P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Threat Intel

DoJ corrected its China hacking claim. It fixed one copy of two, and 17 articles still carry the original

The Department of Justice published the same announcement twice and edited only one. The reason it gave for the edit is a distinction its own sworn affidavit never draws, and the corrected version now understates what that affidavit alleges about three Department of Energy laboratories, NIH and an HHS agency.

By Parminder Kumar Sharma · · 9 min read

Two identical blank sheets of heavy cream paper on a dark desk, the top one curling to reveal the copy beneath, captioned DoJ corrected one copy, the other still says victims, one of two, and 17 articles never corrected at all

What was changed, and what was left alone

On 26 August 2026 the Department of Justice announced the seizure of infrastructure it attributes to a China-linked group the actors call QTFY. The announcement said seven federal bodies were victims of QTFY computer intrusion activity. On 28 August it said something different.

One announcement, two copies, one correction

ONE ANNOUNCEMENT, TWO COPIES, ONE CORRECTIONBoth are on justice.gov. Both are primary sources. As of 31 August they say different things.OFFICE OF PUBLIC AFFAIRS · 26-972CORRECTEDlast modified 28 Aug 2026, 13:09 ET“Among the targets of QTFY are theNational Aeronautics and SpaceAdministration, Federal Reserve …”Appended note says only that edits were madeto reflect the affidavit. It does not say what changed.USAO SOUTHERN DISTRICT OF CALIFORNIANEVER TOUCHEDlast modified 26 Aug 2026, 13:39 ET“Among the victims of QTFYcomputer intrusion activityare the National Aeronautics …”39 minutes after it was published, and notsince. Still live five days later.THE EDIT REMOVED TWO THINGS, NOT ONEOut went victims, and out went computer intrusion activity.The corrected sentence no longer alleges that any named federal body was compromised at all.The reason given does not match the affidavit it points at.DoJ said the affidavit “made clear that all were targeted but only some were compromised”.The affidavit calls an entity a victim on the basis of port scanning alone, and defines neither word.Modification timestamps read from the Department of Justice’s own press-release content API on 31 August 2026,and cross-checked against Internet Archive captures of both pages.
The two copies were byte-identical on the substantive sentence when published. Comparing the archived captures, the only other change to the Office of Public Affairs copy in that window was a site-wide navigation string, which dates the substantive edit to a single change on 28 August. A reader arriving at either page today is given no way to discover that the other exists, or that they disagree.
Modification timestamps read from the Department of Justice’s own press-release content API, and cross-checked against Internet Archive captures of both pages.

The Department published the same announcement twice: once from the Office of Public Affairs as release 26-972, and once from the US Attorney’s Office for the Southern District of California. It edited the first. It has never touched the second, which was last modified 39 minutes after it went up and still tells readers today that those bodies were victims of computer intrusion activity.

Both are on justice.gov. Both are primary sources. They disagree.

The edit also did more than swap one word. Out went victims, and out went computer intrusion activity. The corrected sentence reads “Among the targets of QTFY are…” and no longer alleges that any named federal body was compromised at all. The appended note says only that “Edits have been made to ensure this press release accurately reflects the government’s allegations in the affidavit”. It does not say what changed, and there is no correction notice on the press-release index.

The reason given does not survive a reading of the affidavit

The Department told Reuters, through an unnamed spokesperson, that it corrected the release because the original “described all agencies as victims whereas the government’s affidavit made clear that all were targeted but only some were compromised.”

That is not what the affidavit does.

Worse, the affidavit uses victim for entities it says were merely scanned. Paragraph 21 introduces “four particular victims” and then says QTFY actors “targeted all four”. Paragraph 23 calls a South Korean financial group “the victim” on the basis that QTFY addresses “were scanning IP addresses owned by” it. Paragraph 25 calls a Missouri insurance agency “the victim” on the basis of an address “attempting to exploit” a device.

So the affidavit applies the word the press release retracted to conduct considerably weaker than the conduct the press release originally described. The correction is defensible on its own terms. The reason offered for it is not.

What the affidavit actually alleges, body by body

Targeting and compromise are not evenly distributed

BodyWhat the affidavit saysCompromise alleged
NASA2019 attempt against CVE-2019-11510. Footnote 1 states NASA had patched, so ‘the attempt was not successful’No, expressly failed
Federal ReserveAppears once, in the targeting list. No date, no CVE, no access claimNo
Department of JusticeAppears once, in the targeting listNo
US SenateAppears once, qualified ‘in 2026’No
Three DOE National LaboratoriesSeptember 2024 Ivanti CSA zero-day, ‘conducted computer intrusions’Yes
NIHSame sentence, same intrusionYes
An HHS agencySame sentence. The agency is not named in the affidavitYes
From the FBI affidavit in support of the domain seizure warrants, sworn 24 August 2026. The affidavit states it is submitted for the limited purpose of obtaining a seizure warrant and that only a selection of complaints is discussed, so silence is not a finding of no compromise.

Two of these deserve saying out loud. The NASA intrusion failed, and it failed because NASA had applied a patch. And the Federal Reserve, which led much of the coverage, appears exactly once in the entire document, in a list of targeted networks, with no date, no vulnerability and no claim of access.

Three government documents, three characterisations, one day

The press release was not the only thing published on 26 August. The FBI, NSA and Cyber National Mission Force issued a joint advisory the same day, and its per-event timeline uses different verbs again.

The advisory is more careful than the release it accompanied

DateAdvisory wording
May 2018Vulnerability scanning of the Department of Energy. ‘Unsuccessful attempt to gain access to network.’
Aug 2019Pulse Secure exploit used ‘against’ the Department of Justice, Federal Reserve and NASA
Mar 2020Vulnerability scanning of Health and Human Services. ‘Unsuccessful attempt to gain access to network.’
Sep 2024Ivanti zero-days used ‘at’ three DOE labs, NIH, the Health Resources and Services Administration, and a security device manufacturer
Mar 2026Vulnerability scanning of the US Senate and a hospital system. ‘Unsuccessful attempt to gain access to networks.’
Joint advisory JCSA-20260826-01, published 26 August 2026 by the FBI, NSA and Cyber National Mission Force. Note this is not a CISA advisory and carries no AA-number.

The advisory names HRSA as the affected HHS component. The affidavit says only “an HHS agency”. Nothing published reconciles the two, and no press account carries the HRSA identification at all.

There is a further gap worth noting for anyone reading attribution language closely. The advisory contains no estimative confidence terms anywhere in its 36 pages. No we assess, no high confidence. Attribution is stated flat. The affidavit is more careful than either: it says the actors “work for” a named Nanjing company, that payments from the Ministry of State Security “indicate” the company acts for the government, and that the actors include former members of the People’s Liberation Army.

The correction may now understate the case

This is the part nobody has said. By removing computer intrusion activity rather than only victims, the Department produced a sentence that no longer conveys that any US federal body was compromised. Its own affidavit says three Department of Energy laboratories, NIH and an HHS agency were victims of computer intrusions, and that the actors “used IP address 156.234.193.18 to remotely access all six victims”.

So the first version overstated what happened to NASA, the Federal Reserve, the Justice Department and the Senate. The second understates what happened to DOE, NIH and HHS. Neither version of a document published by the prosecuting department matches the document it is describing.

Everything they used was already on the shelf

14 of 14

advisory CVEs already in KEV

Every vulnerability this group is documented as using was known, catalogued and had a patch available.

Apr 2019

patch for the NASA vector

CVE-2019-11510 was fixed by the vendor before the August 2019 attempt that the affidavit says failed.

17

articles still uncorrected

None carries a correction, an update note or an editor’s note as of 31 August 2026.

CVE identifiers from the joint advisory; catalogue status verified against the CISA Known Exploited Vulnerabilities JSON feed, catalogue version 2026.08.27, on 31 August 2026.

The oldest flaw in the advisory list dates to 2018 and the newest to 2026, and all fourteen are in the CISA Known Exploited Vulnerabilities catalogue. There is no novel capability in the technical account. The single documented federal failure, at NASA, was prevented by a patch that had been available since April 2019.

That is the operational reading, and it is duller and more useful than the headline: this was a group applying catalogued, patchable flaws at scale, and the body that had patched survived.

The wrong version is the one that travelled

Seventeen articles still carry the stronger claim, and not one carries a correction. Several assert compromises the affidavit never alleged: headlines saying China hacked NASA, that agencies were breached, and in two cases that these were confirmed victims.

The sharpest example is not a fringe outlet. The two Reuters reporters who wrote the 28 August correction story have their own original 26 August wire still live and uncorrected on syndication, saying the group was responsible for break-ins on the Justice Department, NASA, the Federal Reserve and the Senate.

A handful got it right on day one and needed no correction at all. BleepingComputer wrote targets from the first paragraph. Security Affairs did the same. CNN hedged as “compromised or attacked” and reserved victims for the DOE laboratories and NIH, which is exactly the distinction the affidavit draws.

Take this with you

If you cited this announcement

  • Check which copy you linked. The Office of Public Affairs release now says targets; the Southern District of California copy still says victims of computer intrusion activity. They are different documents at different URLs and only one has been edited.
  • Do not repeat that NASA was breached. The affidavit says the 2019 attempt failed, and says so because NASA had applied the patch.
  • Do not repeat that the Federal Reserve was compromised. It appears once in the affidavit, in a list of targeted networks, with no supporting allegation of any kind.
  • Where you need the compromise claim, cite the DOE laboratories, NIH and the HHS agency. Those are the ones the affidavit calls victims of computer intrusions, and the corrected release no longer mentions them as such.
  • Treat the affidavit as the anchor, not either press release. It is the sworn document, it is more careful than both, and it is public.

The position

A correction that reaches one of two identical documents has not been made. It has been half made, and the half that was left standing is the one a reader is as likely to reach.

The Department is not obliged to publish a redline. But the current state of play is that the prosecuting department has two contradictory accounts live on its own domain, a stated reason for the change that its own affidavit does not support, and seventeen articles built on the version it withdrew. This site has kept finding the same defect in different clothes: a claim travelling further than its evidence, and the correction arriving quieter than the original.

The practical lesson for anyone who cites government cyber announcements is narrow and worth internalising. The press release is not the evidence. The affidavit is. In this case it was published on the same day, at the same time, by the same department, and it was more accurate than both versions of the summary written about it.

Sources

  1. PrimaryJustice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers, release 26-972, corrected 28 August 2026US Department of Justiceaccessed 2026-08-31
  2. PrimaryThe same announcement, last modified 26 August 2026 and still carrying the original victims wordingUS Attorney's Office, Southern District of Californiaaccessed 2026-08-31
  3. PrimaryAffidavit in Support of Applications for Seizure Warrants, sworn 24 August 2026, Southern District of CaliforniaFederal Bureau of Investigationaccessed 2026-08-31
  4. PrimaryJCSA-20260826-01, China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure, 26 August 2026FBI, NSA and Cyber National Mission Forceaccessed 2026-08-31
  5. PrimaryCapture of release 26-972 on 26 August 2026 carrying the original wordingInternet Archiveaccessed 2026-08-31
  6. PrimaryKnown Exploited Vulnerabilities catalogue, version 2026.08.27, used to check all 14 advisory CVEsCISAaccessed 2026-08-31
  7. PrimaryCVE-2019-11510, the Pulse Secure flaw named in the NASA attemptNIST National Vulnerability Databaseaccessed 2026-08-31
  8. Reported byUS officials revise claims that government agencies were hacked by Chinese, 28 August 2026, carrying the DoJ statement on why it edited the releaseReuters, via syndicationaccessed 2026-08-31

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.