1. Home
  2. / Interesting facts
  3. / Something Is Happening With Security in the United States: Chinese Hackers Managed to Infiltrate the Department of the Treasury
Reading time 2 min of reading Comments 1 comment

Something Is Happening With Security in the United States: Chinese Hackers Managed to Infiltrate the Department of the Treasury

Written by Noel Budeguer
Published on 01/01/2025 at 10:32
EUA - China - Estados Unidos - Hackers
Algo está acontecendo com a segurança nos EUA: hackers chineses conseguiram se infiltrar no Departamento do Tesouro
  • Reaction
  • Reaction
2 people reacted to this.
React to this article

State-Sponsored Chinese Hackers Breach U.S. Treasury Department, Compromising Unclassified Data. Action Reveals Serious Flaws in American Cybersecurity

A state-sponsored group of cybercriminals from China remotely accessed certain workstations used by employees of the U.S. Treasury Department and obtained some unclassified documents. The cybersecurity incident, classified as “significant” by the affected agency, was disclosed in recent hours in a public letter addressed to members of Congress.

To achieve their goal, according to the report, the attackers compromised the security of an external vendor. This is BeyondTrust, which was responsible for securing a remote technical support system used by U.S. Treasury employees. Specifically, an access key was stolen that allowed the aforementioned invasion to occur. They explain that measures were then taken to address the issue.

Authorities attributed the incident to a state-sponsored group of cybercriminals from China

Not the First Chinese Cyberattack Against the United States

One of the measures taken was to disconnect the affected service, while another was to initiate an investigation with the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Intelligence Community, along with independent forensic investigators. The purpose of this latter action was to determine the extent of the attack and, importantly, to identify those responsible.

Authorities attributed the incident to a state-sponsored group of cybercriminals from China. Specifically, they refer to an Advanced Persistent Threat (APT). Behind this type of activity are usually persistent attacks with sophisticated techniques. Certainly, breaching the security of one of the U.S. government’s departments is no small feat.

Speaking of the U.S. Treasury Department is mentioning the agency that oversees important and often confidential data regarding financial systems worldwide. Among its functions is analyzing the economies of other countries, such as China, and implementing sanctions. This agency has indeed been the instrument for applying sanctions against Chinese companies amid Russia’s invasion of Ukraine.

We say that something is happening with the cybersecurity of the world’s largest economic and military power because this is not the first time in recent years that Chinese cybercriminals have managed to breach their systems. In 2023, around 60,000 emails from the State Department were leaked. And this year, it came to light that a group known as Salt Typhoon infiltrated U.S. telecommunications providers and is believed to have extracted information from elected President Donald Trump’s line.

Sign up
Notify of
guest
1 Comment
most recent
older Most voted
Built-in feedback
View all comments
Muriel
Muriel
01/01/2025 17:12

Muito normal esses
Estados tanto um como o outro fazem a todos os outros só que uns tornam público e outros não. Não vejo nada de novo entre potencias

Noel Budeguer

Sou jornalista argentino baseado no Rio de Janeiro, com foco em energia e geopolítica, além de tecnologia e assuntos militares. Produzo análises e reportagens com linguagem acessível, dados, contexto e visão estratégica sobre os movimentos que impactam o Brasil e o mundo. 📩 Contato: noelbudeguer@gmail.com

Share in apps
1
0
I'd love to hear your opinion, please comment.x