The US Department of Justice has quietly softened its account of a major case of hacking by China. On Friday, August 28, it edited a press release issued just two days earlier — one that had named the US Senate, the Federal Reserve, and NASA as victims of a Chinese state-sponsored group. The revised version calls them targets instead. The wording change is small; the meaning behind it is not.
The original statement, released August 26, announced court-authorized seizures of domains behind two hacking platforms, QScan and QTRouter. Court documents unsealed in the Southern District of California named the operator as QTFY, a group employed by Nanjing Xinjiuwei Network Technology Company, which the department said sold hacking services to paying clients — including China’s Ministry of State Security and the People’s Liberation Army.
That distinction carries real weight — being scanned isn’t the same as being breached. A footnote in the FBI affidavit notes the attempt on NASA failed because the agency had already patched the vulnerable software. Confirmed intrusions, by contrast, came later: the same document places them in September 2024, naming three Department of Energy national laboratories, the National Institutes of Health, and an agency within Health and Human Services. A US security device manufacturer was breached as well.
Why the Announcement Against China Was Rushed
Three pressures likely drove the haste.
First, takedown operations move fast, and officials wanted three elements to land together: the domain seizure, a joint FBI–NSA advisory, and a technical report from Lumen’s Black Lotus Labs. Compressing a lengthy affidavit into a few paragraphs of press copy was the price of that coordination.
Second, the two documents answer to different audiences. An affidavit must satisfy a judge; a press release must survive a news cycle — and “victims” reads harder than “targets.” Newsrooms reacted accordingly: within hours, CNBC and others were reporting the Fed, NASA, and the Senate as victims of computer intrusion.
Third, political framing shaped the rollout. FBI Director Kash Patel said the seized tools had let Chinese actors “hide the origin of their attacks” and linked the operation to President Trump’s broader cyber strategy, while Attorney General Todd Blanche vowed to dismantle hacking sponsored by the People’s Republic of China. Neither official paused to distinguish a scan from a breach.
Does China’s Track Record Explain the Claims?
Washington isn’t inventing this pattern from scratch. The Justice Department disrupted the Volt Typhoon botnet in 2023, disabled a Flax Typhoon network in 2024, and stripped PlugX malware from thousands of American computers in 2025. Separately, allied agencies say Salt Typhoon compromised roughly 600 organizations across 80 countries, including telecom carriers.
The QTFY case fits a newer model, too: court documents describe a private Chinese firm selling intrusion tools to the state rather than a military unit running operations directly — a structure that gives Beijing distance from the attacks and complicates attribution, since one platform can serve multiple buyers at once.
Given that history, officials had reason to assume the worst. But assumption isn’t evidence, and each correction hands Beijing a talking point while making the next US warning a little easier to dismiss.
Is Washington Building an Anti-China Atmosphere?
Beijing argues that it is. Foreign Ministry spokesman Lin Jian called the allegations false and accused Washington of “distorting right and wrong,” while the Chinese Embassy said the US routinely uses cybersecurity claims to “smear or discredit China” — the same script Beijing has used in response to similar accusations since 2021.
The timing invites scrutiny.
Washington reportedly plans to impose a 7.5 percent overcapacity tariff on Chinese goods. A Trump–Xi summit will follow next month. Against this backdrop, the hacking announcement two days later fits neatly into the broader sequence.Still, the claims rest on more than rhetoric. Authorities hard-coded the seized domains into the malware, so the takedown rendered both platforms inoperable. The FBI and NSA also published indicators of compromise dating back to 2018, providing technical evidence rather than mere press language.
What’s Still Unknown
The department hasn’t published a damage assessment, hasn’t disclosed what data left the compromised networks, and hasn’t named the affected laboratories or companies.
The joint advisory does add some detail, noting failed attempts against the Senate and an American hospital system in March 2026, and another against an unidentified election system in June 2026.
The FBI and the Cybersecurity and Infrastructure Security Agency did not respond to Reuters on Friday, nor did the Chinese Embassy comment. For now, the claims stand narrowed — not withdrawn.








