US Treasury says it was hacked by China as documents stolen in ‘major incident’

Must Try

Trending

By Nadine Yousif and Joe Tidy | BBC News |

A Chinese state-sponsored hacker has broken into the US Treasury Department’s systems, accessing employee workstations and some unclassified documents, American officials said on Monday.

The breach occurred in early December and was made public in a letter penned by the Treasury Department to lawmakers notifying them of the incident.

The US agency characterised the breach as a “major incident”, and said it had been working with the FBI and other agencies to investigate the impact.

A spokesman for the Chinese embassy in Washington DC told BBC News that the accusation is part of a “smear attack” and was made “without any factual basis”.

The Treasury Department said in its letter to lawmakers that the China-based actor was able to override security via a key used by a third-party service provider that offers remote technical support to its employees.

The compromised third-party service – called BeyondTrust – has since been taken offline, officials said. They added that there is no evidence to suggest the hacker has continued to access Treasury Department information since.

Along with the FBI, the department has been working with the Cybersecurity and Infrastructure Security Agency and third-party forensic investigators to determine the breach’s overall impact.

Based on evidence it has gathered so far, officials said the hack appears to have been carried out by “a China-based Advanced Persistent Threat (APT) actor”.

“In accordance with Treasury policy, intrusions attributable to an APT are considered a major cybersecurity incident,” Treasury Department officials wrote in their letter to lawmakers.

The department was made aware of the hack on 8 December by BeyondTrust, a spokesperson told the BBC. According to the company, the suspicious activity was first spotted on 2 December, but it took three days for the company to determine that it had been hacked.

The spokesperson added that the hacker was able to remotely access several Treasury user workstations and certain unclassified documents that were kept by those users.

The department did not specify the nature of these files, or when and for how long the hack took place. They also did not specify the level of confidentiality of the computer systems. For instance, access to 100 low-level workers would likely be less valuable then access to only 10 computers at a higher echelon within the department.

The hackers may have been able to create accounts or change passwords in the three days that they were being watched by BeyondTrust.

As espionage agents, the hackers are believed to have been seeking information, rather than attempting to steal funds.

The spokesperson said the Treasury Department “takes very seriously all threats against our systems, and the data it holds”, and that it will continue to work on protecting its data from outside threats.

The department letter states that a supplemental report on the incident will be provided to lawmakers in 30 days.

Chinese embassy spokesman Liu Pengyu denied the department’s report, saying in a statement that it can be difficult to trace the origin of hackers.

“We hope that relevant parties will adopt a professional and responsible attitude when characterizing cyber incidents, basing their conclusions on sufficient evidence rather than unfounded speculation and accusations,” he said.

“The US needs to stop using cyber security to smear and slander China, and stop spreading all kinds of disinformation about the so-called Chinese hacking threats.”

This is the latest high-profile and embarrassing US breach blamed on Chinese espionage hackers.

It follows another hack of telecoms companies in December that potentially breached phone record data across large swathes of American society.

Related Articles

Zimbabwe’s ICT Minister, Tatenda Mavetera (right) seen here with NetOne GCEO Eng. Raphael Mushanawani as she tours the NetOne stand, 25 April 2024 (Picture via X - @@NetOneCellular)

Zimbabwe faces alarming rise in cyber attacks amid bank hacking

0
HARARE - Zimbabwe has witnessed a significant surge in cyber attacks in recent months, with local entities, including banks, falling victim to hacking, the country's Minister of Information Communication Technology, Tatenda Mavetera has revealed.
Zimbabwean president Emmerson Mnangagwa seen here with Russian president Vladimir Putin (Picture via www.kremlin.ru)

Global Chessboard: How China, Belarus, Russia and West vie for power in Zimbabwe

1
By Pride Mkono In my previous articles, I delved into the inevitable conclusion of President Emmerson Mnangagwa's tenure and explored potential successors, sparking lively debate and numerous emails on the subject. While I may not be able to respond to each message individually, I encourage continued engagement and dialogue on these important issues. In this piece, I shift the spotlight to the international dynamics surrounding Zimbabwe's succession, a crucial perspective often overlooked. The global stage is populated with a myriad of actors, each driven by their own interests, sometimes aligned, oftentimes in competition. My analysis zeros in on the key players: China, Belarus, Russia, and the United States along with its European allies.

Why China’s military support for Russia would be a ‘game changer’

3
The United States has said China is "considering providing lethal support" for Russia's war in Ukraine. Beijing quickly rebuffed the claim this week but experts say it may have some merit and, if China did give support, could be a "game changer" in the year-old conflict.
LI Changfeng ( Picture By Zim Morning Post )

Chinese national arrested after leaking illegal status during newspaper interview

1
A Chinese national is currently held at Khami Prison awaiting deportation after he leaked his illegal immigration status during a newspaper interview.

Hypersonic missiles: UK, US, and Australia to boost defence co-operation

2
The UK, US, and Australia will begin co-operating on research into hypersonic weapons and how to defend against them, the government has said.

Don't miss a story

Breaking News straight to your inbox.

No spam just news !

0 0 votes
Article Rating
Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Donate to Nehanda Radio

Latest Recipes

Latest

More Recipes Like This