Technology

US Officials Walk Back Claim That Chinese Hackers Breached Agencies

The Justice Department quietly revised a press release on Friday, two days after announcing that a Chinese state-sponsored hacking group had breached the Federal Reserve, NASA, the U.S. Senate and several other federal agencies. [1] The newly edited version says those organizations were "among the targets" of the group, tracked as QTFY, rather than confirmed victims — a narrower claim that the department attributes to a drafting error, not new evidence. [1]

The original August 26 announcement, accompanying the FBI's seizure of domains used by the hackers, described a years-long espionage campaign against the Senate, the Federal Reserve, the Department of Justice, the Department of Energy, the Department of Health and Human Services, the National Institutes of Health, and NASA. [2] Coverage that day, including a CNBC report naming each agency as a target of the breach, took the announcement at face value. [2] The Justice Department's Friday correction explained the walk-back plainly: the August 26 release "described all agencies as victims whereas the government's affidavit made clear that all were targeted but only some were compromised." [1]

The distinction is not cosmetic. A footnote buried in the underlying FBI affidavit states that the bureau investigated the targeting of NASA specifically and found the attempted breach unsuccessful, because the agency had already patched the software the hackers were trying to exploit. [1] The affidavit does describe confirmed "computer intrusions" — at three Department of Energy national laboratories, an NIH agency, an HHS agency, and a security device manufacturer, in September 2024 — a narrower set than the roster named in Wednesday's headline-grabbing announcement. A separate joint advisory from the FBI, NSA, and Cyber Command, published the same Wednesday, listed successful data thefts from unnamed defense contractors and universities in 2024, alongside a specifically unsuccessful attempt against the Senate and a hospital network in March 2026. [1]

The shape of this walk-back is not unfamiliar to readers of this paper. It is the same pattern traced twice this week on the Strait of Hormuz — a confident initial claim, difficult to verify independently, quietly narrowed once the underlying document is read closely. There, U.S. Central Command's claim that Iranian sea mines had been cleared met an on-the-record denial from Iran's deputy foreign minister within hours. Here, the correction came from inside the U.S. government itself, with no adversary required to force it — arguably more troubling, since it suggests the overstatement was caught only after the fact.

The Chinese Embassy, responding to Wednesday's original announcement, accused the United States of using cybersecurity claims to "smear or discredit China." [1] The embassy did not address Friday's correction, and messages seeking comment from the FBI went unanswered. [1] What remains undisputed is narrower than first announced: a genuine, years-long targeting campaign, a handful of confirmed intrusions at second-tier facilities, and a first-tier list of marquee agencies — the Senate, the Federal Reserve, NASA — that the government itself no longer says was actually breached.

-- DAVID CHEN, Beijing

Get the New Grok Times in your inbox

A weekly digest of the stories shaping the timeline — delivered every edition.

No spam. Unsubscribe anytime.