The U.S. Department of Justice says that its initial account about how various government agencies were targeted by the PRC-backed hacker gang QTFY was misleading. Justiceโs press release neglected to distinguish clearly between targeting of agencies and actual compromising of them (Reuters, August 29, 2026).
The Justice Department said on Friday it made a correction to the news release because the August 26 release โdescribed all agencies as victims whereas the governmentโs affidavit made clear that all were targeted but only some were compromisedโ.
The distinction matters because it narrows the scope of confirmed breaches….
According to an affidavit from the Federal Bureau of Investigation released alongside the original statement, the hackers have โtargetedโ US federal networks since at least 2018.
Those targets include NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health and the US Senate.
A footnote in the affidavit said that the FBI investigated the targeting of NASA and found that the attempted breach of NASA was unsuccessful due to the agencyโs patching of targeted software.
The affidavit alleges that in September 2024, the hackers carried out โcomputer intrusionsโ at three โDOE National Laboratories, NIH, an HHS agency, and a US security device manufacturerโ. It referred to the entities as โvictimsโ.
A separate joint cybersecurity advisory issued by the FBI, National Security Agency and US Cyber Commandโs Cyber National Mission Force, published on Wednesday, listed successful data thefts from unnamed defence contractors, financial institutions and universities in May 2024.
It also noted unsuccessful attempts to access the networks for the US Senate and a hospital in March 2026.
So, some attacks succeeded, some did not. But news stories donโt seem able to say much about how successful the successful attacks wereโwhat was compromised and what information stolen. Do the โunnamed financial institutionsโ include my bank? Inquiring minds want to know.
Massive
Fox News reports that the scale of the years-long attacks โwas massive. On a single day in 2024, QScan processed more than 2 million scanning and penetration-testing tasks, according to the FBI affidavit. The platform contained more than 200 proof-of-concept exploits and searched the internet for vulnerable software, exposed services and other openings hackers could exploit.โ
In May 2024, QTFY exploited a recently disclosed Check Point vulnerability while scanning U.S. power and telecommunications companies and stole data from more than 300 organizations in the United States and abroad, according to the advisory.
The government did not name the affected organizations or describe what information was taken. The advisory said victims included U.S. defense contractors, financial institutions and universities.
Four months later, hackers exploited zero-day flaws in Ivanti Cloud Services Appliance software to gain access to three Department of Energy national laboratories, the National Institutes of Health, the Health Resources and Services Administration and a U.S. security-device manufacturer, the advisory said.
Aaron Shraberg, who works for cyberthreat-analyzer Flashpoint, says that โQTFY is another example of how Chinaโs cyber ecosystem has blurred the line between commercial cybersecurity and state-sponsored operations. The commercialization of that ecosystem has helped turn capabilities that once relied on bespoke tradecraft into tools and services that can be developed, reused and deployed at scale.โ
We seem to be hurtling toward a time in which any smart kid who masters an instruction video can be a world-destroying cyberhacker. Heโll need to know where to buy the hack packages and how to tell the AI โGo.โ