State-sponsored Chinese hackers accessed unclassified documents on U.S. Treasury computers via a third-party software vulnerability.
The U.S. Treasury department said a state-sponsored Chinese hacking operation was able to use third-party software to access the desktop computers of Treasury employees in what the department is calling 'a major incident.' In a letter seen by NBC News, Aditi Hardikar, assistant secretary for management of the U.S. Department of the Treasury, wrote that the office was notified on Dec. 8 of the breach. The letter is addressed to Sen. Sherrod Brown, D-Ohio, and Sen. Tim Scott, R-S.C.
, the chairman and ranking member, respectively, of the Committee on Banking, Housing and Urban Affairs. Hardikar wrote that the U.S. Treasury was told by 'a third-party software service provider, BeyondTrust, that a threat actor had gained access to a key used by the vendor to secure a cloud-based service used to remotely provide technical support for Treasury Departmental Offices (DO) end users.' With this access, the 'threat actor' was able to override certain security measures and access the department office user workstations. The information accessed by the 'threat actor' was unclassified documents. The U.S. Treasury has been working with Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, and other members of the intelligence community, as well as 'third-party forensic investigators to fully characterize the incident and determine its overall impact,' according to the letter. In a statement to NBC News, a Treasury spokesperson reiterated the contents of the letter, saying that 'The compromised BeyondTrust service has been taken offline' and that there is 'no evidence indicating the threat actor has continued access to Treasury systems or information.' The spokesperson said the department is working in coordination with other agencies, including the FBI and the Cybersecurity and Infrastructure Security Agency to “ascertain the impact of this incident.” 'Treasury takes very seriously all threats against our systems, and the data it holds
CYBERSECURITY HACKING CHINA US TREASURY DATA BREACH
United States Latest News, United States Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
Chinese Hackers Breach U.S. Treasury DepartmentChinese hackers gained access to unclassified U.S. Treasury Department workstations through a third-party software provider. The breach was discovered in December 2022 and the compromised service has since been taken offline. There is no evidence of ongoing access to Treasury information.
Read more »
Chinese Hackers Breach U.S. Treasury DepartmentChinese hackers gained unauthorized access to several U.S. Treasury Department workstations and unclassified documents via a compromised third-party software provider. The breach was discovered on December 8th, 2022, and the affected service has been taken offline. While the extent of the information compromised remains unclear, the Treasury Department stated that there's no evidence of ongoing access by the threat actors.
Read more »
Chinese Hackers Infiltrate US Treasury WorkstationsChinese state-sponsored hackers infiltrated US Treasury workstations, accessing unclassified documents, according to a letter from the Treasury Department to lawmakers. The incident, described as a major cybersecurity event, involved a stolen key used to override security measures on a cloud-based service.
Read more »
Chinese Hackers Breach Ninth U.S. Telecom CompanyChinese hackers have breached the networks of a ninth U.S. telecommunications company, giving officials in Beijing access to private texts and phone conversations of an unknown number of Americans. The hacking operation, known as Salt Typhoon, has alarmed national security officials and exposed vulnerabilities in the private sector.
Read more »
U.S. officials ‘still working to expel’ Chinese hackers from massive telecom breachThis is additional taxonomy that helps us with analytics
Read more »
FBI Warns of Chinese Hackers Targeting Telecoms, Urges EncryptionThe FBI has issued a warning about Chinese government-linked hackers infiltrating telecom networks and stealing user data. The agency urges people to use end-to-end encryption for phone calls and text messages to protect their information.
Read more »