China-linked attack on US Treasury Department reportedly targeted its sanctions office

The US Treasury Department told lawmakers in a letter back in December that its documents and workstations were accessed by an external party in a security breach. It described the attack as "a major cybersecurity incident" and attributed it to a "China state-sponsored Advanced Persistent Threat actor." Now, The Washington Post has reported that the bad actors infiltrated a "highly sensitive office" within the Treasury in charge of deliberating and administering US government sanctions. 

As The Post explains, the Office of Foreign Assets Control (OFAC) is in possession of some important information that could be very useful to another country's government. While the hackers were only able to steal unclassified data, they could still have gotten their hands on the identities of potential sanction targets. They could also have stolen pieces of evidence that the agency had collected as part of its investigation on entities that the government is thinking of sanctioning. Overall, the attackers could have gotten enough information to give them the knowledge of how the US develops sanctions against foreign entities. 

In addition to OFAC, the Office of the Treasury Secretary and the Office of Financial Research were also affected by the breach. The attackers infiltrated the Treasury's systems by gaining access to a key used by BeyondTrust, a cloud-based service that provides the department with technical support. 

The US government has attributed numerous cyberattacks on its agencies and American companies to China state-sponsored actors over the years. Just last year, the FBI blamed "PRC-affiliated actors" for a massive hack on US telecom companies. The actors, a group known as Salt Typhoon, reportedly targeted the mobile devices of diplomats, government officials and other people linked to both presidential campaigns. According to The Post, Chinese officials called claims that their country was involved in the attack on the Treasury Department "groundless" and insisted that their government "has always opposed all forms of hacker attacks."

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/china-linked-attack-on-us-treasury-department-reportedly-targeted-its-sanctions-office-150033082.html?src=rss https://www.engadget.com/cybersecurity/china-linked-attack-on-us-treasury-department-reportedly-targeted-its-sanctions-office-150033082.html?src=rss
Created 3mo | Jan 2, 2025, 3:10:14 PM


Login to add comment

Other posts in this group

Arkansas social media age verification law blocked by federal Judge

An Arkansas law requiring social media companies to verify the ages of their users has been

Apr 1, 2025, 9:40:18 PM | Engadget
Amazon’s new cinema plan is perfect… for the ‘80s

If you ever needed a definitive example of how money doesn’t necessarily buy you success or taste, take a look at Amazon’s studio arm. The mega-retailer’s production division, now known as Amazon-M

Apr 1, 2025, 5:10:41 PM | Engadget
Apple's Find My has finally launched in South Korea

Apple’s Find My feature has finally been enabled in South Korea,

Apr 1, 2025, 5:10:40 PM | Engadget
TikTok's ban deadline is coming. What happens next?

TikTok's deadline to sell off or cede its US operations is once again approaching. The 75-day extension

Apr 1, 2025, 5:10:39 PM | Engadget
Lazarus review: Wildly stylish, but it’s no Cowboy Bebop

You could call Shinichiro Watanabe's Lazarus a retread of his masterpiece, Cowboy Bebop. That’s not to say the show is bad — based on the five episodes I’ve seen so far, Lazar

Apr 1, 2025, 5:10:38 PM | Engadget