Chinese state-sponsored hackers infiltrate US Treasury in major cyberattack, officials tell Congress

The US Treasury Department informed legislators on Monday that a Chinese state-sponsored actor infiltrated Treasury workstations in what authorities are calling a "major incident."

The Treasury Department says China-backed hackers breached its computer systems.
Michael A. McCoy/The Washington Post

In a letter acquired by CNN, a Treasury official said that on December 8, a third-party software service provider told them that a threat actor had utilized a stolen key to remotely access some Treasury workstations and unclassified data.

"Based on available indicators, the incident has been attributed to a Chinese state-sponsored Advanced Persistent Threat (APT) actor," Aditi Hardikar, assistant secretary for management at the US Treasury, wrote in the letter.

A Treasury spokeswoman told CNN that the hacked service has been taken offline, and authorities are collaborating with law enforcement and the Cybersecurity and Infrastructure Security Agency (CISA).

"There is no evidence that the threat actor has continued access to Treasury systems or information," a Treasury spokeswoman said.

A senior committee source told CNN that Treasury officials want to provide a secret briefing on the breach next week for House Financial Services Committee personnel. The specific timing of the briefing has not yet been determined.

According to the letter to Senate Banking Committee leadership, BeyondTrust, a third-party software service provider, reported that hackers got access to a key used by the vendor to protect a cloud-based service that Treasury utilizes for technical assistance.

"With access to the stolen key, the threat actor was able to override the service's security, remotely access certain Treasury [Departmental Office] user workstations, and access certain unclassified documents maintained by those users," the Treasury letter said.

It is unclear how many workstations were penetrated. However, the Treasury spokeswoman stated that "several" Treasury user workstations were accessed.

According to Hardikar's letter, breaches attributable to advanced persistent threat actors are deemed a "major cybersecurity incident." Treasury authorities must offer an update in a 30-day supplementary report.

It's unclear if Treasury has completely assessed the harm caused by the leak.

Treasury has been working with CISA, the FBI, US intelligence agencies, and third-party forensic investigators to "fully characterize the incident and determine its overall impact," according to Hardikar's letter.

"CISA was engaged immediately upon Treasury’s knowledge of the attack, and the remaining governing bodies were contacted as soon as the scope of the attack became evident," the letter said.

Comments

TRENDING!

Trump says New Orleans attack confirms his 'rhetoric' on crime

Justin Trudeau resigns after nine years in office as Liberals force him out

Trump asks Supreme Court to pause potential US TikTok ban

FBI launches terrorism investigation into New Orleans attack that killed 10

Jimmy Carter, the 39th US president, has died at 100

How two crew members in deadly South Korea plane crash survived

Tesla's annual sales fall for first time in nine years

Trump's tariffs would boost inflation, shrink the economy, CBO says