Categories: CyberCrimeSecurity

US Treasury Workstations Hacked By China In ‘Major Incident’

The US Treasury Department has notified lawmakers that a China state-sponsored attack group infiltrated workstations at the department this month and stole files in what it described as a “major incident”.

The hackers compromised a third-party cybersecurity service provided by BeyondTrust and gained access to unclassified documents, according to a letter sent by the Treasury.

The attackers gained access to a key used by the vendor to secure a cloud-based service that provides technical support for end users at Treasury departmental offices, the department said.

With access to the stolen key, the threat actor was able to override the service’s security, remotely access some workstations and access unclassified documents maintained by those users, the letter said.

Image credit: Unsplash

Third-party tool

The department said it was alerted to the breach by BeyondTrust on 8 December and that it was working with the US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI to assess the impact of the attack.

“Based on available indicators, the incident has been attributed to a Chinese state-sponsored Advanced Persistent Threat (APT) actor,” said US Treasury assistant secretary for management Aditi Hardikar in the letter.

The compromised service has been taken offline, the Treasury said in a separate statement.

“There is no evidence indicating the threat actor has continued access to Treasury systems or information,” the department stated.

Treasury officials are reportedly planning a classified briefing about the breach next week with staff members of the House Financial Services Committee.

A Treasury spokesperson said “several” workstations were breached, but did not provide a more precise indication of how many.

‘Major incident’

Hardikar said in the letter that intrusions attributed to advanced persistent threat actors are designated as a “major cybersecurity incident”, with Treasury officials required to provide an update in a 30-day supplemental report.

In an effort to “fully characterise the incident and determine its overall impact” the Treasury has been working with CISA, the FBI, US intelligence agencies and third-party forensic investigators, Hardikar said.

CISA was engaged “immediately” upon Treasury’s knowledge of the attack and the remaining governing bodies were contacted as soon as the scope of the attack became evident, the letter said.

The Chinese embassy in Washington, DC told Reuters the country rejected responsibility for the attack and that it opposes US “smear attacks against China without any factual basis”.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

OpenAI Argues Case For AI-Friendly US Rules

OpenAI document proposes exemption from state regulations, access to copyrighted materials, promotion of US AI…

10 hours ago

Foxconn Misses Profit Expectations After iPhone Sales Drop

Taiwan's Foxconn misses profit expectations for fourth quarter after iPhone sales decline, but predicts rosy…

11 hours ago

Tesla Developing Cheaper Model Y To Stem China Losses

Tesla reportedly developing cheaper version of popular Model Y EV to stem market-share losses in…

11 hours ago

Global Smartwatch Sales Fall For First Time

Worldwide smartwatch sales see first-ever decline as market leader Apple records 19 percent year-over-year drop

12 hours ago

European Parliament Bans Huawei Lobbyists After Arrests

European Parliament bans Huawei lobbyists after police make arrests in corruption probe around company's links…

12 hours ago