Home Kripto US Treasury Says China-Linked Hackers Breached Systems in Cyberattack
Kripto

US Treasury Says China-Linked Hackers Breached Systems in Cyberattack

US Treasury Says China-Linked Hackers Breached Systems in Cyberattack

Hackers linked to the Chinese government breached the US Treasury Department using vulnerabilities in third-party remote management software, marking a significant security incident. As reported by The New York Times, the breach exposed unclassified documents and highlights the persistent risks posed by state-sponsored cyberattacks.

According to a letter the Treasury Department shared with lawmakers (via TechCrunch), US officials learned of the breach on December 8. BeyondTrust, a third-party company providing remote support tools, informed the Treasury that a compromised security key used for technical support had been stolen. Hackers used the key to remotely access employee workstations and unclassified documents.

The incident targeted BeyondTrust, a company that provides remote support tools for large organizations, including government agencies. On December 8, BeyondTrust informed the Treasury that a stolen key, used to secure its cloud-based service, had been compromised. This allowed attackers to bypass security protocols, gaining remote access to employee workstations and unclassified files.

The Treasury, with assistance from the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, quickly responded by taking the affected BeyondTrust service offline. Officials confirmed there is no evidence of continued access to Treasury systems. Treasury spokesperson Michael Gwin told The Verge that the department has worked to fortify its defenses in recent years.

“Treasury takes very seriously all threats against our systems and the data it holds,” Gwin said. “We will continue working with both private and public sector partners to protect our financial system from threat actors.”

BeyondTrust disclosed the incident earlier this month, noting that the compromised API key was immediately revoked and affected customers were notified. However, the company has not provided further details about how the breach occurred.

The Treasury attributed the attack to an advanced persistent threat group backed by the Chinese government, although the specific group remains unnamed. Chinese Embassy spokesperson Liu Pengyu denied the allegations, stating that the US has not provided evidence to support its claims.

This breach follows a series of cyberattacks linked to Chinese state-sponsored groups, including campaigns targeting US telecommunications providers to intercept communications of senior officials.

The breach underscores the vulnerability of critical systems relying on third-party software and the importance of robust cybersecurity measures. While the Treasury reports no ongoing access, the incident raises concerns about the safeguards in place to prevent similar attacks in the future.

Related Articles

Beware of Phishing Scams Featuring AI-Generated YouTube CEO Clips
Kripto

Beware of Phishing Scams Featuring AI-Generated YouTube CEO Clips

YouTube has issued a warning to its users about a new phishing...

Carmakers Get Temporary Relief from Trump’s Tariffs on Canada and Mexico
Kripto

Carmakers Get Temporary Relief from Trump’s Tariffs on Canada and Mexico

President Donald Trump announced the imposition of a 25% tariff on goods...

Greenland’s Prime Minister Rejects Trump’s Bid for Control of the Island
Kripto

Greenland’s Prime Minister Rejects Trump’s Bid for Control of the Island

Greenland, a self-governing territory of Denmark, finds itself at the center of...

Canadians Cancel U.S. Travel Plans Due to Tariffs and Weak Loonie
Kripto

Canadians Cancel U.S. Travel Plans Due to Tariffs and Weak Loonie

Canadian travelers have significantly reduced leisure trips to the United States, reflecting...