China-linked hackers accessed over 400 US Treasury computers

The US Treasury Department announced in a letter back in December that it had been the victim of a security breach, attributing it to a “China state-sponsored Advanced Persistent Threat actor.” Now we know more about the extent of the hack, thanks to reporting by Bloomberg.

The hacking group got into more than 400 laptop and desktop computers, many of which were linked to senior leaders focused on “sanctions, international affairs and intelligence.” They also accessed employee usernames and passwords, in addition to more than 3,000 files on unclassified personal computers. These documents included travel data, organizational charts, sanction materials and foreign investment metrics.

An agency report indicates that the perpetrators likely stole a whole lot of this data, but were unable to get into the Treasury’s classified or email systems. The hackers did access materials regarding investigations run by the Committee on Foreign Investment. This committee reviews security implications surrounding real estate purchases and foreign investments in the US.

The agency report also notes that there wasn’t any evidence to suggest that the hackers tried to hide in the Treasury’s systems for the purpose of long-term intelligence gathering, and they didn’t leave behind any malware.

China reacts on ‘Treasury-Hack’ pic.twitter.com/7j7OaQ6eKD

— Willem Middelkoop (@wmiddelkoop) January 2, 2025

Investigators have attributed the intrusion to a notorious Chinese state-sponsored hacking group called Silk Typhoon, Halfnium or UNC5221. It has been suggested that they performed the hack outside of normal working hours to avoid detection. Last month, a spokesperson for the Chinese Foreign Ministry called the accusation that the attack was state-sponsored “unwarranted and groundless.”

Counterintelligence officials are still in the midst of a “comprehensive damage assessment” but Treasury employees are set to brief the Senate Committee on Banking, Housing and Urban Affairs on the matter this week.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/china-linked-hackers-accessed-over-400-us-treasury-computers-182420268.html?src=rss https://www.engadget.com/cybersecurity/china-linked-hackers-accessed-over-400-us-treasury-computers-182420268.html?src=rss
Létrehozva 1mo | 2025. jan. 16. 20:10:15


Jelentkezéshez jelentkezzen be

EGYÉB POSTS Ebben a csoportban

The Apple Pencil Pro is back on sale for $99

Apple’s fantastic stylus, the Pencil Pro, is on sale

2025. febr. 24. 18:30:26 | Engadget
Blendo Games' oddball sci-fi shooter Skin Deep hits PC on April 30

Blendo Games' latest installment of interactive weirdness, Skin Deep, is due to hit Steam on April 30, after nearly seven years of development. Skin Deep is a first-

2025. febr. 24. 18:30:24 | Engadget
Nintendo Switch 2 is launching soon, here's everything we know so far

As the world turns, so do the console generations. The Nintendo Switch is over seven years old

2025. febr. 24. 18:30:23 | Engadget
An enhanced version of Sayonara Wild Hearts for PS5 is out now

My dream of a Sayonara Wild Hearts sequel might never be f

2025. febr. 24. 18:30:22 | Engadget
Apple plans to invest $500 billion in the US over the next four years

Apple plans to ramp up its US hiring and investments. On Monday, the company

2025. febr. 24. 18:30:20 | Engadget
Pick up one of our favorite power banks while it's on sale for 52 percent off

If you're on the market for a power bank that can serve your laptop in addition to all your mobile devices, the

2025. febr. 24. 16:10:20 | Engadget