Chinese hackers access U.S. Treasury Department workstations, obtain unclassified documents

May Be Interested In:A Health Policy Veteran Puts 2025 in Perspective – KFF Health News


Washington — Chinese hackers remotely accessed several U.S. Treasury Department workstations and unclassified documents after compromising a third-party software service provider, the agency said Monday.

The department didn’t provide details on how many workstations had been accessed or what sort of documents the hackers may have obtained, but said in a letter to lawmakers revealing the breach that “at this time there is no evidence indicating the threat actor has continued access to Treasury information.” It said the hack was being investigated as a “major cybersecurity incident.”

“Treasury takes very seriously all threats against our systems, and the data it holds,” a department spokesperson said in a separate statement. “Over the last four years, Treasury has significantly bolstered its cyber defense, and we will continue to work with both private and public sector partners to protect our financial system from threat actors.”

China denied any involvement, Agency France-Presse reported, citing China’s foreign ministry as saying Beijing “has always opposed all forms of hacker attacks, and we are even more opposed to the spread of false information against China for political purposes.”

“We have stated our position many times regarding such groundless accusations that lack evidence,” foreign ministry spokeswoman Mao Ning said. 

The revelation comes as U.S. officials are continuing to grapple with the fallout from a massive Chinese cyberespionage campaign known as Salt Typhoon that gave officials in Beijing access to private texts and phone conversations of an unknown number of Americans. A top White House official said Friday that the number of telecommunications companies confirmed to have been affected by the hack has now risen to nine.

The Treasury Department said it learned of the problem on Dec. 8 when a third-party software service provider, BeyondTrust, flagged that hackers had stolen a key “used by the vendor to secure a cloud-based service used to remotely provide technical support” to workers. That key helped the hackers override the service’s security and gain remote access to several employee workstations. 


Chinese hackers accessed data from internet providers, intelligence officials warn

00:22

The compromised service has since been taken offline, and there’s no evidence that the hackers still have access to department information, Aditi Hardikar, an assistant Treasury secretary, said in the letter Monday to leaders of the Senate Banking Committee.

The department said it was working with the FBI and the Cybersecurity and Infrastructure Security Agency, and that the hack had been attributed to Chinese culprits. It did not elaborate.

share Share facebook pinterest whatsapp x print

Similar Content

Former top aide to New York City's mayor surrenders to DA's office to face charges
Former top aide to New York City’s mayor surrenders to DA’s office to face charges
Alone with a killer in the Montana wilderness
Alone with a killer in the Montana wilderness
Jeff Bezos says he is 'optimistic' about a new Trump term and can help with cutting regulations
Jeff Bezos says he is ‘optimistic’ about a new Trump term and can help with cutting regulations
3 smart gold investing moves to make before November
3 smart gold investing moves to make before November
Saturday Sessions: Waxahatchee performs
Saturday Sessions: Waxahatchee performs
What to know about Billy Long, the ex-congressman and auctioneer Trump wants to head the IRS
What to know about Billy Long, the ex-congressman and auctioneer Trump wants to head the IRS
Eyes on the World: Uncovering Hidden Truths | © 2024 | Daily News