Tuesday, 6 May 2025
26.8 C
Singapore
30.8 C
Thailand
21.3 C
Indonesia
29 C
Philippines

US Treasury Department faces major security breach

The US Treasury Department faced a cyberattack linked to a China-state-sponsored hacker exploiting third-party software. No ongoing access was found.

You may be alarmed to learn that the US Treasury Department has suffered a significant cyberattack. A China state-sponsored hacker has been linked to the breach, which exploited third-party remote management software. This unsettling incident, first reported by The New York Times, has raised serious concerns about cybersecurity in critical government agencies.

The breach details revealed

On December 8, the Treasury Department received an alert from BeyondTrust, which provides its remote management software. BeyondTrust informed the agency that a threat actor had stolen a key to secure its cloud-based service. This service is vital for technical support to Treasury employees in the Departmental Offices (DO).

The hacker bypassed security measures using the stolen key and accessed user workstations remotely. The breach also allowed them to retrieve “some unclassified documents” stored on these systems. While these documents were not classified, their exposure underscores the severity of the incident.

Following the breach, the Treasury Department immediately sought help from the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI. The incident was attributed to an Advanced Persistent Threat (APT) group with links to the Chinese government.

BeyondTrust’s role in the attack

The attack appears connected to an earlier incident disclosed by BeyondTrust, which affected customers using its remote support software. BeyondTrust revealed that an API key used in its software had been compromised. In response, the company revoked the API key, informed affected customers, and suspended impacted systems.

Despite the swift action, the breach underscores vulnerabilities in third-party software that could impact critical infrastructure. BeyondTrust has yet to provide additional comments on the matter despite outreach from media outlets.

Government response and strengthened defences

Michael Gwin, a spokesperson for the Treasury Department, assured the public that the compromised BeyondTrust service had been taken offline. He confirmed no evidence of ongoing access to Treasury systems or information by the threat actor.

“Treasury takes all threats against our systems and the data it holds very seriously,” Gwin said. He highlighted significant improvements in the agency’s cyber defences over the last four years and reaffirmed its commitment to working with public and private partners to safeguard the financial system.

This breach is a stark reminder of the persistent threats posed by state-sponsored cyberattacks. It also highlights the importance of securing third-party tools, which often serve as entry points for hackers.

Hot this week

Google expands AI Mode with new features and wider access

Google expands AI Mode in Search, adding smarter shopping, local info cards, and saved searches for easier planning and research.

Hugging Face launches budget-friendly 3D-printed robotic arm starting at US$100

Hugging Face unveils the SO-101, a new 3D-printed robotic arm starting at US$100 that offers faster assembly, smart learning, and wider availability.

ASUS teams up with Bethesda to launch ROG Astral GeForce RTX 5080 DOOM Edition

ASUS celebrates 30 years of graphics cards with a limited ROG RTX 5080 DOOM Edition, launched in partnership with Bethesda and id Software.

Xiaomi enters China’s AI race with new model to power smart devices

Xiaomi joins China’s AI race with its new MiMo model, aiming to power devices with smarter tech and compete with big tech firms.

AI-driven bots now dominate global web traffic, posing new cybersecurity challenges

AI-fuelled bots now make up 51% of web traffic, with rising attacks on APIs and critical industries, says 2025 Imperva Bad Bot Report.

Nintendo sues Genki over Switch 2 accessory mockups and trademark use

Nintendo sued Genki for showing Switch 2 mockups before launch, claiming trademark misuse and misleading promotion.

Grand Theft Auto VI release has been delayed to 2026, with an official date now confirmed

Rockstar confirms GTA VI will now be released on May 26, 2026, moving from its original 2025 window for more polish and quality.

Half-Life 3 could be fully playable and announced this year

Half-Life 3 may finally arrive. Valve insiders say it’s fully playable and could be announced this summer and released this winter.

ASUS IoT secures IEC 62443-4-1 cybersecurity certification for industrial systems

ASUS IoT earns IEC 62443-4-1 certification, strengthening cybersecurity in industrial systems through secure development lifecycle practices.

Related Articles

Popular Categories