Business

‘Major incident’: China-backed hackers breached US Treasury workstations

By Sama Marwan,

The U.S. Treasury Department notified lawmakers on Monday that a China state-sponsored actor infiltrated Treasury workstations in what officials are describing as a “major incident.”

In a letter, Aditi Hardikar, the Assistant Secretary for Management at the Treasury, stated that “based on available indicators, the incident has been attributed to a Chinese state-sponsored Advanced Persistent Threat (APT) actor.”

The spokesperson added: “There is no evidence suggesting continued access to Treasury systems or information.”

The Treasury Department plans to hold a classified briefing next week for House Financial Services Committee staffers about the breach, although the timing of the briefing has not yet been confirmed.

China’s Foreign Ministry denied the hacking accusations, calling them groundless and lacking evidence. The ministry’s spokesperson, Mao Ning, reiterated China’s opposition to cyberattacks and false political claims.

The breach reportedly occurred through third-party software provider BeyondTrust. The attackers accessed a key used to secure a cloud service employed by the Treasury for technical support, allowing them to bypass security and access certain unclassified documents and workstations.

BeyondTrust identified the incident on December 2 and informed affected customers after confirming suspicious behavior on December 5. The company is investigating and working with law enforcement and an external cybersecurity team.

The exact number of compromised workstations is unclear, but several Treasury workstations were affected. The incident is being considered a “major cybersecurity incident” under Treasury policy, and officials are working with CISA, the FBI, and intelligence agencies to assess the damage.

CISA was notified immediately after the breach was detected, and other agencies were contacted as the full scope of the attack became evident.

 

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button