City
Epaper

Chinese cyberattack targets US Treasury: Workstations compromised, documents accessed

By ANI | Updated: December 31, 2024 05:10 IST

Washington DC [US], December 31 : In a 'major incident' of a cyberattack, a Chinese state-sponsored actor gained access ...

Open in App

Washington DC [US], December 31 : In a 'major incident' of a cyberattack, a Chinese state-sponsored actor gained access to US Treasury workstations and unclassified documents, the US Treasury Department notified Congress on Monday (local time).

In a letter reviewed by CNN, a US Treasury official revealed that a Chinese state-sponsored Advanced Persistent Threat (APT) actor used a stolen key to remotely access certain Treasury workstations and unclassified documents, as informed by a third-party software service provider on December 8.

"Based on available indicators, the incident has been attributed to a Chinese state-sponsored Advanced Persistent Threat (APT) actor," Aditi Hardikar, assistant secretary for management at the US Treasury, wrote in the letter.

A US Treasury spokesperson told CNN that the compromised service has been taken offline and steps are being taken in coordination with law enforcement and the Cybersecurity and Infrastructure Security Agency (CISA). "There is no evidence indicating the threat actor has continued access to Treasury systems or information," the Treasury spokesperson said.

According to CNN, Treasury officials are likely to hold a classified briefing next week with the House Financial Services Committee to analyze the breach. However, the exact timing of the briefing is yet to be decided, a senior committee staffer informed CNN.

The third-party software service provider, BeyondTrust, stated that hackers gained access to a key used by the vendor to secure a cloud-based service that the Treasury Department uses for technical support, according to the letter addressed to Senate Banking Committee leadership.

"With access to the stolen key, the threat actor was able to override the service's security, remotely access certain Treasury [Departmental Office] user workstations, and access certain unclassified documents maintained by those users," the Treasury letter said.

Hardikar noted in the letter that intrusions attributed to advanced persistent threat actors are considered a "major cybersecurity incident."

The full extent of the damage caused by the breach has not yet been determined, CNN reported.

Hardikar further wrote that to "fully characterise the incident and determine its overall impact," Treasury has been working with CISA, the FBI, US intelligence agencies, and third-party forensic investigators.

"CISA was engaged immediately upon Treasury's knowledge of the attack, and the remaining governing bodies were contacted as soon as the scope of the attack became evident," the letter added.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

Cricket"He is right up there with some of the best": Dinesh Karthik applauds Yash Dayal's last-over heroics against CSK

InternationalGovt terminates services of K Subramanian as India's Executive Director at IMF

Cricket"I take the blame": MS Dhoni takes fall for CSK's defeat against RCB

CricketIPL 2025: RCB edge past CSK in nail-bitting thriller at Chinnaswamy stadium

NationalBharatiya Kisan Union (Ekta-Sidhupur) protests against Punjab govt for not giving compensation for destroyed crops

International Realted Stories

InternationalAngola President Lourenco condemns Pahalgam terror attack

International"Muizzu's narrative collapsed under his own words, people of India and Maldives deserve apology": MDP chief Abdulla Shahid

InternationalIndia, Angola decide to expand energy partnership

InternationalAngola signs International Solar Alliance agreement during President Lourenco's India visit

InternationalIndia announces $200 million defence credit line for modernization of Angola's armed forces