China-linked hackers accessed over 400 US Treasury computers

The US Treasury Department announced in a letter back in December that it had been the victim of a security breach, attributing it to a “China state-sponsored Advanced Persistent Threat actor.” Now we know more about the extent of the hack, thanks to reporting by Bloomberg.

The hacking group got into more than 400 laptop and desktop computers, many of which were linked to senior leaders focused on “sanctions, international affairs and intelligence.” They also accessed employee usernames and passwords, in addition to more than 3,000 files on unclassified personal computers. These documents included travel data, organizational charts, sanction materials and foreign investment metrics.

An agency report indicates that the perpetrators likely stole a whole lot of this data, but were unable to get into the Treasury’s classified or email systems. The hackers did access materials regarding investigations run by the Committee on Foreign Investment. This committee reviews security implications surrounding real estate purchases and foreign investments in the US.

The agency report also notes that there wasn’t any evidence to suggest that the hackers tried to hide in the Treasury’s systems for the purpose of long-term intelligence gathering, and they didn’t leave behind any malware.

China reacts on ‘Treasury-Hack’ pic.twitter.com/7j7OaQ6eKD

— Willem Middelkoop (@wmiddelkoop) January 2, 2025

Investigators have attributed the intrusion to a notorious Chinese state-sponsored hacking group called Silk Typhoon, Halfnium or UNC5221. It has been suggested that they performed the hack outside of normal working hours to avoid detection. Last month, a spokesperson for the Chinese Foreign Ministry called the accusation that the attack was state-sponsored “unwarranted and groundless.”

Counterintelligence officials are still in the midst of a “comprehensive damage assessment” but Treasury employees are set to brief the Senate Committee on Banking, Housing and Urban Affairs on the matter this week.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/china-linked-hackers-accessed-over-400-us-treasury-computers-182420268.html?src=rss https://www.engadget.com/cybersecurity/china-linked-hackers-accessed-over-400-us-treasury-computers-182420268.html?src=rss
созданный 1mo | 16 янв. 2025 г., 20:10:15


Войдите, чтобы добавить комментарий

Другие сообщения в этой группе

Atari’s side-scrolling Breakout reboot arrives on March 25

Proving that truly no IP is safe from modern reboot

25 февр. 2025 г., 17:40:10 | Engadget
Paramount+ adds 50 classic MTV Unplugged episodes

If you're a music fan of a certain age, there's a good chance MTV Unplugged has special place in your heart. With the first episode airing in 1989, over the decades the series has produced some of

25 февр. 2025 г., 17:40:09 | Engadget
UK creatives protest AI copyright law changes with silent album and campaign

British creatives are speaking out against the government's proposed changes to copyright law. Take Kate Bush, Annie Lennox and Ben Howard, who join over 1,000 musicians in releasing a protest albu

25 февр. 2025 г., 17:40:08 | Engadget
Philips Hue Sync now available on LG smart TVs, eliminating the need for a control box

The Philips Hue Sync app is now available for many LG televisions, allowing synchronization between smart lights and TV screens. This eliminates the need for one of those

25 февр. 2025 г., 17:40:07 | Engadget
Clicks is finally releasing its keyboard add-on for some Android phones

First announced at CES 2024, the Clicks physical keyboard add-on for iPhones

25 февр. 2025 г., 17:40:06 | Engadget
OnePlus is delaying the Watch 3 launch because of a typo

One thing writers and multinational consumer electronics corporations have in common is we both need a good editor. Or, failing that, at least a good spell-checker. OnePlus somehow missed that step

25 февр. 2025 г., 17:40:05 | Engadget