US Walks Back Claim That Chinese Hackers Breached NASA, Senate, and Federal Reserve

The US Department of Justice corrected its 26 August 2026 press release on 29 August 2026 to clarify that the US Senate, the Federal Reserve, NASA, and other federal agencies were "among the targets of QTFY" — a Chinese state-sponsored hacking group — rather than victims of successful breaches (Al Jazeera). The revision came three days after the DOJ and FBI announced the seizure of two domains allegedly used by the group to target sensitive US networks. That operation was described as the disruption of a global botnet — a network of hijacked computers controlled remotely by attackers — and a hacking platform used by Chinese state-sponsored hackers to target US critical infrastructure (DOJ).
The DOJ said it corrected the earlier release because it "described all agencies as victims whereas the government's affidavit made clear that all were targeted but only some were compromised" (Al Jazeera). A note appended to the revised statement said edits were made to ensure the press release accurately reflects the government's allegations in the affidavit — the sworn legal document filed in support of the domain seizures.
The distinction matters. An FBI affidavit released alongside the original DOJ statement alleges that the Chinese hackers have "targeted" US federal networks since at least 2018. The targets listed include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate (Al Jazeera).
But targeting is not the same as compromise. Think of it as the difference between someone trying every lock on your doors and actually getting inside. A footnote in the FBI affidavit states that the FBI investigated the targeting of NASA and found the attempted breach was unsuccessful due to the agency's patching of targeted software — meaning NASA had already applied updates that closed the vulnerability the hackers tried to exploit. The affidavit does allege that in September 2024 the hackers carried out "computer intrusions" at three DOE National Laboratories, NIH, an HHS agency, and a US security device manufacturer, referring to those entities specifically as "victims" (Al Jazeera).
A joint cybersecurity advisory issued by the FBI, NSA, and US Cyber Command's Cyber National Mission Force, published on 26 August 2026, adds further detail. The advisory lists successful data thefts from unnamed defence contractors, financial institutions, and universities in May 2024. It also notes unsuccessful attempts to access the networks of the US Senate and a hospital in March 2026 (Al Jazeera).
The hacking operation was linked to a Chinese company affiliated with the Beijing government, and the group used a massive botnet of compromised IoT (internet-connected) devices to conduct its operations (Washington Examiner; TechRadar).
In response to the US announcement, a Chinese Embassy spokesperson said the US uses cybersecurity to "smear or discredit China" and that China opposes the US overstretching the concept of national security as a pretext for discriminatory restrictions on Chinese companies (Al Jazeera).
The broader context here is one of escalatory optics on both sides. The DOJ's initial press release, by conflating targeted and compromised agencies into a single category of "victims," inflated the publicly perceived scope of successful intrusions. The correction narrows the government's formal claims to what the supporting affidavit actually alleges: a broad targeting campaign spanning years, with a smaller set of confirmed compromises at research labs, health agencies, and a security device manufacturer. For policymakers and threat intelligence professionals tracking the QTFY group's activities, the affidavit's specificity about which entities were merely targeted versus successfully breached is the operationally relevant signal. NASA's patching stopped one intrusion vector; the Senate and a hospital repelled attempts in March 2026. The confirmed data thefts occurred in the private sector, at unnamed defence contractors, financial institutions, and universities.
The gap between the original and corrected press release also raises a question about how DOJ frames cyber operations for public consumption. Prosecutors had the affidavit's precise language available; the initial release chose broader phrasing. Whether that was an inadvertent error or a deliberate framing choice, the correction came only after the affidavit's own footnotes contradicted the release's characterisation. For an audience assessing the credibility of US government attributions of Chinese state-sponsored cyber activity, that gap between charging documents and press communications is worth weighing.


