US Treasury Department Hacked by China-Based Threat Actor

US Treasury Department Hacked by China-Based Actor.
Matilda
US Treasury Department Hacked by China-Based Threat Actor
A major security breach at the US Treasury Department has been confirmed, with a China-based threat actor gaining unauthorized access to employee workstations and unclassified documents. The incident, first reported by The New York Times, involved a compromise of remote management software used by the Treasury Department. Key Findings: Breach Impact: A China state-sponsored Advanced Persistent Threat (APT) actor exploited a vulnerability in BeyondTrust's remote management software. Data Compromised: The breach allowed the attacker to access employee workstations and steal "some unclassified documents." Mitigation Efforts: The Treasury Department, in collaboration with CISA and the FBI, has taken the compromised service offline and is investigating the extent of the breach. BeyondTrust Involvement: BeyondTrust acknowledged a security incident earlier this month, impacting customers using its remote support software. The company attributed the issue to a compromised API key. Back…