December 30th, 2024

China-backed hackers breached US Treasury workstations

The U.S. Treasury Department experienced a significant cybersecurity breach by a China-backed hacker group, leading to unauthorized access and collaboration with agencies to assess the damage and threats.

Read original articleLink Icon
China-backed hackers breached US Treasury workstations

The U.S. Treasury Department reported a significant cybersecurity breach attributed to a China-backed hacker group. The incident, described as a "major incident," involved unauthorized access to Treasury workstations using a stolen key from a third-party software provider, BeyondTrust. The breach was discovered on December 8, and the Treasury has since taken the compromised service offline. Treasury officials stated that there is currently no evidence of ongoing access to their systems. A classified briefing for lawmakers is planned to discuss the breach, although the full extent of the damage remains unclear. The Treasury is collaborating with the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and other agencies to assess the situation and determine the impact of the intrusion. The incident highlights ongoing cybersecurity threats from state-sponsored actors, particularly from China, and underscores the importance of robust security measures in government operations.

- China-backed hackers breached U.S. Treasury workstations using a stolen key.

- The breach was reported as a "major incident" and involved unclassified documents.

- Treasury officials are working with law enforcement and cybersecurity agencies to assess the damage.

- A classified briefing for lawmakers is scheduled to discuss the breach.

- The incident emphasizes the ongoing cybersecurity threats from state-sponsored actors.

Link Icon 2 comments
By @ChrisArchitect - 4 months