Chinese Hackers Breach Treasury Department in Major Cybersecurity Incident
Chinese state-sponsored hackers breached the Treasury Department in a major cybersecurity incident earlier this year, as disclosed by the department to lawmakers. The breach was detected on Dec. 8, when BeyondTrust, an external vendor, identified the hacker’s access to an online key used for remote technical support of Treasury offices via a cloud-based service.
Details of the Breach
The hacker successfully bypassed security systems, gaining remote access to Treasury workstations and specific unclassified documents. A subsequent investigation linked the attack to a China state-sponsored actor known as an ‘Advanced Persistent Threat’.
Response and Investigation
Upon notification by BeyondTrust, Treasury promptly engaged with the Cybersecurity and Infrastructure Security Agency (CISA) and collaborated with law enforcement partners to assess the breach’s impact. The compromised BeyondTrust service was immediately shut down, with no current evidence of ongoing access by the threat actor.
Treasury has committed to providing additional details on the incident in a forthcoming report within the next 30 days. Senator Tim Scott of South Carolina has requested a briefing on the breach and is closely monitoring developments.
Vendor’s Actions
BeyondTrust, the service provider involved, has informed a limited number of affected customers and is actively assisting law enforcement in the investigation. The company has also shared updates on the incident and investigation progress on its website to keep customers informed throughout the resolution process.