China-linked hackers accessed over 400 US Treasury computers

The US Treasury Department announced in a letter back in December that it had been the victim of a security breach, attributing it to a “China state-sponsored Advanced Persistent Threat actor.” Now we know more about the extent of the hack, thanks to reporting by Bloomberg.

The hacking group got into more than 400 laptop and desktop computers, many of which were linked to senior leaders focused on “sanctions, international affairs and intelligence.” They also accessed employee usernames and passwords, in addition to more than 3,000 files on unclassified personal computers. These documents included travel data, organizational charts, sanction materials and foreign investment metrics.

An agency report indicates that the perpetrators likely stole a whole lot of this data, but were unable to get into the Treasury’s classified or email systems. The hackers did access materials regarding investigations run by the Committee on Foreign Investment. This committee reviews security implications surrounding real estate purchases and foreign investments in the US.

The agency report also notes that there wasn’t any evidence to suggest that the hackers tried to hide in the Treasury’s systems for the purpose of long-term intelligence gathering, and they didn’t leave behind any malware.

China reacts on ‘Treasury-Hack’ pic.twitter.com/7j7OaQ6eKD

— Willem Middelkoop (@wmiddelkoop) January 2, 2025

Investigators have attributed the intrusion to a notorious Chinese state-sponsored hacking group called Silk Typhoon, Halfnium or UNC5221. It has been suggested that they performed the hack outside of normal working hours to avoid detection. Last month, a spokesperson for the Chinese Foreign Ministry called the accusation that the attack was state-sponsored “unwarranted and groundless.”

Counterintelligence officials are still in the midst of a “comprehensive damage assessment” but Treasury employees are set to brief the Senate Committee on Banking, Housing and Urban Affairs on the matter this week.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/china-linked-hackers-accessed-over-400-us-treasury-computers-182420268.html?src=rss https://www.engadget.com/cybersecurity/china-linked-hackers-accessed-over-400-us-treasury-computers-182420268.html?src=rss
Creato 4h | 16 gen 2025, 20:10:15


Accedi per aggiungere un commento

Altri post in questo gruppo

Google decides it won't comply with EU fact-checking law

Google has told the EU it will not comply with a forthcoming fact-checking law, according to a copy of a let

16 gen 2025, 22:30:05 | Engadget
CFPB fines Block $175m over Cash App's lax fraud controls

The Consumer Financial Protection Bureau (CFPB) announced today that's

16 gen 2025, 22:30:04 | Engadget
AGDQ just ended, but there's already a schedule for Frost Fatales and it owns

Awesome Games Done Quick has already wrapped up for 2025 (with a cool

16 gen 2025, 22:30:03 | Engadget
MoviePass made a film trailer app for the Oculus Quest and Apple Vision Pro

If you're a cinephile who misses the old Apple TV app for movie trailers, MoviePass CEO Stacy Spikes knows your pain. So he decided to build a trailer app of his own, one that could easily

16 gen 2025, 20:10:14 | Engadget
TikTok, Temu and more face complaints alleging GDPR violations in EU

Austrian privacy advocate NOYB has launched its first GDPR complaints against Chinese businesses. The organization has filed complaints against TikTok, Xiaomi, Shein, AliExpress, Temu and WeChat, a

16 gen 2025, 20:10:13 | Engadget
Apple pauses AI notification summaries of news alerts in latest iOS beta

Some significant changes are coming to Apple Intelligence notification summaries. With the latest slate of developer previews for iOS 18.3, iPadOS 18.3 and macOS Sequoia 15.3, Apple has suspended t

16 gen 2025, 20:10:12 | Engadget
The Nintendo Switch 2 has been announced, here's everything we know

As the world turns, so do the console generations. The Nintendo Switch is over seven years old

16 gen 2025, 17:40:29 | Engadget