Severity Daily

IT and AI security incidents, checked against the primary source

Tag: attribution

  • The Justice Department edited its China hacking announcement to say seven agencies were targets, not victims

    The Justice Department edited its China hacking announcement to say seven agencies were targets, not victims

    The August 26 release named NASA, the Federal Reserve, and the Senate as victims of QTFY. Two days later it said they were among the targets, and the original sentence is gone.

    The Justice Department announced on Wednesday, August 26, 2026, that it and the FBI had seized the domains behind two hacking platforms run by a China state-sponsored group it tracks as QTFY. The release named seven federal bodies, and as originally published it described them as victims. On Friday, August 28, 2026, the department rewrote that description. The seven are now “among the targets of QTFY.”

    The page carries an “Updated August 28, 2026” stamp and a one-line editor’s note: “Edits have been made to ensure this press release accurately reflects the government’s allegations in the affidavit in support of the domain seizures.” The note does not say which sentence changed, and the original wording is not preserved anywhere on justice.gov. What the release said on August 26 is known from contemporaneous reporting by the Associated Press, not from the department.

    What happened

    The seizure itself is not in dispute. According to the release, the department obtained court authorization in the Southern District of California to seize domains hard-coded into two tools: QScan, which “automatically scans and infects thousands of internet-of-things devices” worldwide, and QTRouter, an obfuscation network that let operators “conceal the PRC-origin of their computer intrusion activities because the malicious communications appear to originate from computers … that are outside of the PRC.” Because the seized domains were used by both tools for communication and authentication, the department says taking them rendered the platforms inoperable.

    QTFY is described as employed by Nanjing Xinjiuwei Network Technology Company, which the government alleges “offers computer hacking services to its paying customers, including the PRC’s Ministry of State Security and the People’s Liberation Army.” Attorney General Todd Blanche is quoted saying, “State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped.” FBI Director Kash Patel is quoted saying the operation “seized adversary infrastructure and shut these platforms down.” The FBI’s San Diego Field Office and Cyber Division, the U.S. Attorney’s Office for the Southern District of California, and the National Security Cyber Section of the Justice Department’s National Security Division ran the case.

    The sentence that changed is the one that matters to anyone building a risk picture. The current text reads: “Among the targets of QTFY are the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health, and the U.S. Senate.”

    The Associated Press, which first reported the change, wrote that the August 26 version described all seven as victims, and that the department said the affidavit made clear all were targeted while only some were compromised. Severity Daily could not verify the original sentence against a primary source: the department replaced it in place, and the affidavit supporting the seizures is not published alongside the release. AP also reported an affidavit footnote stating that the attempted breach of NASA was unsuccessful because the agency had patched the software being targeted. That footnote is the only specific outcome for any of the seven that has surfaced publicly, and it reached the public through a reporter reading a court filing rather than through the announcement.

    AP reported that the FBI and CISA did not immediately respond to requests for clarification on the day of the edit. As of this writing, the department has not published a separate correction notice, a statement naming which agencies were compromised, or a copy of the original text.

    Why it matters

    “Target” and “victim” are not synonyms with different registers. One describes an attempt and the other describes an outcome, and the gap between them is the entire question a defender asks about someone else’s incident: did it work? The August 26 release answered that question for NASA, the Federal Reserve, the Department of Energy, the Justice Department, Health and Human Services, the National Institutes of Health, and the Senate. The August 28 release declines to answer it for any of them.

    That is not a small retreat, and it leaves the public record emptier than it was before the correction. The first version overstated compromise; the second removes the claim entirely and puts nothing in its place. Nobody outside the government now knows, from the government, whether any of the seven named bodies was breached. The one data point that exists — NASA’s patching held — points the other way, and it is not in the release.

    The mechanics of the correction compound the problem. An edit made in place, annotated only with a note that edits were made, is invisible to anyone arriving after the fact. A reader who opens the release today sees a clean, internally consistent document with no indication that its central factual claim was different two days earlier. Anyone who quoted the original — in a threat brief, a board update, a congressional statement, a vendor blog post — is now holding a quotation that cannot be checked against the source it came from. The department did not hide the edit, but it did not preserve what it edited, which for practical purposes puts the burden of proof on whoever copied it first.

    Reach is asymmetric here in the way it always is. The original announcement was a Wednesday press release from the Justice Department about Chinese state hacking of the Federal Reserve and the Senate; it traveled. The Friday edit was a silent word change on the same URL. Wire copy, aggregator summaries, and internal briefings written between Wednesday and Friday carry the stronger claim, and most of them will never be revisited.

    This publication has spent the past week documenting the same failure across very different records: a Microsoft exploited-in-the-wild flag that was set and then retracted with no note of what it had said, a vulnerability report deleted along with its author, and a CISA assessment of the PaperCut zero-days that still reads “none” for exploitation a day after the vendor said customers were being attacked. The common feature is not carelessness. It is that the systems publishing these records — press offices, advisory databases, scoring pipelines — are built to state the current position and not to preserve the previous one. Corrections are treated as maintenance rather than as news, even when the thing being maintained is the answer to whether a federal agency was breached.

    Government attribution statements get a level of deference that vendor advisories do not. They are cited in policy debates, procurement decisions, and insurance underwriting. That deference is reasonable, and it is exactly why the first draft has to be right, or the correction has to be as loud as the original. Here it was neither.

    What to do

    If you cited the August 26 release in anything that is still circulating internally — a threat briefing, a risk register entry, a slide claiming federal agencies were breached by this group — go back and check the wording you carried forward against the current text. The department’s position today is that these seven were among the targets. It has not said which, if any, were compromised, and you should not infer it.

    Do not treat the list of seven as a list of confirmed intrusions in any model you feed to someone else. If a vendor product or feed you consume asserts that the Federal Reserve or the Senate was breached by QTFY, ask what it is sourced to, and check whether the source is the pre-edit release.

    Keep dated copies of government press releases you rely on. Justice.gov publishes no diff, no revision history, and no archived prior version, so the only defense against an in-place edit is your own capture with a timestamp. This costs nothing and it is the difference between citing a source and citing a memory of one.

    On the operational side, the release is still useful. QScan targets internet-of-things devices at scale and QTRouter relays traffic through compromised machines outside China to disguise its origin. If you run edge devices, cameras, or routers with internet-facing management, the seizure removes two platforms but not the exposure that made them work. The affidavit’s one confirmed outcome is that patching stopped the attempt against NASA.

    Sourcing note

    Checked: the Justice Department press release “Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers,” read directly at justice.gov, including its “Updated August 28, 2026” stamp, its editor’s note, and the quotations from Blanche and Patel reproduced above. Associated Press coverage of the edit, published August 28, 2026, is the source for the original wording, for the department’s explanation that the affidavit distinguished targeting from compromise, for the NASA footnote, and for the FBI’s and CISA’s non-response.

    Not reached: the affidavit supporting the seizures, which is not linked from the release; the pre-edit text of the release, which the department did not preserve; cisa.gov, which returns 403 to automated fetching, so no CISA advisory was checked directly for this story.

    Unresolved: which of the seven named bodies, if any, QTFY compromised. The department asserted it on August 26, withdrew the assertion on August 28, and has not replaced it. Also unresolved is whether the pre-edit wording exists in any government-published form.