US Treasury Workstations Hacked By China In ‘Major Incident’


US Treasury says workstations accessed by China-backed attackers and files accessed after compromise of third-party security provider

The US Treasury Department has notified lawmakers that a China state-sponsored attack group infiltrated workstations at the department this month and stole files in what it described as a “major incident”.

The hackers compromised a third-party cybersecurity service provided by BeyondTrust and gained access to unclassified documents, according to a letter sent by the Treasury.

The attackers gained access to a key used by the vendor to secure a cloud-based service that provides technical support for end users at Treasury departmental offices, the department said.

With access to the stolen key, the threat actor was able to override the service’s security, remotely access some workstations and access unclassified documents maintained by those users, the letter said.

Image credit: Unsplash

Third-party tool

The department said it was alerted to the breach by BeyondTrust on 8 December and that it was working with the US Cybersecurity and Infrastructure Security Agency (CISA) and the FBI to assess the impact of the attack.

“Based on available indicators, the incident has been attributed to a Chinese state-sponsored Advanced Persistent Threat (APT) actor,” said US Treasury assistant secretary for management Aditi Hardikar in the letter.

The compromised service has been taken offline, the Treasury said in a separate statement.

“There is no evidence indicating the threat actor has continued access to Treasury systems or information,” the department stated.

Treasury officials are reportedly planning a classified briefing about the breach next week with staff members of the House Financial Services Committee.

A Treasury spokesperson said “several” workstations were breached, but did not provide a more precise indication of how many.

‘Major incident’

Hardikar said in the letter that intrusions attributed to advanced persistent threat actors are designated as a “major cybersecurity incident”, with Treasury officials required to provide an update in a 30-day supplemental report.

In an effort to “fully characterise the incident and determine its overall impact” the Treasury has been working with CISA, the FBI, US intelligence agencies and third-party forensic investigators, Hardikar said.

CISA was engaged “immediately” upon Treasury’s knowledge of the attack and the remaining governing bodies were contacted as soon as the scope of the attack became evident, the letter said.

The Chinese embassy in Washington, DC told Reuters the country rejected responsibility for the attack and that it opposes US “smear attacks against China without any factual basis”.



Source link

Share

Latest Updates

Frequently Asked Questions

Related Articles

Overseas education firms join student exodus from American classrooms

The Trump administration’s immigration regime is not only impacting students who are aspiring...

How AI Is Upending Politics, Tech, the Media, and More

In an increasingly divided world, one thing that everyone seems to agree on...

Telesat pitches Lightspeed as stopgap to Europe’s IRIS²

TAMPA, Fla. — Canada’s Telesat is pitching Lightspeed as a bridge to IRIS²...

Apple watchOS 26 system requirements: will it run on your Apple Watch?

The latest Apple smartwatch software is called watchOS 26. After months of beta...
sabung ayam online sabung ayam online sabung ayam online sabung ayam online sabung ayam online Sabung Ayam Online Sv388 Sv388 SV388 sabung ayam online sabung ayam online Sabung Ayam Online sabung ayam online sabung ayam online sabung ayam online Sabung ayam online Sabung ayam online SV388 sabung ayam online sabung ayam online sabung ayam online sabung ayam online sabung ayam online sabung ayam online SV388 sabung ayam online SV388 SV388 Sabung Ayam Online Sabung Ayam Online Sabung Ayam Online Sabung Ayam Online Sv388 SV388 SV388 sabung ayam online sv388 sv388 sabung ayam online sv388
judi bola judi bola Judi bola SBOBET judi bola judi bola judi bola Judi Bola Online judi bola judi bola judi bola judi bola judi bola judi bola juara303 juara303 Judi bola online judi bola judi bola judi bola judi bola judi bola judi bola judi bola judi bola SBOBET judi bola judi bola judi bola Judi Bola SBOBET88 SBOBET88 judi bola judi bola judi bola JUDI BOLA ONLINE JUDI BOLA ONLINE SBOBET88 Judi Bola Judi Bola judi bola judi bola judi bola judi bola judi bola Judi Bola Online judi bola judi bola judi bola judi bola mix parlay
CASINO ONLINE SLOT GACOR live casino mahjong ways Live Casino Online Slot Gacor Mahjong Ways slot pulsa Casino Online Slot Gacor Mix Parlay live casino online live casino online LIVE CASINO ONLINE LIVE CASINO ONLINE slot pulsa slot pulsa slot pulsa Mpo Slot
https://ejurnal.staidarulkamal.ac.id/ https://doctorsnutritionprogram.com/ https://nielsen-restaurante.com/ https://www.atobapizzaria.com.br/ https://casadeapoio.com.br/ https://bracoalemao.com.br/ https://letspetsresort.com.br/ https://mmsolucoesweb.com.br/ https://procao.com.br/
Rahasia Kemenangan di Mahjong Wild Pemain Tidak Menyangka Pola Scatter Jangan Anggap Remeh Mahjong Wild Pemain Pemula Heran Setelah Coba Mahjong Wild Menemukan Pola Rahasia yang Bikin Scatter Muncul Pola Scatter Rahasia yang Baru Terbongkar Pola Rahasia Pemain Pemula Terbongkar Mereka Ketagihan Karena Sering Dapat Kemenangan Mereka Ketagihan Karena Sering Dapat Kemenangan Trik Sederhana Saat Taruhan Kecil Pola Wild Liar Tersembunyi Bisa Menggandakan uang Pola Rahasia Baru Bisa Menghasilkan Wild Buktikan Pola Wild Liar dan Scatter Hitam Kaya Setelah Main Mahjong Wild Pria Asal Nepal Obrak-Abarik Kantor DPR