Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Five Things To Know On The ‘Major’ US Treasury Department Hack

CRN by CRN
January 3, 2025
Home News
Share on FacebookShare on Twitter


The China-linked breach is tied to the compromise of BeyondTrust’s remote support tool and reportedly led to the breach of multiple offices within the Treasury Department.

New details have emerged on the China-linked breach disclosed by the U.S. Treasury Department earlier this week, which the agency characterized as a “major” cybersecurity incident.

The Washington Post reported Wednesday that the hack led to the compromise of multiple offices within the Treasury Department.

[Related: 10 Major Ransomware Attacks And Data Breaches In 2024]

The breach is tied to the compromise of BeyondTrust’s remote support tool, which the company had disclosed in December.

In a letter to lawmakers earlier this week, the Treasury Department said that “based on available indicators, the incident has been attributed to a China state-sponsored Advanced Persistent Threat (APT) actor.”

“In accordance with Treasury policy, intrusions attributable to an APT are considered a major cybersecurity incident,” the agency said.

What follows are five things to know on the U.S. Treasury Department hack.

BeyondTrust Compromise

The U.S. Treasury Department said its systems were compromised in connection with the breach of BeyondTrust, which the identity and access security vendor had initially disclosed Dec. 8.

BeyondTrust had previously said in an advisory that a “limited number” of customers were affected by the compromise of its Remote Support SaaS offering.

The investigation led to the discovery of two vulnerabilities—one of which is rated as “critical”— affecting its products.

In a statement Thursday, BeyondTrust said that it “previously identified and took measures to address a security incident in early December 2024 that involved the Remote Support product.”

“BeyondTrust notified the limited number of customers who were involved, and it has been working to support those customers since then,” the company said.

‘Major’ Cyberattack Disclosed

In a Dec. 30 letter sent to lawmakers, an assistant secretary in the U.S. Treasury Department disclosed that the agency was notified by BeyondTrust on Dec. 8 that it was impacted in the attack, which has since been linked to a China-affiliated hacker group.

The department was informed that “a threat actor had gained access to a key used by the vendor to secure a cloud-based service used to remotely provide technical support for Treasury Departmental Offices (DO) end users.”

The affected BeyondTrust service was taken offline and “at this time there is no evidence indicating the threat actor has continued access to Treasury information,” the letter from Aditi Hardikar, U.S. Treasury’s assistant secretary for management, had said.

Multiple Offices Impacted

The Washington Post indicated in its report Wednesday that the affected offices within the U.S. Treasury Department included the Office of Foreign Assets Control (OFAC). The office oversees the administration of economic sanctions, including sanctions against countries as well as individuals.

In addition to OFAC, the Post reported that the Office of the Treasury Secretary and the department’s Office of Financial Research were compromised in the attack.

CRN has reached out to the Treasury Department for comment.

Unclassified Documents Accessed

In its Dec. 30 letter to lawmakers, the Treasury Department official said that obtaining the stolen BeyondTrust key allowed the threat actor to remotely access some user workstations and “access certain unclassified documents maintained by those users.”

Treasury has worked with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as well as the FBI, members of the intelligence community and third-party investigators “to fully characterize the incident and determine its overall impact,” the letter said.

The Chinese government is highly interested in obtaining information about potential future sanctions against entities in China, the Post reported, citing U.S. officials.

Prior Sanctions Against China

In March 2024, OFAC had announced sanctions against “actors affiliated with the Chinese state-sponsored APT 31 hacking group.”

Those included the Wuhan Xiaoruizhi Science and Technology Company, which the Treasury Department characterized in a news release as a “front company” for China’s Ministry of State Security “that has served as cover for multiple malicious cyber operations.”

OFAC also sanctioned several Chinese nationals at the same time “for their roles in malicious cyber operations targeting U.S. entities that operate within U.S. critical infrastructure sectors,” the agency said in the March 2024 news release.



Source link

Tags: CyberattacksCybersecurityData breaches
CRN

CRN

Next Post
The 10 Biggest Intel News Stories Of 2024

The 10 Biggest Intel News Stories Of 2024

Recommended.

Netskope Threat Labs: Phishing Clicks Nearly Tripled in 2024, Ubiquitous Use of Personal Cloud Apps and GenAI Tools Require Modern Workplace Security to Mitigate Risk

Netskope Threat Labs: Phishing Clicks Nearly Tripled in 2024, Ubiquitous Use of Personal Cloud Apps and GenAI Tools Require Modern Workplace Security to Mitigate Risk

January 7, 2025
Dell Technologies Expects To Sell B In AI Servers This Year Amid ‘Optimistic’ Outlook For 2025, COO Jeff Clarke Says

Dell Technologies Expects To Sell $15B In AI Servers This Year Amid ‘Optimistic’ Outlook For 2025, COO Jeff Clarke Says

March 6, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
30 Notable IT Executive Moves: April 2026

30 Notable IT Executive Moves: April 2026

May 11, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio