China-linked attack on US Treasury Department reportedly targeted its sanctions office

The US Treasury Department told lawmakers in a letter back in December that its documents and workstations were accessed by an external party in a security breach. It described the attack as "a major cybersecurity incident" and attributed it to a "China state-sponsored Advanced Persistent Threat actor." Now, The Washington Post has reported that the bad actors infiltrated a "highly sensitive office" within the Treasury in charge of deliberating and administering US government sanctions. 

As The Post explains, the Office of Foreign Assets Control (OFAC) is in possession of some important information that could be very useful to another country's government. While the hackers were only able to steal unclassified data, they could still have gotten their hands on the identities of potential sanction targets. They could also have stolen pieces of evidence that the agency had collected as part of its investigation on entities that the government is thinking of sanctioning. Overall, the attackers could have gotten enough information to give them the knowledge of how the US develops sanctions against foreign entities. 

In addition to OFAC, the Office of the Treasury Secretary and the Office of Financial Research were also affected by the breach. The attackers infiltrated the Treasury's systems by gaining access to a key used by BeyondTrust, a cloud-based service that provides the department with technical support. 

The US government has attributed numerous cyberattacks on its agencies and American companies to China state-sponsored actors over the years. Just last year, the FBI blamed "PRC-affiliated actors" for a massive hack on US telecom companies. The actors, a group known as Salt Typhoon, reportedly targeted the mobile devices of diplomats, government officials and other people linked to both presidential campaigns. According to The Post, Chinese officials called claims that their country was involved in the attack on the Treasury Department "groundless" and insisted that their government "has always opposed all forms of hacker attacks."

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/china-linked-attack-on-us-treasury-department-reportedly-targeted-its-sanctions-office-150033082.html?src=rss https://www.engadget.com/cybersecurity/china-linked-attack-on-us-treasury-department-reportedly-targeted-its-sanctions-office-150033082.html?src=rss
Creată 2d | 2 ian. 2025, 15:10:14


Autentifică-te pentru a adăuga comentarii

Alte posturi din acest grup

What to read this weekend: The friends you make in the apocalypse

These are the new releases that caught our attention this week: a (surprisingly refreshing) post-apocalyptic tale, and an exorcism thriller.

4 ian. 2025, 15:50:17 | Engadget
Utah lawsuit alleges TikTok knew minors were being exploited on livestreams

Streams on TikTok Live were used to exploit children, according to

3 ian. 2025, 23:30:13 | Engadget
CES 2025: The new tech we're expecting to see from Samsung, NVIDIA, LG and more in Las Vegas

Time to get into the habit of writing "2025" instead of 2024, and the year may have just begun, but the Engadget team is already working hard for CES 2025. This weekend, many from the Engadget team

3 ian. 2025, 21:20:09 | Engadget
Meta sends its AI-generated profiles to hell where they belong

Meta has nuked a bunch of its AI-generated profiles from Facebook Instagram, the company confirmed, after the AI characters prompted widespread outrage and ridicule from users on social media.

3 ian. 2025, 21:20:08 | Engadget
Hisense’s new ‘laser TV’ projector boosts the brightness and contrast

Hisense unveiled its latest L9 series laser TV — the L9Q — at CES 2025. The “television” (an ultra-short-throw laser pr

3 ian. 2025, 18:50:21 | Engadget