Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Five Things To Know On The ‘Major’ US Treasury Department Hack

CRN by CRN
January 3, 2025
Home News
Share on FacebookShare on Twitter


The China-linked breach is tied to the compromise of BeyondTrust’s remote support tool and reportedly led to the breach of multiple offices within the Treasury Department.

New details have emerged on the China-linked breach disclosed by the U.S. Treasury Department earlier this week, which the agency characterized as a “major” cybersecurity incident.

The Washington Post reported Wednesday that the hack led to the compromise of multiple offices within the Treasury Department.

[Related: 10 Major Ransomware Attacks And Data Breaches In 2024]

The breach is tied to the compromise of BeyondTrust’s remote support tool, which the company had disclosed in December.

In a letter to lawmakers earlier this week, the Treasury Department said that “based on available indicators, the incident has been attributed to a China state-sponsored Advanced Persistent Threat (APT) actor.”

“In accordance with Treasury policy, intrusions attributable to an APT are considered a major cybersecurity incident,” the agency said.

What follows are five things to know on the U.S. Treasury Department hack.

BeyondTrust Compromise

The U.S. Treasury Department said its systems were compromised in connection with the breach of BeyondTrust, which the identity and access security vendor had initially disclosed Dec. 8.

BeyondTrust had previously said in an advisory that a “limited number” of customers were affected by the compromise of its Remote Support SaaS offering.

The investigation led to the discovery of two vulnerabilities—one of which is rated as “critical”— affecting its products.

In a statement Thursday, BeyondTrust said that it “previously identified and took measures to address a security incident in early December 2024 that involved the Remote Support product.”

“BeyondTrust notified the limited number of customers who were involved, and it has been working to support those customers since then,” the company said.

‘Major’ Cyberattack Disclosed

In a Dec. 30 letter sent to lawmakers, an assistant secretary in the U.S. Treasury Department disclosed that the agency was notified by BeyondTrust on Dec. 8 that it was impacted in the attack, which has since been linked to a China-affiliated hacker group.

The department was informed that “a threat actor had gained access to a key used by the vendor to secure a cloud-based service used to remotely provide technical support for Treasury Departmental Offices (DO) end users.”

The affected BeyondTrust service was taken offline and “at this time there is no evidence indicating the threat actor has continued access to Treasury information,” the letter from Aditi Hardikar, U.S. Treasury’s assistant secretary for management, had said.

Multiple Offices Impacted

The Washington Post indicated in its report Wednesday that the affected offices within the U.S. Treasury Department included the Office of Foreign Assets Control (OFAC). The office oversees the administration of economic sanctions, including sanctions against countries as well as individuals.

In addition to OFAC, the Post reported that the Office of the Treasury Secretary and the department’s Office of Financial Research were compromised in the attack.

CRN has reached out to the Treasury Department for comment.

Unclassified Documents Accessed

In its Dec. 30 letter to lawmakers, the Treasury Department official said that obtaining the stolen BeyondTrust key allowed the threat actor to remotely access some user workstations and “access certain unclassified documents maintained by those users.”

Treasury has worked with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as well as the FBI, members of the intelligence community and third-party investigators “to fully characterize the incident and determine its overall impact,” the letter said.

The Chinese government is highly interested in obtaining information about potential future sanctions against entities in China, the Post reported, citing U.S. officials.

Prior Sanctions Against China

In March 2024, OFAC had announced sanctions against “actors affiliated with the Chinese state-sponsored APT 31 hacking group.”

Those included the Wuhan Xiaoruizhi Science and Technology Company, which the Treasury Department characterized in a news release as a “front company” for China’s Ministry of State Security “that has served as cover for multiple malicious cyber operations.”

OFAC also sanctioned several Chinese nationals at the same time “for their roles in malicious cyber operations targeting U.S. entities that operate within U.S. critical infrastructure sectors,” the agency said in the March 2024 news release.



Source link

Tags: CyberattacksCybersecurityData breaches
CRN

CRN

Next Post
The 10 Biggest Intel News Stories Of 2024

The 10 Biggest Intel News Stories Of 2024

Recommended.

Databricks Looks To Exceed 0B Valuation With New Funding Round

Databricks Looks To Exceed $100B Valuation With New Funding Round

August 19, 2025
Texas has ‘stronger brand than New York’ as Wall Street looks south, Gov. Greg Abbott says

Texas has ‘stronger brand than New York’ as Wall Street looks south, Gov. Greg Abbott says

March 18, 2025

Trending.

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

March 10, 2026
Huawei lanceert Next Generation FAN-oplossing

Huawei lanceert Next Generation FAN-oplossing

March 7, 2026
Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

February 26, 2026
Half of Google’s software development now AI-generated | Computer Weekly

Half of Google’s software development now AI-generated | Computer Weekly

February 5, 2026
Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

March 24, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio