other sensitive targets.
According to an affidavit from the Federal Bureau of Investigation (FBI) released alongside the original statement, the hackers have “targeted” US federal networks since at least 2018.
Those targets include NASA, the Federal Reserve, the Department of Energy (DOE), the Department of Justice, the Department of Health and Human Services (HHS), the National Institutes of Health (NIH) and the US Senate.
A footnote in the affidavit said that the FBI investigated the targeting of NASA and found that the attempted breach of NASA was unsuccessful due to the agency’s patching of targeted software.
The affidavit alleges that in September 2024, the hackers carried out “computer intrusions” at three “DOE National Laboratories, NIH, an HHS agency, and a US security device manufacturer”. It referred to the entities as “victims”.
A separate joint cybersecurity advisory issued by the FBI, National Security Agency and US Cyber Command’s Cyber National Mission Force, published on Wednesday, listed successful data thefts from unnamed defence contractors, financial institutions and universities in May 2024.
It also noted unsuccessful attempts to access the networks for the US Senate and a hospital in March 2026.
Messages seeking clarification from the FBI and the Cybersecurity and Infrastructure Security Agency were not immediately returned on Friday.
The Chinese Embassy in Washington did not immediately respond to a request for comment from Reuters news agency on Friday.
In response to Wednesday’s announcement, an embassy spokesperson said the US uses cybersecurity to “smear or discredit China”.
It added that China “opposes the US overstretching the concept of national security and using it as a pretext to impose discriminatory restrictions on Chinese companies and will firmly safeguard the legitimate rights and interests of Chinese companies”.
What to Watch
AI outlook — possibilities, not facts
The US will impose additional sanctions or restrictions on Chinese technology firms in response to the hacking allegations.
Likely · Within months
Congressional hearings will be held to investigate the extent of the cyber intrusions and US cybersecurity preparedness.
Very likely · Within weeks
Open Questions
- Which specific agencies were confirmed compromised in the hacking campaign?
- What data, if any, was successfully stolen from the confirmed victims?
- What actions will the US take in response to the confirmed intrusions?
- Is there evidence linking the hacking group QTFY directly to the Chinese state?





