Tuesday , February 18 2025
US treasury

US Treasury says it was hacked by China via third party: Beijing denies

The US Treasury Department said on Monday that Chinese-linked hackers were able to gain access to ‘unclassified documents’ after compromising the agency’s networks earlier this month.

According to a US Treasury letter addressed to US Senators Sherrod Brown (D-OH) and Tim Scott (R-SC) on Monday – the Chinese hackers gained access to the documents via a third-party vendor responsible for providing cybersecurity services to the agency.

150 Gov.t Portal affected
Black-Hat SEO Poisoning Indian “.gov.in, .ac.in” domain

Indian government and educational websites, along with reputable financial brands, have experienced SEO poisoning, causing user traffic to be redirected...
Read More
150 Gov.t Portal affected  Black-Hat SEO Poisoning Indian “.gov.in, .ac.in” domain

CVE-2018-19410 Exposes 600 PRTG Instances in Bangladesh

The Cyber Threat Intelligence Unit of BGD e-GOV CIRT has found 600 vulnerable PRTG instances in Bangladesh, affected by the...
Read More
CVE-2018-19410 Exposes 600 PRTG Instances in Bangladesh

Builder claims Rs 150 cr for data loss; AWS faces FIR In Bengaluru

Amazon Web Services (AWS) has been named in an FIR after a builder claimed damages to the tune of Rs...
Read More
Builder claims Rs 150 cr for data loss;  AWS faces FIR In Bengaluru

CISA Warns Active Exploitation of Apple iOS Security Flaw

CISA has issued an urgent warning about a critical zero-day vulnerability in Apple iOS and iPadOS, known as CVE-2025-24200, which...
Read More
CISA Warns Active Exploitation of Apple iOS Security Flaw

Massive IoT Data Breach Exposes 2.7 Billion Records

A major IoT data breach has exposed 2.7 billion records, including Wi-Fi network names, passwords, IP addresses, and device IDs....
Read More
Massive IoT Data Breach Exposes 2.7 Billion Records

SonicWall Firewall Auth Bypass Vulnerability Exploited in Wild

A serious authentication bypass vulnerability in SonicWall firewalls, called CVE-2024-53704, is currently being exploited, according to cybersecurity firms. The increase...
Read More
SonicWall Firewall Auth Bypass Vulnerability Exploited in Wild

AMD Patches High-Severity SMM Vulns Affecting EPYC and Ryzen Processors

AMD has released security patches for two high-severity vulnerabilities in its System Management Mode (SMM). If exploited, these could let...
Read More
AMD Patches High-Severity SMM Vulns Affecting EPYC and Ryzen Processors

Lazarus Group Unleashes New Malware Against Developers Worldwide

Lazarus Group has initiated a complex global campaign aimed at software developers and cryptocurrency users. Operation Marstech Mayhem uses the...
Read More
Lazarus Group Unleashes New Malware Against Developers Worldwide

Daily Security Update Dated : 15.02.2025

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Update Dated : 15.02.2025

Salt Typhoon to target Bangladeshi Universities, One identified

RedMike (Salt Typhoon) targeted university devices in Bangladesh, likely to access research in telecommunications, engineering, and technology, especially from institutions...
Read More
Salt Typhoon to target Bangladeshi Universities, One identified

The cybersecurity firm, BeyondTrust, was the first to become aware of the breach, alerting the Treasury Department on December 8th.

According to the Treasury, the hackers broke into employee workstations and were able to access the documents using a stolen key to its cloud-based tech support platform. The letter called the state-sponsored cyberattack a “major incident,” under US Treasury guidelines.

Attributed to a Chinese APT (advanced persistent threat), the Beijing threat actors “gained access to a key used by the vendor to secure a cloud-based service used to remotely provide technical support for Treasury Departmental Offices (DO) end users,” the letter said.

Once the key was in their possession, the hackers were able to “override the service’s security, remotely access certain Treasury DO user workstations, and access certain unclassified documents maintained by those users,” it stated.

Following incident response protocols, the compromised BeyondTrust service was taken offline, disrupting any further access to Treasury information.

Source: Cybernews

Senior Researcher John Scott-Railton of the Citizen Lab at the University of Toronto posted about the incident on X noting that the “attackers used the platform like a backdoor on Treasury machines where it was installed.”

“Given BeyondTrust’s big client list, makes one wonder if other customers were targeted,” he commented.

The letter also said that the US Cybersecurity and Security Infrastructure Agency (CISA) was immediately notified and an official investigation was launched with the FBI and other third-party experts.

A spokesperson for BeyondTrust, based in Johns Creek, Georgia, told Reuters in an email that the company “previously identified and took measures to address a security incident in early December 2024” involving its remote support product. BeyondTrust “notified the limited number of customers who were involved,” and law enforcement was notified, the spokesperson said. “BeyondTrust has been supporting the investigative efforts.”

Referring to a statement on its website updated on December 18th, the cybersecurity firm said it had “notified the limited number of customers who were involved.” The spokesperson added that “BeyondTrust has been supporting the investigative efforts.”

Meantime, Tom Hegel, a threat researcher at SentinelOne, said the reported security incident “fits a well-documented pattern of operations by PRC-linked groups, with a particular focus on abusing trusted third-party services – a method that has become increasingly prominent in recent years,” although added that BeyondTrust had not officially confirmed the link.

A spokesperson for the Chinese Embassy in Washington on Monday denied involvement, instead stating that Beijing “firmly opposes the US smear attacks against China without any factual basis,” Reuters reported.

CISA and the FBI had no formal comment as of Monday.

“Beijing has hit back at accusations that a China state-sponsored actor was behind a cyber breach at the US treasury department, calling the claims “groundless”.

On Tuesday, China denied the claims, with the foreign ministry saying Beijing “has always opposed all forms of hacker attacks, and we are even more opposed to the spread of false information against China for political purposes”.

“We have stated our position many times regarding such groundless accusations that lack evidence,” the foreign ministry spokesperson Mao Ning said, reported by The Guardian.

Check Also

January 2025

TRACKING RANSOMWARE
Akira Topped January 2025 as the Most Active Ransomware Threat

In January 2025, there were 510 global ransomware incidents, with Akira as the leading group …

Leave a Reply

Your email address will not be published. Required fields are marked *