Article Details
Scrape Timestamp (UTC): 2025-01-06 20:58:30.165
Original Article Text
Click to Toggle View
CISA says recent government hack limited to US Treasury. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said today that the Treasury Department breach disclosed last week did not impact other federal agencies. "At this time, there is no indication that any other federal agencies have been impacted by this incident," CISA said. "CISA continues to monitor the situation and coordinate with relevant federal authorities to ensure a comprehensive response." The Treasury Department disclosed last Monday that Chinese government hackers breached its network in what it described as a "major cybersecurity incident" after compromising a BeyondTrust instance used by the federal agency using a stolen Remote Support SaaS API key. In a letter to Congress, the agency said its remote support provider, BeyondTrust, first notified it of the breach on December 8th. "Based on available indicators, the incident has been attributed to a China state-sponsored Advanced Persistent Threat (APT) actor. In accordance with Treasury policy, intrusions attributable to an APT are considered a major cybersecurity incident," the letter added. Since then, U.S. officials have revealed that the attackers specifically targeted the Office of Foreign Assets Control (OFAC), which administers and enforces trade and economic sanctions programs, likely to collect intelligence on what Chinese individuals and organizations the U.S. might consider sanctioning. The hackers also breached the Treasury's Office of Financial Research, but the full impact of the attack is still being assessed. However, officials said there was no evidence that the Chinese state hackers maintained access to the agency's systems after shutting down the compromised BeyondTrust instance. "The security of federal systems and the data they protect is of critical importance to our national security," the U.S. cybersecurity agency added today. "We are working aggressively to safeguard against any further impacts and will provide updates, as appropriate."
Daily Brief Summary
The US Treasury disclosed a cybersecurity breach by Chinese government hackers, impacting the Office of Foreign Assets Control and the Office of Financial Research.
The breach, attributed to a state-sponsored Advanced Persistent Threat (APT), involved compromising a BeyondTrust SaaS API key.
CISA has confirmed that no other federal agencies have been affected by this incident.
The breach was first detected by BeyondTrust on December 8, and the compromised instance was subsequently shut down.
The primary intent behind targeting the OFAC appears to be gathering intelligence related to potential sanctions against Chinese entities.
There is currently no indication that the hackers still have access to Treasury's systems post-breach.
CISA is coordinating with relevant federal authorities to ensure a comprehensive response and prevent future incidents.