Wednesday, 5 February 2025
25 C
Singapore
35.1 C
Thailand
27.5 C
Indonesia
26 C
Philippines

US Treasury Department faces major security breach

The US Treasury Department faced a cyberattack linked to a China-state-sponsored hacker exploiting third-party software. No ongoing access was found.

You may be alarmed to learn that the US Treasury Department has suffered a significant cyberattack. A China state-sponsored hacker has been linked to the breach, which exploited third-party remote management software. This unsettling incident, first reported by The New York Times, has raised serious concerns about cybersecurity in critical government agencies.

The breach details revealed

On December 8, the Treasury Department received an alert from BeyondTrust, which provides its remote management software. BeyondTrust informed the agency that a threat actor had stolen a key to secure its cloud-based service. This service is vital for technical support to Treasury employees in the Departmental Offices (DO).

The hacker bypassed security measures using the stolen key and accessed user workstations remotely. The breach also allowed them to retrieve โ€œsome unclassified documentsโ€ stored on these systems. While these documents were not classified, their exposure underscores the severity of the incident.

Following the breach, the Treasury Department immediately sought help from the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI. The incident was attributed to an Advanced Persistent Threat (APT) group with links to the Chinese government.

BeyondTrustโ€™s role in the attack

The attack appears connected to an earlier incident disclosed by BeyondTrust, which affected customers using its remote support software. BeyondTrust revealed that an API key used in its software had been compromised. In response, the company revoked the API key, informed affected customers, and suspended impacted systems.

Despite the swift action, the breach underscores vulnerabilities in third-party software that could impact critical infrastructure. BeyondTrust has yet to provide additional comments on the matter despite outreach from media outlets.

Government response and strengthened defences

Michael Gwin, a spokesperson for the Treasury Department, assured the public that the compromised BeyondTrust service had been taken offline. He confirmed no evidence of ongoing access to Treasury systems or information by the threat actor.

โ€œTreasury takes all threats against our systems and the data it holds very seriously,โ€ Gwin said. He highlighted significant improvements in the agencyโ€™s cyber defences over the last four years and reaffirmed its commitment to working with public and private partners to safeguard the financial system.

This breach is a stark reminder of the persistent threats posed by state-sponsored cyberattacks. It also highlights the importance of securing third-party tools, which often serve as entry points for hackers.

Hot this week

Tesla earnings day: What to expect from Musk, profits, and AI

Teslaโ€™s earnings report is here, with investors eager for updates on profits, AI, and Muskโ€™s self-driving ambitions. Will Teslaโ€™s future plans impress?

Exabeam launches AI-powered LogRhythm Intelligence Copilot to revolutionise threat detection

Exabeam unveils LogRhythm Intelligence Copilot, an AI-driven feature designed to improve threat detection and security team workflows globally.

Samsung Galaxy S25 Ultra dominates pre-orders in South Korea

The Samsung Galaxy S25 Ultra leads pre-orders in South Korea, making up 60-70% of sales. Find out which colours are trending and how to pre-order yours.

ASUS AI POD with NVIDIA GB200 NVL72 set to ship in March, transforming AI infrastructure

ASUS AI POD with NVIDIA GB200 NVL72 to ship in March, offering transformative AI solutions with NVIDIA GPUs, advanced cooling, and high performance.

Microsoft unveils new Surface devices with Copilot+ PC capabilities

Microsoft launches the new Surface Pro and Surface Laptop with Intel Arrow Lake processors, 5G support, and enhanced security.

SECO partners with impact.com to boost Senheng appโ€™s growth through affiliate marketing

SECO partners with impact.com to scale the Senheng app through affiliate marketing, aiming for growth, better ROI, and personalised consumer engagement.

Commvault partners with CrowdStrike to improve cyber threat detection and recovery

Commvault partners with CrowdStrike to enhance threat detection and data recovery, providing businesses with faster responses and stronger cyber resilience.

Unlock free skins during the Overwatch 2 spotlight livestream on February 12

Watch the Overwatch 2 spotlight livestream on February 12 to claim free skins, including Lucioโ€™s Cyber DJ and Flirty Flare Baptiste.

Singtel dominates mobile speeds in Singapore

Singtel and MyRepublic top Ooklaโ€™s 2024 Speedtest Connectivity Report, offering Singaporeans faster and more reliable mobile and broadband internet.

Related Articles