Threat Intelligence

DoJ Walks Back Claim of Chinese Hack, Clarifies Agencies Were Targeted, Not Breached

The Hacker News · 31 Aug 2026
Key Takeaway When cyber incidents are reported, verify whether an organisation was actually breached or merely targeted before assuming data or systems were compromised.

The U.S. Department of Justice has issued a correction to a previous press statement that named several federal agencies as victims of a cyberattack attributed to Chinese state-linked threat actors. The agencies involved, including NASA, the Federal Reserve, the Department of Energy, and the DoJ itself, were initially described as having been compromised. The DoJ has now clarified that these organisations were targeted by the attackers, but this does not necessarily mean they were successfully breached.

This distinction matters significantly in cybersecurity reporting. Being 'targeted' means an organisation was in the sights of threat actors, whether through phishing attempts, network scanning, or exploitation attempts, but it does not confirm that attackers gained access to systems or data. Conflating the two can create unnecessary panic or misrepresent the actual severity and scope of an incident.

While this story centres on U.S. federal agencies, it serves as a useful reminder for Australian businesses about the importance of accurate incident communication. Organisations of all sizes should be cautious about jumping to conclusions when a cyber incident is reported, whether about themselves or third parties, and should verify the actual impact before reacting.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.