Cybersecurity

US Treasury Hacked by Suspected Chinese Actors, Officials Confirm

U.S. Treasury officials have announced that the department was targeted in a cyberattack believed to be orchestrated by Chinese state-sponsored actors. According to reports, the breach enabled these hackers to penetrate government workstations and view unclassified documents after obtaining a security key that bypassed existing protective measures.

The incident came to light following a message from the third-party software supplier, BeyondTrust, which alerted the Treasury on December 8. Following this notification, the Treasury informed the Senate Banking Committee, labeling the event a “major incident,” which aligns with its policy on nation-state hacking breaches. Specific details about how many workstations were compromised or the exact documents accessed remain unclear, but officials stated that there is no current evidence suggesting that the hackers still have access to Treasury systems.

In response to the breach, the Treasury quickly engaged with the Cybersecurity and Infrastructure Security Agency (CISA) and disabled the affected BeyondTrust service. A Treasury spokesperson articulated the department's commitment to safeguarding its systems and data, noting significant improvements in their cyber defenses in recent years and ongoing collaboration with both private and public sector partners.

Assistant Treasury Secretary Aditi Hardikar also confirmed the attribution of the hack to Chinese actors, labeling them as a state-sponsored Advanced Persistent Threat (APT) group. The attack involved exploiting a security key, which allowed the perpetrators to remotely access various Treasury workstations and unclassified files. CISA was alerted as soon as the Treasury became aware of the breach, and further notifications were disseminated as the situation unfolded.

In response to these allegations, the Chinese embassy in the U.S. has denied any wrongdoing, dismissing the accusations as unfounded and indicative of a smear campaign. They condemned the U.S.'s claims as lacking factual basis. The Treasury has committed to providing additional details on the situation to lawmakers within the next month.

BeyondTrust has acknowledged the security incident, stating they acted swiftly to mitigate the issue and notified affected customers and authorities of the breach. A cybersecurity expert pointed out that this hack aligns with established tactics used by groups linked to the People's Republic of China, particularly emphasizing their method of exploiting trusted third-party services.

Read-to-Earn opportunity
Time to Read
You earned: None
Date

Post Profit

Post Profit
Earned for Pluses
...
Comment Rewards
...
Likes Own
...
Likes Commenter
...
Likes Author
...
Dislikes Author
...
Profit Subtotal, Twei ...

Post Loss

Post Loss
Spent for Minuses
...
Comment Tributes
...
Dislikes Own
...
Dislikes Commenter
...
Post Publish Tribute
...
PnL Reports
...
Loss Subtotal, Twei ...
Total Twei Earned: ...
Price for report instance: 1 Twei

Comment-to-Earn

5 Comments

Avatar of Habibi

Habibi

It's absurd that the U.S. is pointing fingers while they can't even secure their own systems properly.

Avatar of Comandante

Comandante

Claiming it was state-sponsored does not mean it is true. The lack of evidence is highly concerning.

Avatar of Coccinella

Coccinella

Sounds like the U.S. is trying to distract from their own internal issues by blaming an external enemy.

Avatar of The Truth

The Truth

Cybersecurity is an inside job. Blaming external actors won’t solve the issue if the U.S. doesn’t get its house in order.

Avatar of Comandante

Comandante

This is just another baseless accusation against China. Why can't the U.S. own up to its own cybersecurity failures?

Available from LVL 13

Add your comment

Your comment avatar