Tuesday , June 23 2026
US treasury

US Treasury says it was hacked by China via third party: Beijing denies

The US Treasury Department said on Monday that Chinese-linked hackers were able to gain access to ‘unclassified documents’ after compromising the agency’s networks earlier this month.

According to a US Treasury letter addressed to US Senators Sherrod Brown (D-OH) and Tim Scott (R-SC) on Monday – the Chinese hackers gained access to the documents via a third-party vendor responsible for providing cybersecurity services to the agency.

India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

Anthropic’s Mythos reportedly broke NSA classified systems in hours

The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
Anthropic’s Mythos reportedly broke NSA classified systems in hours

OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

AryStinger botnet infected thousands of D-Link routers globally

AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
AryStinger botnet infected thousands of D-Link routers globally

Hacker suspected of sending alerts across Brazil

Brazil's government suspects a hacking attack triggered an unauthorized ‌alert sent to cell phones across parts of the country early...
Read More
Hacker suspected of sending alerts across Brazil

CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

Barracuda hosts Dhaka roundtable on cyber resilience

Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
Barracuda hosts Dhaka roundtable on cyber resilience

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

CISA: Splunk flaw under active exploit, patch by Sunday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has asked federal agencies to protect their systems by Sunday from a...
Read More
CISA: Splunk flaw under active exploit, patch by Sunday

Texas data breach exposes 3 million driver’s licenses

The Texas Parks and Wildlife Department (TPWD) revealed a data leak at its license system provider. This leak exposed private...
Read More
Texas data breach exposes 3 million driver’s licenses

The cybersecurity firm, BeyondTrust, was the first to become aware of the breach, alerting the Treasury Department on December 8th.

According to the Treasury, the hackers broke into employee workstations and were able to access the documents using a stolen key to its cloud-based tech support platform. The letter called the state-sponsored cyberattack a “major incident,” under US Treasury guidelines.

Attributed to a Chinese APT (advanced persistent threat), the Beijing threat actors “gained access to a key used by the vendor to secure a cloud-based service used to remotely provide technical support for Treasury Departmental Offices (DO) end users,” the letter said.

Once the key was in their possession, the hackers were able to “override the service’s security, remotely access certain Treasury DO user workstations, and access certain unclassified documents maintained by those users,” it stated.

Following incident response protocols, the compromised BeyondTrust service was taken offline, disrupting any further access to Treasury information.

Source: Cybernews

Senior Researcher John Scott-Railton of the Citizen Lab at the University of Toronto posted about the incident on X noting that the “attackers used the platform like a backdoor on Treasury machines where it was installed.”

“Given BeyondTrust’s big client list, makes one wonder if other customers were targeted,” he commented.

The letter also said that the US Cybersecurity and Security Infrastructure Agency (CISA) was immediately notified and an official investigation was launched with the FBI and other third-party experts.

A spokesperson for BeyondTrust, based in Johns Creek, Georgia, told Reuters in an email that the company “previously identified and took measures to address a security incident in early December 2024” involving its remote support product. BeyondTrust “notified the limited number of customers who were involved,” and law enforcement was notified, the spokesperson said. “BeyondTrust has been supporting the investigative efforts.”

Referring to a statement on its website updated on December 18th, the cybersecurity firm said it had “notified the limited number of customers who were involved.” The spokesperson added that “BeyondTrust has been supporting the investigative efforts.”

Meantime, Tom Hegel, a threat researcher at SentinelOne, said the reported security incident “fits a well-documented pattern of operations by PRC-linked groups, with a particular focus on abusing trusted third-party services – a method that has become increasingly prominent in recent years,” although added that BeyondTrust had not officially confirmed the link.

A spokesperson for the Chinese Embassy in Washington on Monday denied involvement, instead stating that Beijing “firmly opposes the US smear attacks against China without any factual basis,” Reuters reported.

CISA and the FBI had no formal comment as of Monday.

“Beijing has hit back at accusations that a China state-sponsored actor was behind a cyber breach at the US treasury department, calling the claims “groundless”.

On Tuesday, China denied the claims, with the foreign ministry saying Beijing “has always opposed all forms of hacker attacks, and we are even more opposed to the spread of false information against China for political purposes”.

“We have stated our position many times regarding such groundless accusations that lack evidence,” the foreign ministry spokesperson Mao Ning said, reported by The Guardian.

Check Also

FortiBleed

FortiBleed: 70,000 Fortinet Firewalls Compromised Globally

A vast cyber spying operation called “FortiBleed” has quietly compromised more than 73,932 different Fortinet …