August 29, 2026
QTFY Targeted Federal Networks for Years. Four Named Agencies Later Lost 1,503 IT Employees.
FederalHiringData found four QTFY-targeted agencies lost 1,503 broad IT-management employees as public cyber controls and recruiting diverged.
By Evan Mercer
Published August 29, 2026Last edited August 29, 2026

The Justice Department's first public account of the QTFY hacking campaign named a striking list of federal targets: NASA, the Federal Reserve, the departments of Energy, Justice and Health and Human Services, the National Institutes of Health and, in 2026, the U.S. Senate.
Two days later, DOJ added an important note. Its Aug. 26 release had been edited so it would accurately reflect the affidavit used to seize the group's domains. The distinction matters. The public record does not say every named agency was hacked. It describes a mixture of scanning, attempted exploitation, activity with an unstated outcome and confirmed intrusions.
NASA provides the clearest counterexample to an easy headline. According to the FBI affidavit, QTFY actors tried to exploit a remote-access appliance at the agency in August 2019. NASA had already applied the available patch. The attempt was unsuccessful.
The record later becomes more serious. In September 2024, the affidavit says, QTFY actors conducted intrusions at three Department of Energy national laboratories, NIH, another HHS agency and a U.S. security-device manufacturer. The joint federal advisory identifies that HHS agency as the Health Resources and Services Administration. Those six entities are described as victims.
That range of outcomes is the central fact for understanding the workforce behind federal cyber defense. People matter, but headcount alone neither creates nor defeats an intrusion. Patching, architecture, asset visibility, configuration, shared defenses and contractor capacity matter too.
FederalHiringData found that the broad Information Technology Management workforce nevertheless contracted sharply across four of the named executive departments that can be measured consistently in public Office of Personnel Management records. NASA, Energy, Justice and HHS together had 9,091 series-2210 employees in December 2024. By June 2026, they had 7,588 - 1,503 fewer employees, a decline of 16.5%.
That is not a count of federal cybersecurity workers. Series 2210 includes many kinds of IT work, and cyber roles also exist outside it. It is the longest consistent agency-level capacity measure available across the named targets. Its movement raises a serious workforce question without answering an incident-causation question the data cannot support.
What the government actually alleged
The corrected DOJ release says the China-linked group developed two complementary platforms used to scan, exploit and conceal activity through compromised internet-connected devices. Court-authorized seizures disabled key domains on which those platforms depended. The release says the edits were made to align the public description with the affidavit.
The joint advisory from the FBI, National Security Agency and Cyber National Mission Force supplies a sample timeline. It dates QTFY's activity to at least 2018 and separates unsuccessful access attempts from the later victim intrusions.
In May 2018, the group scanned Energy systems but did not gain access. In August 2019, it used an exploit against DOJ, the Federal Reserve and NASA. The advisory does not state the outcomes at DOJ or the Federal Reserve. The affidavit provides NASA's missing result: the patch was already in place, so the attempt failed.
In March 2020, scanning at HHS also failed to gain access. In September 2024 came the six intrusions involving three Energy laboratories, NIH, HRSA and the private manufacturer. In March 2026, QTFY scanned the Senate and again failed to gain access, according to the advisory.

The chronology prevents two opposite errors. Calling every target a breach overstates the government's evidence. Treating all the activity as harmless scanning understates the documented intrusions.
It also places workforce change in the correct order. Much of the named targeting occurred years before the 2025-2026 staffing contraction. The data cannot show that later personnel losses caused earlier incidents. At most, it can show how the measurable staffing base changed while agencies continued to face a threat that federal investigators say had operated for years.
Four workforces moved differently before falling together
FederalHiringData tracked monthly OPM employment at NASA, Energy, Justice and HHS from January 2018 through June 2026. The comparison uses parent-agency codes and avoids adding NIH separately because NIH is already inside HHS.
The four agencies did not share one trajectory. NASA's series-2210 workforce rose from 431 employees in January 2018 to 664 in January 2025. Energy rose from 622 to a peak of 933 in February 2025. HHS increased from 3,254 to 4,129 in January 2025. Justice moved more gradually, from 3,179 in January 2018 to a peak of 3,432 in October 2024.
By June 2026, all four were below their late-2024 or early-2025 highs.

HHS recorded the largest numerical change after December 2024: 4,079 series-2210 employees became 3,137, a decline of 942 or 23.1%. The NIH subelement moved from 942 to 765 during the same period, a decline of 177. NIH is a subset of the HHS total, not an additional row to add.
Justice fell by 257, from 3,430 to 3,173, or 7.5%. Energy fell by 175, from 923 to 748, or 19.0%. NASA fell by 129, from 659 to 530, or 19.6%.

| Agency | Dec. 2024 all employees | June 2026 all employees | Total change | Dec. 2024 series 2210 | June 2026 series 2210 | 2210 change |
|---|---|---|---|---|---|---|
| Health and Human Services | 93,035 | 72,919 | -20,116 | 4,079 | 3,137 | -942 |
| Department of Justice | 117,379 | 107,082 | -10,297 | 3,430 | 3,173 | -257 |
| Department of Energy | 17,607 | 13,339 | -4,268 | 923 | 748 | -175 |
| NASA | 17,999 | 14,248 | -3,751 | 659 | 530 | -129 |
The larger denominator matters. Total employment in the four-agency panel fell 15.6%, from 246,020 to 207,588. Series 2210 fell 16.5%. The technical category contracted slightly faster, but not so differently that it can be separated from the broader 2025-2026 workforce reduction.
Related research
Put this finding in context

Data investigationsAugust 22, 2026
Two Army Depots Lost 785 Government Workers as Repair Work Became Harder to Plan
Anniston and Red River added 241 contractor personnel, but skills gaps, vehicle condition, parts, drawings and old machinery complicated billions in repair work.

Data investigationsAugust 24, 2026
TSA Has More Than 1,300 Aviation Inspectors. Its Cybersecurity Role Map Is Outdated.
TSA added aviation cybersecurity requirements as its broad inspection and compliance workforce contracted and its public cyber role map remained outdated.
The age pattern does not support a simple retirement story either. Employees age 50 or older were 50.7% of the panel's 2210 workforce in December 2024 and 48.9% in June 2026. Older employees declined, but younger groups did too. An age share is not a retirement forecast, and OPM's employment snapshots do not attach a reason to each departure.
The Federal Reserve Board and Senate are excluded from this workforce panel. The current OPM “Federal Reserve System” agency record contains the Consumer Financial Protection Bureau, not a comparable Board workforce. The legislative branch is not represented on the same basis. Substituting those records would create false precision.
Personnel actions show an abrupt reversal
The employee snapshots show the result. OPM's accession and separation files show the flow of recorded actions around it.
Across the four agencies, series 2210 recorded 877 accession actions and 526 separation actions in fiscal 2024. In fiscal 2025, accessions fell to 393 while separations rose to 1,473. That is 3.7 separation actions for each accession action.
Fiscal 2026 was still imbalanced through June: 320 accessions and 579 separations. Because that period covers only October 2025 through June 2026, it should not be compared with a full fiscal year as though both were complete.

The agency details again diverged. HHS recorded 207 accession actions and 893 separation actions in fiscal 2025. Justice recorded 115 and 405; Energy, 42 and 111; NASA, 29 and 64.
By fiscal 2026 through June, NASA had recorded 145 accessions and 146 separations, much closer to balance than the other agencies. HHS recorded 27 accessions and 213 separations. Justice recorded 124 and 171; Energy, 24 and 49.
These are personnel actions, not necessarily unique people. A transfer can create an exit in one organization and an entry in another. Corrections, timing and reorganizations also prevent the action totals from matching snapshot change exactly. The files establish a sharp shift in recorded movement, not a roster of cyber specialists who left.
The recruiting channel narrowed, then partially reopened
The FederalHiringData historical USAJOBS archive provides a separate view of public recruiting. It contains announcement records, not vacancies or hires. One announcement may list one, many or an unspecified number of openings, and the archive does not reveal applications, referrals, interviews or selections.
Across NASA, Energy, Justice and HHS, the archive contains 1,388 series-2210 announcements opened in 2024. The total fell to 238 in 2025. Through Aug. 14, 2026, the partial-year count had reached 273.
A narrower title proxy shows a similar but more selective pattern. FederalHiringData counted titles containing “cyber,” “cybersecurity,” “information security,” “infosec” or “IT security.” The four agencies produced 174 such announcement records in 2024, 18 in 2025 and 53 through Aug. 14, 2026.

The strict title filter is not an official cyber workforce code. It misses security work hidden behind generic titles and may capture jobs that combine cyber duties with broader IT management. It is useful because the rule is transparent and reproducible, not because it is complete.
The 2026 partial-year signal was uneven. Justice had 21 strict-title records, HHS 19 and Energy 13. NASA had none through Aug. 14 despite 15 broader series-2210 announcements. The Senate, outside the four-agency OPM panel, had nine strict-title records. The Federal Reserve Board had none in the archive's 2026 period.

Federal Hiring Data Weekly
Get the biggest federal workforce changes in your inbox.
Subscribe to Federal Hiring Data Weekly for federal hiring trends, salary data, agency movements, and original investigations, with email confirmation before delivery.
The visible openings leaned senior. Eighteen of Justice's 21 strict-title records began at GS-13 or above; so did 14 of 19 at HHS and 10 of 13 at Energy. Only two of those 53 executive-agency records began at GS-9 or below. Thirty-one named a clearance level. None was confirmed fully remote, while 24 were marked telework eligible.
The median advertised maximum was about $187,093 for Justice and HHS and $149,091 for Energy. Those are announcement ceilings, not promised salaries or payroll averages. Grade and pay-plan rules, qualifications, location and final step-setting determine actual offers.
The mix suggests agencies were seeking experienced technical staff more often than building a large entry pipeline. It does not show whether they filled those jobs.
Public security reviews show different control problems
Staffing is only one layer of defense. Public Inspector General evaluations provide a second, imperfect layer: whether selected security processes were mature and effective.
The reports cannot be ranked like a common scorecard. They cover different systems, samples, periods and methods. Their findings nevertheless show that the named agencies entered the current threat period with different control records.
| Entity | Public review | Result | Published metric | Scope caution |
|---|---|---|---|---|
| NASA | FY2025 FISMA | Level 3, below the effective threshold | 22 of 27 prior recommendations closed; 5 remained | Agency program evaluation |
| Department of Energy | FY2024 cybersecurity evaluation | Additional effort needed | 44 prior recommendations remained; 79 new recommendations issued; 120 open at year-end | 29 locations; maturity testing at 6 |
| Department of Justice | FY2025 FISMA reviews | Weaknesses in 7 of 10 domains | 32 recommendations | Selected components and 15 systems |
| Health and Human Services | FY2025 FISMA | Not effective for sixth consecutive year | Core Level 3; supplemental Ad Hoc; 10 recommendations | Systems from 5 divisions |
| Federal Reserve Board | FY2025 FISMA | No longer effective | 3 new recommendations; 18 prior remained open | Board information-security program |
NASA's FY2025 FISMA evaluation rated the program “Consistently Implemented,” one level below the “Managed and Measurable” threshold considered effective. The OIG said NASA had closed 22 of 27 prior recommendations. It also found recurring gaps in risk documentation, supply-chain risk tracking and privileged-access controls.
That rating did not prevent NASA from patching the appliance before QTFY's 2019 attempt. One effective control can matter even when an enterprise program remains below a maturity threshold. Conversely, one blocked attempt does not prove every NASA system was secure.
Energy's FY2024 evaluation reported weaknesses across all five cybersecurity framework functions then in use. Eight reviewed sites had vulnerability-management processes that were not fully effective. The OIG said 44 earlier recommendations remained open, issued 79 new ones and counted 120 open at fiscal year-end after some actions closed.
HHS's FY2025 audit rated the department's program not effective for a sixth consecutive year. The report said the 2025 workforce optimization initiative affected HHS's ability to demonstrate that selected Govern, Identify and Detect activities had been performed. That is an audit limitation and a control finding, not proof that the workforce change caused the 2024 intrusions.
Justice's OIG reported weaknesses in seven of 10 FISMA domains across selected components and systems and issued 32 recommendations. The Federal Reserve Board OIG said its program's maturity declined in 2025 and was no longer effective.
These public assessments support scrutiny. They do not reveal the condition of every system QTFY touched, and some sensitive findings remain nonpublic.
Why headcount is not the whole defensive system
NASA's patch is the simplest reason not to convert 1,503 employees into a breach explanation. The federal advisory's own top recommendations focus on actions: install current software and firmware, audit internet-facing applications, isolate critical systems from edge devices and hunt for indicators.
Agencies also operate inside shared federal defenses. CISA says all 23 CFO Act agencies share cyber-risk information through Continuous Diagnostics and Mitigation dashboards, giving the agency an integrated view of the unclassified federal enterprise. Binding Operational Directive 23-01 requires asset discovery and vulnerability scanning and offers technical and program assistance. Shared tools do not replace agency staff, but agency headcount does not measure them.
Contractors are another major missing denominator. DOE says 16 of its 17 national laboratories are government-owned but contractor-operated. OPM employment records count federal civilians, not the private-sector employees who operate those laboratories. The three laboratories compromised in 2024 cannot be reduced to the 748 federal Energy employees coded 2210 in June 2026.
Cloud providers, managed-service vendors, software companies and incident-response contractors also contribute capacity. Public records do not provide a comparable agency-by-agency contractor cyber count. Federal workers and contractors must therefore remain separate rather than being silently combined.
The same caution applies to occupations. A 2210 employee may manage applications, networks, data, policy, customer support or security. A cyber defender may instead be coded as an engineer, computer scientist, investigator or intelligence specialist. Agencies increasingly use cyber work-role codes, but the local long-run OPM series does not expose a consistent governmentwide role field.
A stronger measure would connect approved cyber work roles to people, assignments, contractors and mission systems over time. It would also distinguish a vacancy from a filled position and a general IT specialist from someone responsible for vulnerability management, identity, incident response or threat hunting. No public governmentwide file currently provides that longitudinal combination. The broad 2210 trend is therefore useful as a warning about technical capacity, but not as a count of defenders available on the dates of particular QTFY activity.
The workforce question the public record can answer
The QTFY documents establish a persistent campaign and a mixed record of federal outcomes. The workforce data establishes a broad technical contraction after 2024. The FISMA reports identify control gaps, while NASA's blocked attempt, CISA's shared services and DOE's contractor model show why defenses extend beyond a payroll count.
Those records do not prove that the 1,503-person decline enabled an intrusion. They do support a more useful question for oversight: as agencies rebuild or reorganize technical capacity, can they show which defensive work roles remain, which functions contractors perform, how quickly critical vulnerabilities are remediated and whether recruiting produces hires at the grades agencies need?
The current public metrics do not answer those questions consistently. Series 2210 is too broad. Announcement titles are too incomplete. FISMA reviews are differently scoped. Contractor staffing is not comparable. Classified defenses are appropriately absent.
That measurement gap matters because the threat record is not hypothetical. Some attempts failed. Some outcomes were not stated. Six entities were described as victims. A mature public account should be able to hold all three facts at once.
Methodology and limitations
FederalHiringData used the corrected Aug. 26 DOJ release, the supporting FBI affidavit and the Aug. 26 joint advisory from the FBI, NSA and Cyber National Mission Force to classify federal QTFY activity. “Targeted” is used unless a primary record explicitly describes an intrusion, victim or unsuccessful attempt. The advisory says its timeline is a sample, not a complete incident census. No exploit detail beyond the public records is reproduced here.
Workforce calculations use monthly OPM employment records for parent agency codes NN, DN, DJ and HE from January 2018 through June 2026. HHS includes NIH, so NIH is shown only as a subset and never added to the panel total. Federal Reserve Board and Senate workforces are excluded because comparable OPM agency records are unavailable. Headcount is not budget FTE.
Series 2210 Information Technology Management is a broad technical proxy, not a cyber-only workforce. Personnel-action files count accession and separation actions, not unique people. Transfers, corrections and timing mean actions do not mechanically reconcile to monthly headcount change. Fiscal 2026 is partial through June.
USAJOBS calculations use distinct control numbers in the FederalHiringData historical archive. Coverage begins in March 2017; charts begin with 2018, the first full year, and end Aug. 14, 2026. The strict title proxy matches cyber, cybersecurity, information security, infosec or IT security. Announcements are not vacancies, applications, referrals, interviews, selections or hires. Advertised salary is not payroll salary.
Public FISMA findings are presented with their scopes and are not treated as directly comparable ratings. OPM federal employees are not contractor employees. The analysis cannot observe classified systems, every current work-role code, all contractor support, system inventory, patch time or incident workload. Research and writing used no OpenAI API calls.
Readers can inspect current federal job announcements, compare broader federal workforce statistics, read the related investigation of the federal cyber rotation program, or browse more FederalHiringData reporting.
Related research
More from FederalHiringData

Data investigationsAugust 25, 2026
The Coast Guard Plans to Add 15,000 Military Members. Only 26% of Its Workforce Requirements Are Current.
Recruiting rebounded, but cutter vacancies widened and covered civilian employment fell 9.9% as Force Design accelerated.

Data investigationsAugust 22, 2026
Space Force Filled 75% of Its Documented Need. Now It Says Personnel Must Double.
A GAO review found 13,509 assignments against 18,002 documented requirements as the service planned to double personnel without a complete workforce ledger.

Data investigationsAugust 20, 2026
634 Applications, Eight Completed Rotations: Why the Federal Cyber Exchange Stalled
Employees showed interest in the federal cyber rotation program. Home-agency approval, unreimbursed staffing costs and senior qualification demands narrowed the path.
Federal Hiring Data Weekly
Get the biggest federal workforce changes in your inbox.
Subscribe to Federal Hiring Data Weekly for federal hiring trends, salary data, agency movements, and original investigations, with email confirmation before delivery.