US Treasury Department breached through remote support platform
The U.S. Treasury Department experienced a cybersecurity breach by Chinese state-sponsored hackers via BeyondTrust's platform, using a stolen API key. The FBI and CISA are investigating the incident.
Read original articleThe U.S. Treasury Department has confirmed a cybersecurity breach attributed to Chinese state-sponsored hackers, specifically an Advanced Persistent Threat (APT) group. The breach occurred through a remote support platform provided by BeyondTrust, a vendor that the Treasury uses for privileged access management. The Treasury was first notified of the incident on December 8, 2024, after BeyondTrust discovered that threat actors had exploited vulnerabilities in their Remote Support SaaS platform. These hackers gained access using a stolen API key, allowing them to reset passwords and access sensitive documents remotely. Following the breach, BeyondTrust identified two zero-day vulnerabilities that facilitated the attack and subsequently shut down the compromised instances. The FBI and CISA are involved in the investigation, and there is currently no evidence that the hackers retain access to the Treasury's systems. This incident is part of a broader pattern of attacks linked to the same group, known as "Salt Typhoon," which has also targeted multiple U.S. telecommunications companies. In response to these breaches, CISA has recommended that government officials adopt end-to-end encrypted messaging to enhance security.
- The U.S. Treasury Department was breached by Chinese state-sponsored hackers via a remote support platform.
- The breach was facilitated by vulnerabilities in BeyondTrust's Remote Support SaaS.
- The hackers used a stolen API key to gain privileged access to sensitive documents.
- The FBI and CISA are investigating the incident, and compromised systems have been shut down.
- This breach is part of a series of attacks linked to the "Salt Typhoon" group targeting U.S. telecom companies.
Related
China Hacked Treasury Dept. In 'Major Incident,' U.S. Says
The U.S. Treasury Department experienced a cybersecurity breach by a state-sponsored Chinese actor, accessing workstations and documents. The Treasury is collaborating with the FBI to assess the situation.
China-backed hackers breached US Treasury workstations
The U.S. Treasury Department experienced a significant cybersecurity breach by a China-backed hacker group, leading to unauthorized access and collaboration with agencies to assess the damage and threats.
US treasury's workstations breached in cyber-attack by China – report
Chinese state-sponsored hackers breached the US Treasury Department via a third-party provider, accessing unclassified documents. The Treasury has secured its systems and engaged federal agencies to investigate the incident.
The US Treasury Department was hacked
The US Treasury Department suffered a security breach by a China-based hacker, accessing BeyondTrust software and employee workstations. The agency is collaborating with CISA and the FBI to enhance cyber defenses.
US Treasury computers hacked by Chinese 'threat actor' in 'major incident'
The U.S. Treasury Department experienced a cybersecurity breach linked to a Chinese state-sponsored group, accessing unclassified documents via a third-party service. Investigations are ongoing, with a report expected in 30 days.
Related
China Hacked Treasury Dept. In 'Major Incident,' U.S. Says
The U.S. Treasury Department experienced a cybersecurity breach by a state-sponsored Chinese actor, accessing workstations and documents. The Treasury is collaborating with the FBI to assess the situation.
China-backed hackers breached US Treasury workstations
The U.S. Treasury Department experienced a significant cybersecurity breach by a China-backed hacker group, leading to unauthorized access and collaboration with agencies to assess the damage and threats.
US treasury's workstations breached in cyber-attack by China – report
Chinese state-sponsored hackers breached the US Treasury Department via a third-party provider, accessing unclassified documents. The Treasury has secured its systems and engaged federal agencies to investigate the incident.
The US Treasury Department was hacked
The US Treasury Department suffered a security breach by a China-based hacker, accessing BeyondTrust software and employee workstations. The agency is collaborating with CISA and the FBI to enhance cyber defenses.
US Treasury computers hacked by Chinese 'threat actor' in 'major incident'
The U.S. Treasury Department experienced a cybersecurity breach linked to a Chinese state-sponsored group, accessing unclassified documents via a third-party service. Investigations are ongoing, with a report expected in 30 days.