December 30th, 2024

The US Treasury Department was hacked

The US Treasury Department suffered a security breach by a China-based hacker, accessing BeyondTrust software and employee workstations. The agency is collaborating with CISA and the FBI to enhance cyber defenses.

Read original articleLink Icon
The US Treasury Department was hacked

The US Treasury Department experienced a significant security breach attributed to a China-based state-sponsored hacker. The incident occurred after the hacker accessed the third-party remote management software, BeyondTrust, used by the Treasury. The breach was reported to the Treasury on December 8, 2024, when BeyondTrust informed the agency that a key used to secure its cloud-based service had been stolen. This allowed the hacker to override security measures and remotely access employee workstations and some unclassified documents. Following the attack, the Treasury collaborated with the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI. A spokesperson for the Treasury stated that the compromised service has been taken offline and there is no evidence of continued access by the hacker. The attack is linked to a prior security incident disclosed by BeyondTrust, which involved a compromised API key. The Treasury emphasized its commitment to enhancing cyber defenses and collaborating with both public and private sectors to safeguard its systems.

- The US Treasury Department was hacked by a China-based state-sponsored actor.

- The breach involved the remote management software BeyondTrust, which was compromised.

- The hacker accessed employee workstations and unclassified documents.

- The Treasury is working with CISA and the FBI to address the incident.

- The Treasury has taken steps to bolster its cyber defenses in recent years.

Link Icon 3 comments
By @gnabgib - 4 months
Original source - more detail including link to a source (26 points, no discussion yet) https://news.ycombinator.com/item?id=42553154

The letter: https://legacy.www.documentcloud.org/documents/25472740-lett...

The Verge suggests NYT is the source (5 points, no comments) [0] , but it doesn't mention the letter that Reuters has.

[0]: https://news.ycombinator.com/item?id=42553233

By @mu53 - 4 months
I think the media is dropping the ball from hammering home just how bad this is for national security and world politics. Banning tiktok is superfluous in a world where every device can be compromised, every telecom is compromised, and government agencies are unable to mitigate attacks.

The reality is that the follow up to this information exposure is never connected to the outcome. How many government agents have been compromised using the OPM hack data? nobody knows. How many politicians/corporations intimidated via blackmail?

How have these hacks changed the outcome of world events?

By @ChrisArchitect - 4 months