The U.S. Department of Justice has just amended an official press release concerning a Chinese cyberespionage operation — a correction that fundamentally changes the scope of the case.
Agencies as sensitive as NASA, the Federal Reserve, and the U.S. Senate were initially presented as victims. The reality is more nuanced, and the DOJ has had to acknowledge that publicly.
This clarification raises serious questions about the rigor of official communications on cybersecurity matters — and about the true scale of the Chinese threat against critical U.S. infrastructure.
The DOJ Sets the Record Straight: Targets vs. Victims — A Critical Distinction
On August 26, 2026, the Department of Justice published a press release describing a cyberespionage campaign orchestrated by QTFY, a group sponsored by the People’s Republic of China. In its original version, the document referred to a list of high-profile federal agencies as victims: NASA, the Federal Reserve, the U.S. Senate, the Department of Energy, the Department of Justice itself, the Department of Health and Human Services (HHS), and the National Institutes of Health (NIH).
The problem: the underlying affidavit — the legal document supporting the domain seizures — does not confirm intrusions across all of those entities. The DOJ therefore corrected its press release, replacing the word “victims” with “targets.” An explanatory note states that the changes were made to “accurately reflect the government’s allegations in the affidavit.”
This distinction is far from trivial. In the field of cybersecurity, being a target means that an attempted intrusion was detected or suspected — without any confirmed compromise of the system. Being a victim implies a confirmed breach with actual access to data or systems. Conflating the two in an official press release constitutes a significant factual error.
What the Affidavit Actually Reveals: Confirmed but Limited Intrusions

According to the affidavit, the confirmed intrusions are concentrated within a far narrower perimeter than the original press release suggested. In September 2024, three national laboratories under the Department of Energy were compromised, along with the NIH, one HHS agency, and a U.S. manufacturer of cybersecurity devices.
The attempted hack targeting NASA, however, failed. The space agency had already patched the software exploited by QTFY before the intrusion could succeed — a textbook example of effective vulnerability management. This detail underscores the critical importance of security updates in protecting sensitive infrastructure.
The DOJ’s correction therefore mechanically reduces the official toll of this long-running cyberespionage campaign against U.S. networks. It also raises a fundamental question: how did an agency as rigorous as the Department of Justice manage to publish a press release so far removed from the facts established in its own affidavit? For players in the cybersecurity space — and for crypto markets closely monitoring systemic risks tied to financial infrastructure — this kind of official imprecision only fuels legitimate distrust toward institutional communications in times of crisis.