The Justice Department Rewrites Its Hacking Announcement
The US Justice Department has quietly rewritten a press release that claimed Chinese hackers had targeted numerous federal agencies, including the Senate, Federal Reserve, NASA, Department of Energy, Health and Human Services, and several other institutions.
The original announcement, issued on August 26th, stated that these organizations were victims of a cyberattack, while the revised version, published two days later, clarifies that they were merely targets, and only some were successfully compromised.
The amended release includes a statement: "Edits have been made to ensure this press release accurately reflects the government’s allegations in the affidavit in support of the domain seizures." This suggests a discrepancy between the initial release and the affidavit upon which it was based.
While state-sponsored cyberattacks on federal agencies are not uncommon, the specific details of this case are significant. The affidavit details confirmed intrusions, but fewer than initially reported, with some breaches dating back to 2024.
The operation involved multiple American agencies, including the FBI, National Security Agency, US Cyber Command, Justice Department, and CISA, resulting in the seizure of domains associated with the campaign. Domain seizures are a typical response to such incidents, as they disrupt the infrastructure used by the attackers without requiring arrests.
The cause of the error in the original release remains unknown. There has been no official explanation or identification of the person responsible for the correction.
For European security teams, the practical implications lie in the specific tactics, timeline, and target selection of this Chinese espionage group, which are not limited to the US or Europe.