US NewsChinese-backed hackers breach U.S. treasury via tech flaw

Chinese-backed hackers breach U.S. treasury via tech flaw

The United States Treasury Department reported a cyberattack that allowed hackers, allegedly sponsored by Chinese authorities, to access the department employees' computers via third-party software. According to NBC News, authorities described the situation as a "major incident. "

President of China Xi Jinping
President of China Xi Jinping
Images source: © Getty Images | Manuel Orbegozo

The attackers gained access to the Treasury Department systems through BeyondTrust, a cybersecurity services provider that offers remote technical support. By compromising a security key used by BeyondTrust, the hackers managed to bypass security measures and gain access to user workstations, the report reads.

A threat actor had gained access to a key used by the vendor to secure a cloud-based service used to remotely provide technical support for Treasury Departmental Offices (DO) end users, as stated in a letter to Senators Sherrod Brown and Tim Scott.

China reacts to the allegations

According to NBC News, Chinese authorities categorically denied the accusations. "China consistently opposes all forms of hacking and is firmly against the spread of false information targeting China for political purposes," declared Mao Ning, spokeswoman for the Chinese Ministry of Foreign Affairs.

U.S. authorities, including the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and forensic specialists, are working on a full assessment of the incident and its potential implications.

According to NBC News, a Treasury Department spokesperson assured that "the compromised BeyondTrust service has been taken offline" and that there is "no evidence indicating the threat actor has continued access to Treasury systems or information. "

Treasury takes very seriously all threats against our systems, and the data it holds. Over the last four years, Treasury has significantly bolstered its cyber defense, and we will continue to work with both private and public sector partners to protect our financial system from threat actorsThe department takes all threats to its systems and data very seriously. Cyber defenses have been significantly strengthened in recent years, it was added in the statement.
Related content
© essanews.com
·

Downloading, reproduction, storage, or any other use of content available on this website—regardless of its nature and form of expression (in particular, but not limited to verbal, verbal-musical, musical, audiovisual, audio, textual, graphic, and the data and information contained therein, databases and the data contained therein) and its form (e.g., literary, journalistic, scientific, cartographic, computer programs, visual arts, photographic)—requires prior and explicit consent from Wirtualna Polska Media Spółka Akcyjna, headquartered in Warsaw, the owner of this website, regardless of the method of exploration and the technique used (manual or automated, including the use of machine learning or artificial intelligence programs). The above restriction does not apply solely to facilitate their search by internet search engines and uses within contractual relations or permitted use as specified by applicable law.Detailed information regarding this notice can be found  here.