DOJ walks back claims that QTFY breached NASA and the Senate
An edited Friday statement said the Senate, the Federal Reserve and NASA were targets of the Chinese state-linked group, not confirmed victims. Court papers still describe September 2024 intrusions at three Energy Department labs, NIH and an HHS agency.

Washington3 min read
Last updated
The Justice Department spent Friday correcting its own announcement. On 26 August the department and the FBI said they had seized domains used by QScan and QTRouter, two platforms they tied to a Chinese state-sponsored group called QTFY. The original public language treated several U.S. government networks as hacked. By Friday the department had edited the statement. Reuters reported that the Senate, the Federal Reserve, NASA and other named agencies were now described as “among the targets of QTFY,” not as confirmed victims of a completed breach.
The distinction is not cosmetic. An FBI affidavit filed in the Southern District of California, and unsealed with the original notice, said QTFY had “targeted” federal networks including NASA, the Federal Reserve, the Department of Energy, the Department of Justice, Health and Human Services, the National Institutes of Health and the Senate since at least 2018. A footnote in the same affidavit said the attempted NASA breach failed because the agency patched the software that was being probed.
The affidavit is less cautious about September 2024. It alleges “computer intrusions” that month at three Energy Department national laboratories, NIH, an HHS agency and a U.S. security-device manufacturer, and it calls those entities victims. A joint advisory issued the same week by the FBI, the National Security Agency and U.S. Cyber Command listed successful thefts from unnamed defence contractors, banks and universities in May 2024, and unsuccessful attempts on the Senate and a hospital in March 2026.
What was seized
Prosecutors say QTFY works through Nanjing Xinjiuwei Network Technology Company, a private firm in Nanjing that sold scanning and proxy services to paying clients, among them China's Ministry of State Security and the People's Liberation Army. Court papers cite payments from the ministry to the company as evidence that the work was done for the state.
QScan is the hunter. It scans the public internet for weak internet-of-things devices, infects them, and hands them to QTRouter. QTRouter is the mask. It mixes those hijacked cameras and routers with commercial proxy nodes and rented virtual servers so that the next intrusion appears to come from a machine outside China, sometimes from a device on the same street as the target. The bureau said the network touched devices in more than 130 countries.
The operational cut on 26 August was a domain seizure. Without the domains used for command, authentication and updates, the two platforms stopped talking to the infected devices. FBI Director Kash Patel called it a disruption of a global botnet used against U.S. critical infrastructure. Attorney General Todd Blanche said state-sponsored hackers preying on that infrastructure would be stopped and prosecuted. No individual arrests in China were announced with the seizures.
The Check Point wave
Investigators say QTFY moved fast when a new flaw appeared. Court documents allege that in May 2024 the group used a freshly disclosed weakness in Check Point security equipment and stole server settings and user accounts from more than 300 U.S. organisations. That figure, if it holds, is the largest single harvest tied to this file. It is also the kind of event that makes a later correction on NASA and the Senate more, not less, important. A department that overstates a Senate breach and under-explains a 300-organisation theft will be read for both errors.
The Friday edit does not unwind the seizure. The domains are still in U.S. hands. The affidavit is still on the docket. What changed is the public map of who was hit and who was only aimed at. NASA, on the present record, patched and held. Three Energy labs, NIH and an HHS agency, on the same record, did not. Readers who saw Wednesday's headlines should keep both sentences.
Continue reading
- News
Carney plans a Turkey visit this month, the first dedicated one by a Canadian prime minister
Almanaque Digital DeskOttawa
- News
Palace says Charles will not apologise for slavery on the Caribbean tour
Almanaque Digital DeskLondon
- News
Sheinbaum wants a bill next week ordering platforms to pull violent posts