Chinese Hackers Breach US Treasury Systems in Major Cybersecurity Incident

The US Treasury Department has reported a significant cybersecurity breach allegedly orchestrated by Chinese state-sponsored hackers. The attackers gained access to employee workstations and unclassified documents earlier this month, prompting the agency to label it a “major incident” in a formal notification to lawmakers.
The attack is part of a broader pattern of high-profile breaches in the US blamed on China, which has denied involvement, dismissing the accusations as “baseless.” The Treasury Department revealed that the hackers exploited a vulnerability in a third-party service provider, BeyondTrust, which offers remote technical support to employees. BeyondTrust has since been taken offline to mitigate further risks.
Initial investigations, involving the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and forensic experts, suggest the breach was carried out by a “China-based Advanced Persistent Threat (APT) actor.” Officials assured that no evidence indicates continued unauthorized access to Treasury data.
This incident follows other recent cyberattacks attributed to China, including a December hack targeting telecom companies that potentially exposed extensive phone records. The breach underscores ongoing challenges in protecting critical US infrastructure from advanced cyber threats.


