US officials have adjusted previous statements that several government agencies were breached by Chinese hackers, now saying these organizations were merely on the group's target list.
In a revised statement on Friday, the Department of Justice said the Senate, the Federal Reserve, NASA, and other agencies were "among the targets of QTFY," a state-backed Chinese hacking group. An earlier version of the statement had described these agencies as among the group's victims.
A note at the end of the revised statement reads: "Edits have been made to ensure this press release accurately reflects the government's allegations in the affidavit supporting the seizure of the domain names."
The Justice Department said on Friday that it corrected the press release because the August 26 version "described all the agencies as victims while the government's affidavit makes clear that they were all targeted but only some were compromised." This distinction is significant because it narrows the scope of confirmed intrusions.
The department alleged that Chinese actors conducted a years-long cyber espionage campaign against US government agencies, defense contractors, and other sensitive targets. According to an FBI affidavit released with the original statement, the hackers had been "targeting" US federal networks since at least 2018.
Targets included NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. A footnote in the affidavit said the FBI investigated the targeting of NASA and found that an attempt to breach NASA was unsuccessful because the agency had patched the targeted software.
The affidavit alleged that in September 2024, the hackers executed "computer intrusions" at three "DOE National Laboratories, NIH, an HHS agency, and a U.S. security equipment manufacturer." These entities were referred to as "victims."
A joint cybersecurity advisory issued on Wednesday by the FBI, the National Security Agency, and the US Cyber Command's National Cyber Mission Force listed successful data thefts from unnamed defense contractors, financial institutions, and a university in May 2024. The advisory also noted unsuccessful attempts to access networks of the US Senate and a hospital in March 2026.
Requests for clarification sent to the FBI and the Cybersecurity and Infrastructure Security Agency were not immediately returned on Friday. The Chinese Embassy in Washington also did not respond to a request for comment from Reuters.
In response to Wednesday's announcement, a spokesperson for the embassy suggested that the US uses cybersecurity to "slander or discredit China." The embassy added that China "opposes the United States stretching the concept of national security and using it as a pretext to impose discriminatory restrictions on Chinese companies, and will resolutely protect the legitimate rights and interests of Chinese companies."