Cyberattack on US Treasury Department from China
The US Treasury Department announced that it was targeted by a China-backed actor at the beginning of December.
AA
In a letter sent to Congress regarding the matter, the Department stated that a "significant incident" had been identified.
On December 8, the Department learned from third-party software service provider BeyondTrust that hackers had gained access to a cloud service used to provide remote technical support to end-users in Treasury Department offices.
It was noted that the hackers had gained remote access to certain workstations and accessed some unclassified documents.
It was stated that the incident in question was carried out by a state-sponsored actor from China.
Meanwhile, in a statement released by the US Treasury Department, it was reported that they had contacted the Cybersecurity and Infrastructure Security Agency (CISA) and were working with law enforcement to determine the impact of the incident.
The statement noted, "The compromised BeyondTrust service has been taken offline, and there is no evidence that the threat actor continues to have access to Treasury systems or information."
Emphasizing that the Treasury takes all threats to its systems and data very seriously, the statement added, "The Treasury has significantly strengthened its cyber defenses over the last four years, and we will continue to work with both private and public sector partners to protect our financial system from threat actors."