Overview
- The Justice Department edited its Aug. 26 press release to say the Senate, the Federal Reserve, NASA and other agencies were “targets” of QTFY rather than universally confirmed victims.
- An FBI affidavit and joint U.S. cyber advisories identify specific confirmed intrusions in September 2024 at three Department of Energy national labs, the National Institutes of Health, an HHS agency and a U.S. security device maker.
- Investigators found an attempted breach of NASA was blocked after the agency patched the targeted software, underscoring that some intrusions were unsuccessful.
- Authorities seized domains tied to QTFY to disrupt its proxy and botnet infrastructure, but officials say technical operations and further investigation continue because the full scope of data theft remains unresolved.
- China’s embassy denied the allegations and criticised U.S. actions, while filings show QTFY allegedly used automated scanning, compromised routers and leased infrastructure to hide origins, raising persistence and supply‑chain risks.