Chinese-sponsored hackers accessed Treasury documents in ‘major incident’

Published on January 10, 2025

Chinese government-aligned hackers accessed Treasury Department workstations in a “major incident” that involved the compromise of a third-party provider, according to a letter reviewed by Nextgov/FCW and confirmed in a statement by Treasury on Friday.

The letter addressed to leaders on the Senate Banking Committee says that on Dec. 8 BeyondTrust, a provider of cloud security services, alerted Treasury to a breach where hackers had obtained a key used to secure a cloud-based service for remotely supporting Treasury Departmental Offices users. 

Using the stolen key, the attacker bypassed the service’s security, remotely accessed Treasury workstations and retrieved certain unclassified documents stored by those users.

“The compromised BeyondTrust service has been taken offline and there is no evidence indicating the threat actor has continued access to Treasury systems or information,” the agency said in a statement.

Read the full article here.