China-linked hackers accessed over 400 US Treasury computers

The US Treasury Department announced in a letter back in December that it had been the victim of a security breach, attributing it to a “China state-sponsored Advanced Persistent Threat actor.” Now we know more about the extent of the hack, thanks to reporting by Bloomberg.

The hacking group got into more than 400 laptop and desktop computers, many of which were linked to senior leaders focused on “sanctions, international affairs and intelligence.” They also accessed employee usernames and passwords, in addition to more than 3,000 files on unclassified personal computers. These documents included travel data, organizational charts, sanction materials and foreign investment metrics.

An agency report indicates that the perpetrators likely stole a whole lot of this data, but were unable to get into the Treasury’s classified or email systems. The hackers did access materials regarding investigations run by the Committee on Foreign Investment. This committee reviews security implications surrounding real estate purchases and foreign investments in the US.

The agency report also notes that there wasn’t any evidence to suggest that the hackers tried to hide in the Treasury’s systems for the purpose of long-term intelligence gathering, and they didn’t leave behind any malware.

China reacts on ‘Treasury-Hack’ pic.twitter.com/7j7OaQ6eKD

— Willem Middelkoop (@wmiddelkoop) January 2, 2025

Investigators have attributed the intrusion to a notorious Chinese state-sponsored hacking group called Silk Typhoon, Halfnium or UNC5221. It has been suggested that they performed the hack outside of normal working hours to avoid detection. Last month, a spokesperson for the Chinese Foreign Ministry called the accusation that the attack was state-sponsored “unwarranted and groundless.”

Counterintelligence officials are still in the midst of a “comprehensive damage assessment” but Treasury employees are set to brief the Senate Committee on Banking, Housing and Urban Affairs on the matter this week.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/china-linked-hackers-accessed-over-400-us-treasury-computers-182420268.html?src=rss https://www.engadget.com/cybersecurity/china-linked-hackers-accessed-over-400-us-treasury-computers-182420268.html?src=rss
Établi 10d | 16 janv. 2025 à 20:10:15


Connectez-vous pour ajouter un commentaire

Autres messages de ce groupe

WhatsApp could soon let iOS users have multiple accounts on one device

The latest WhatsApp beta update for iOS gives users the ability to add and switch between multiple accounts on a single device, according to

26 janv. 2025 à 00:30:09 | Engadget
What to read this weekend: An immersive new work of Africanfuturism

These are the new releases that we picked up this week.

 

25 janv. 2025 à 22:10:23 | Engadget
The filmmaker behind Barbarian is leading a new Resident Evil reboot

A new Resident Evil reboot from Barbarian writer and director Zach Cregger is in the works, according to

25 janv. 2025 à 19:50:03 | Engadget
Endless Legend 2 is real and there’s a mysterious trailer to prove it

The extremely popular strategy game Endless Legend

24 janv. 2025 à 20:40:05 | Engadget
Apple says 68 percent of all iPhones are running iOS 18

Apple posted iOS 18 adoption

24 janv. 2025 à 20:40:03 | Engadget
The best Super Bowl 2025 TV deals we could find

Super Bowl LIX is just a couple of weeks away, which means it's a decent time to be in the market for a new TV. If you're looking to make a living room upgrade, we've picked through Amazon, Best Bu

24 janv. 2025 à 18:21:19 | Engadget