U.S. corrects QTFY cyberespionage notice
The Justice Department said several named agencies were targets, not confirmed victims, in a campaign attributed to QTFY.
The U.S. Justice Department corrected a notice on a cyberespionage campaign attributed to QTFY, a group allegedly linked to China, after clarifying that several federal agencies and financial entities named in the original release were detected targets, not confirmed victims. Reuters and other reports said some of those targets were in fact breached.
The U.S. Justice Department corrected a notice on a cyberespionage campaign attributed to QTFY, allegedly backed by the People’s Republic of China, after clarifying that several federal agencies and financial institutions named in the original release were detected targets, not confirmed victims. Available reporting places the operation against federal networks and sectors including energy, defense, telecom, utilities, hospitals and banking, with some cases involving successful access and others limited to attempted intrusion.
What did the Justice Department correct?
The Justice Department clarified that its initial version described all of the agencies as victims, when the affidavit showed that all had been targeted by the campaign, but only some had confirmed intrusions. Reuters said the correction was made because the original notice mixed up targets and victims, and that some of the named entities had not been compromised.
The campaign was attributed in secondary sources to the group QTFY, also referred to as QT or QTCYBER in a joint notice from the FBI, the NSA and the Cyber National Mission Force. That notice said China-linked actors had developed malicious distributed platforms to compromise networks belonging to organizations in the U.S. and abroad.
What targets did the reporting mention?
The reporting named U.S. federal networks that include the Department of Energy, NIH, HHS, the Federal Reserve, NASA, the Justice Department and the Senate. It also pointed to targets in financial firms, defense contractors, utilities, telecommunications companies and hospitals, although not all were identified as confirmed victims.
Reuters added that the affidavit alleged computer intrusions in September 2024 against three DOE national laboratories, NIH, an HHS agency and a U.S. manufacturer of security devices. The same report said it was not publicly identified which of those intrusions succeeded at each target.
What techniques and scope were described?
Cybersecurity Dive reported that the FBI and the Justice Department seized domains tied to a years-long campaign attributed to QTFY aimed at critical infrastructure and U.S. government agencies. According to the NSA and FBI notice cited in that coverage, the attackers used zero-day and n-day vulnerabilities for initial access and credential theft to maintain persistence.
Reuters added that the joint notice included successful data theft in May 2024 against defense contractors, financial entities and universities. It also reported failed access attempts against the U.S. Senate and a U.S. hospital in March 2026.
How was attribution presented?
Security Current and SC World reported that the operation was attributed to a China-based entity in Nanjing, Xinjiuwei Network Technology Company, and that the seized platforms were QScan and QTRouter. Moncloa.com, meanwhile, said the FBI and the Justice Department dismantled a network active since 2018 and attributed to QTFY, with the attribution based on a government-funded front company and former military personnel, according to that secondary source.
Sources
- Federal authorities disrupt China-backed hacking ...cybersecuritydive.com· Cybersecurity Dive
- US denies access to China-linked group behind hacking federal agenciesscworld.com· SC World
- DOJ corrige sus declaraciones sobre el hackeo chinoinvestx.fr· Investx.frUnverified URL
- EE.UU. matiza impacto de ciberataques chinos a sus agenciastvn.cl· TVN Chile
- US officials revise claims that government agencies were hacked by Chinesereuters.com· ReutersUnverified URL
- US officials revise claims that government agencies were hacked by Chinese, now say they were targetsinternazionale.it· Internazionale / Reuters
- FBI y Justicia de EE.UU. desarticulan una red de espionaje chino que comprometió infraestructura crítica desde 2018moncloa.com· Moncloa.com



