← Latest briefing

Technology

US Justice Department clarifies government agencies were targeted, not breached, by Chinese hacking group

The DOJ corrected an earlier statement to clarify that NASA, the Federal Reserve, and the Senate were among the targets, but not necessarily compromised.

The short version

  • The U.S. Department of Justice revised an August 26 statement to clarify that several federal agencies, including the U.S. Senate, Federal Reserve, and NASA, were targeted but not successfully breached by a Chinese state-sponsored hacking group named QTFY.
  • An FBI affidavit revealed that while some entities like NASA successfully blocked the intrusion attempts via software patching, other targets—such as Department of Energy laboratories and the National Institutes of Health—did experience actual breaches in late 2024.
  • The Chinese Embassy in Washington denied the allegations, accusing the U.S. of using cybersecurity concerns to discredit China.

Key facts

  • The U.S. Department of Justice edited a previous statement to clarify that the U.S. Senate, the Federal Reserve, and NASA were targets of the Chinese state-sponsored hacking group QTFY rather than victims of successful breaches.[Al Jazeera]
  • The FBI found that an attempted cyberattack on NASA was unsuccessful because the agency had patched the targeted software.[Al Jazeera]
  • An FBI affidavit alleges that the hacking group successfully compromised networks at three Department of Energy National Laboratories, the National Institutes of Health, a Health and Human Services agency, and a U.S. security device manufacturer in September 2024.[Al Jazeera]
  • A joint advisory by the FBI, NSA, and U.S. Cyber Command reported successful data thefts from unnamed defense contractors, financial institutions, and universities in May 2024.[Al Jazeera]
  • A spokesperson for the Chinese Embassy in Washington stated that the U.S. overstretches national security concepts and uses cybersecurity allegations to smear China.[Al Jazeera]

What remains uncertain

  • The full scope of the compromise remains unclear as U.S. officials did not detail the specific data or level of access obtained during the successful breaches of the DOE National Laboratories, NIH, or other compromised entities.[Al Jazeera]

Sources