US authorities have corrected earlier claims that several major government agencies had been hacked by a Chinese state-sponsored cyber group, clarifying that some were targeted but not necessarily compromised.The US Department of Justice said on Friday that the Senate, Federal Reserve, NASA and several other agencies were “among the targets” of QTFY, a China-linked hacking group accused of conducting a years-long cyber-espionage campaign.The correction narrows the scope of the breaches confirmed by US authorities. The DOJ said an earlier statement released on August 26 had incorrectly described all the agencies as victims, while an FBI affidavit showed that they had all been targeted but only some were successfully compromised.FBI affidavit reveals scope of hacking campaignAccording to the FBI affidavit, QTFY has targeted US federal networks since at least 2018, including those belonging to Nasa, the Federal Reserve, the Department of Energy, the Justice Department, the Department of Health and Human Services, the National Institutes of Health and the US Senate.The affidavit also provides details about the outcomes of some of the attacks. An FBI investigation found that an attempted intrusion into NASA was unsuccessful after the agency patched the software targeted by the hackers.However, US authorities said the group successfully carried out intrusions in September 2024 at three Department of Energy national laboratories, an NIH facility, an HHS agency and a US security-device manufacturer.A joint advisory from the FBI, National Security Agency and US Cyber Command also said hackers had successfully stolen data from unnamed defence contractors, financial institutions and universities in May 2024. Attempts to access the networks of the US Senate and a US hospital in March 2026 were unsuccessful.US seizes hacking infrastructureThe clarification came as US authorities announced the seizure of two internet domains allegedly linked to QTFY’s hacking infrastructure, known as QScan and QTRouter.The DOJ alleged that the platforms were operated by a China-based company and used to scan and infect internet-connected devices, creating a network that could route malicious traffic through compromised systems around the world. This allegedly helped hackers conceal the true origin of attacks.FBI Director Kash Patel said the tools were used by Chinese cyber actors to hide the source of attacks targeting US critical infrastructure.The DOJ said the seized domains were embedded in the malware and were required for communication and authentication, making QScan and QTRouter inoperable after the court-authorised seizures.China’s embassy in Washington rejected the US allegations, accusing Washington of using cybersecurity claims to “smear or discredit China”.
Click Here For The Original Source.
