US Officials Correct China Hacking Claims
US officials revise statements on China hacking, agencies targeted not breached. Revised statement draws distinction between attempted attacks and confirmed compromises.

US officials have revised their earlier statements regarding the alleged hacking of several government agencies by Chinese hackers. According to the revised statement, the US Senate, the Federal Reserve, NASA, and other organisations were among the targets of a Chinese state-sponsored hacking group known as QTFY.
The Department of Justice issued the revised statement on Friday, correcting an earlier version that had described the government agencies as victims of the hacking attempts. The revised wording is significant, as being targeted in a cyberattack does not necessarily mean that hackers successfully gained access to a network.
The change in wording draws a clearer distinction between attempted attacks and confirmed compromises, which is an important distinction when describing the scale of a state-linked cyber campaign. A note at the bottom of the revised statement explained that the edits were made to ensure the press release accurately reflected the government's allegations in the affidavit in support of the domain seizures.
The Department of Justice said that it corrected the press release because the original statement had described all agencies as victims, whereas the government's affidavit made clear that all were targeted but only some were compromised. The FBI affidavit released with the original statement detailed the targets of the hacking group, including US federal networks, such as those of NASA, the Federal Reserve, and the Department of Energy.
The affidavit alleged that the hackers had targeted these networks since at least 2018 and had carried out successful breaches at three DOE National Laboratories, the NIH, an HHS agency, and a US security device manufacturer. However, a footnote in the affidavit noted that the FBI investigated the targeting of NASA and found that the attempted breach was unsuccessful because the agency had patched the software that was targeted.
The distinction in the affidavit helps explain why officials revised the broader public statement. While some organisations were allegedly compromised, the available information does not support describing every targeted agency as a victim of a successful breach.
A separate joint cybersecurity advisory issued on Wednesday by the FBI, National Security Agency, and US Cyber Command's Cyber National Mission Force listed successful data thefts from unnamed defence contractors, financial institutions, and universities in May 2024. The advisory also listed unsuccessful attempts to access the networks of the US Senate and a US hospital in March 2026.
The revised statement and the cybersecurity advisory highlight the ongoing threat of state-sponsored hacking and the importance of distinguishing between attempted attacks and confirmed compromises. The US government's efforts to correct its earlier statements demonstrate a commitment to accuracy and transparency in reporting on cyber threats.
The incident also underscores the need for organisations to be vigilant in protecting their networks from cyber threats. The fact that some organisations were able to prevent breaches by patching software vulnerabilities highlights the importance of proactive cybersecurity measures.
In conclusion, the revised statement from US officials regarding the alleged hacking of government agencies by Chinese hackers draws a clearer distinction between attempted attacks and confirmed compromises. The incident highlights the ongoing threat of state-sponsored hacking and the importance of accuracy and transparency in reporting on cyber threats.
Frequently asked questions
What is the name of the Chinese state-sponsored hacking group?
The Chinese state-sponsored hacking group is known as QTFY.
Which US government agencies were targeted by the hacking group?
The US Senate, the Federal Reserve, NASA, and other organisations were among the targets of the hacking group.