DoJ corrected its China hacking claim. It fixed one copy of two, and 17 articles still carry the original
The Department of Justice published the same announcement twice and edited only one. The reason it gave for the edit is a distinction its own sworn affidavit never draws, and the corrected version now understates what that affidavit alleges about three Department of Energy laboratories, NIH and an HHS agency.
By Parminder Kumar Sharma · · 9 min read

What was changed, and what was left alone
On 26 August 2026 the Department of Justice announced the seizure of infrastructure it attributes to a China-linked group the actors call QTFY. The announcement said seven federal bodies were victims of QTFY computer intrusion activity. On 28 August it said something different.
One announcement, two copies, one correction
The Department published the same announcement twice: once from the Office of Public Affairs as release 26-972, and once from the US Attorney’s Office for the Southern District of California. It edited the first. It has never touched the second, which was last modified 39 minutes after it went up and still tells readers today that those bodies were victims of computer intrusion activity.
Both are on justice.gov. Both are primary sources. They disagree.
The edit also did more than swap one word. Out went victims, and out went computer intrusion activity. The corrected sentence reads “Among the targets of QTFY are…” and no longer alleges that any named federal body was compromised at all. The appended note says only that “Edits have been made to ensure this press release accurately reflects the government’s allegations in the affidavit”. It does not say what changed, and there is no correction notice on the press-release index.
The reason given does not survive a reading of the affidavit
The Department told Reuters, through an unnamed spokesperson, that it corrected the release because the original “described all agencies as victims whereas the government’s affidavit made clear that all were targeted but only some were compromised.”
That is not what the affidavit does.
Worse, the affidavit uses victim for entities it says were merely scanned. Paragraph 21 introduces “four particular victims” and then says QTFY actors “targeted all four”. Paragraph 23 calls a South Korean financial group “the victim” on the basis that QTFY addresses “were scanning IP addresses owned by” it. Paragraph 25 calls a Missouri insurance agency “the victim” on the basis of an address “attempting to exploit” a device.
So the affidavit applies the word the press release retracted to conduct considerably weaker than the conduct the press release originally described. The correction is defensible on its own terms. The reason offered for it is not.
What the affidavit actually alleges, body by body
Targeting and compromise are not evenly distributed
| Body | What the affidavit says | Compromise alleged |
|---|---|---|
| NASA | 2019 attempt against CVE-2019-11510. Footnote 1 states NASA had patched, so ‘the attempt was not successful’ | No, expressly failed |
| Federal Reserve | Appears once, in the targeting list. No date, no CVE, no access claim | No |
| Department of Justice | Appears once, in the targeting list | No |
| US Senate | Appears once, qualified ‘in 2026’ | No |
| Three DOE National Laboratories | September 2024 Ivanti CSA zero-day, ‘conducted computer intrusions’ | Yes |
| NIH | Same sentence, same intrusion | Yes |
| An HHS agency | Same sentence. The agency is not named in the affidavit | Yes |
Two of these deserve saying out loud. The NASA intrusion failed, and it failed because NASA had applied a patch. And the Federal Reserve, which led much of the coverage, appears exactly once in the entire document, in a list of targeted networks, with no date, no vulnerability and no claim of access.
Three government documents, three characterisations, one day
The press release was not the only thing published on 26 August. The FBI, NSA and Cyber National Mission Force issued a joint advisory the same day, and its per-event timeline uses different verbs again.
The advisory is more careful than the release it accompanied
| Date | Advisory wording |
|---|---|
| May 2018 | Vulnerability scanning of the Department of Energy. ‘Unsuccessful attempt to gain access to network.’ |
| Aug 2019 | Pulse Secure exploit used ‘against’ the Department of Justice, Federal Reserve and NASA |
| Mar 2020 | Vulnerability scanning of Health and Human Services. ‘Unsuccessful attempt to gain access to network.’ |
| Sep 2024 | Ivanti zero-days used ‘at’ three DOE labs, NIH, the Health Resources and Services Administration, and a security device manufacturer |
| Mar 2026 | Vulnerability scanning of the US Senate and a hospital system. ‘Unsuccessful attempt to gain access to networks.’ |
The advisory names HRSA as the affected HHS component. The affidavit says only “an HHS agency”. Nothing published reconciles the two, and no press account carries the HRSA identification at all.
There is a further gap worth noting for anyone reading attribution language closely. The advisory contains no estimative confidence terms anywhere in its 36 pages. No we assess, no high confidence. Attribution is stated flat. The affidavit is more careful than either: it says the actors “work for” a named Nanjing company, that payments from the Ministry of State Security “indicate” the company acts for the government, and that the actors include former members of the People’s Liberation Army.
The correction may now understate the case
This is the part nobody has said. By removing computer intrusion activity rather than only victims, the Department produced a sentence that no longer conveys that any US federal body was compromised. Its own affidavit says three Department of Energy laboratories, NIH and an HHS agency were victims of computer intrusions, and that the actors “used IP address 156.234.193.18 to remotely access all six victims”.
So the first version overstated what happened to NASA, the Federal Reserve, the Justice Department and the Senate. The second understates what happened to DOE, NIH and HHS. Neither version of a document published by the prosecuting department matches the document it is describing.
Everything they used was already on the shelf
14 of 14
advisory CVEs already in KEV
Every vulnerability this group is documented as using was known, catalogued and had a patch available.
Apr 2019
patch for the NASA vector
CVE-2019-11510 was fixed by the vendor before the August 2019 attempt that the affidavit says failed.
17
articles still uncorrected
None carries a correction, an update note or an editor’s note as of 31 August 2026.
The oldest flaw in the advisory list dates to 2018 and the newest to 2026, and all fourteen are in the CISA Known Exploited Vulnerabilities catalogue. There is no novel capability in the technical account. The single documented federal failure, at NASA, was prevented by a patch that had been available since April 2019.
That is the operational reading, and it is duller and more useful than the headline: this was a group applying catalogued, patchable flaws at scale, and the body that had patched survived.
The wrong version is the one that travelled
Seventeen articles still carry the stronger claim, and not one carries a correction. Several assert compromises the affidavit never alleged: headlines saying China hacked NASA, that agencies were breached, and in two cases that these were confirmed victims.
The sharpest example is not a fringe outlet. The two Reuters reporters who wrote the 28 August correction story have their own original 26 August wire still live and uncorrected on syndication, saying the group was responsible for break-ins on the Justice Department, NASA, the Federal Reserve and the Senate.
A handful got it right on day one and needed no correction at all. BleepingComputer wrote targets from the first paragraph. Security Affairs did the same. CNN hedged as “compromised or attacked” and reserved victims for the DOE laboratories and NIH, which is exactly the distinction the affidavit draws.
Take this with you
If you cited this announcement
- Check which copy you linked. The Office of Public Affairs release now says targets; the Southern District of California copy still says victims of computer intrusion activity. They are different documents at different URLs and only one has been edited.
- Do not repeat that NASA was breached. The affidavit says the 2019 attempt failed, and says so because NASA had applied the patch.
- Do not repeat that the Federal Reserve was compromised. It appears once in the affidavit, in a list of targeted networks, with no supporting allegation of any kind.
- Where you need the compromise claim, cite the DOE laboratories, NIH and the HHS agency. Those are the ones the affidavit calls victims of computer intrusions, and the corrected release no longer mentions them as such.
- Treat the affidavit as the anchor, not either press release. It is the sworn document, it is more careful than both, and it is public.
The position
A correction that reaches one of two identical documents has not been made. It has been half made, and the half that was left standing is the one a reader is as likely to reach.
The Department is not obliged to publish a redline. But the current state of play is that the prosecuting department has two contradictory accounts live on its own domain, a stated reason for the change that its own affidavit does not support, and seventeen articles built on the version it withdrew. This site has kept finding the same defect in different clothes: a claim travelling further than its evidence, and the correction arriving quieter than the original.
The practical lesson for anyone who cites government cyber announcements is narrow and worth internalising. The press release is not the evidence. The affidavit is. In this case it was published on the same day, at the same time, by the same department, and it was more accurate than both versions of the summary written about it.
Sources
- PrimaryJustice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers, release 26-972, corrected 28 August 2026US Department of Justiceaccessed 2026-08-31
- PrimaryThe same announcement, last modified 26 August 2026 and still carrying the original victims wordingUS Attorney's Office, Southern District of Californiaaccessed 2026-08-31
- PrimaryAffidavit in Support of Applications for Seizure Warrants, sworn 24 August 2026, Southern District of CaliforniaFederal Bureau of Investigationaccessed 2026-08-31
- PrimaryJCSA-20260826-01, China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure, 26 August 2026FBI, NSA and Cyber National Mission Forceaccessed 2026-08-31
- PrimaryCapture of release 26-972 on 26 August 2026 carrying the original wordingInternet Archiveaccessed 2026-08-31
- PrimaryKnown Exploited Vulnerabilities catalogue, version 2026.08.27, used to check all 14 advisory CVEsCISAaccessed 2026-08-31
- PrimaryCVE-2019-11510, the Pulse Secure flaw named in the NASA attemptNIST National Vulnerability Databaseaccessed 2026-08-31
- Reported byUS officials revise claims that government agencies were hacked by Chinese, 28 August 2026, carrying the DoJ statement on why it edited the releaseReuters, via syndicationaccessed 2026-08-31


