China-linked attack on US Treasury Department reportedly targeted its sanctions office

The US Treasury Department told lawmakers in a letter back in December that its documents and workstations were accessed by an external party in a security breach. It described the attack as "a major cybersecurity incident" and attributed it to a "China state-sponsored Advanced Persistent Threat actor." Now, The Washington Post has reported that the bad actors infiltrated a "highly sensitive office" within the Treasury in charge of deliberating and administering US government sanctions. 

As The Post explains, the Office of Foreign Assets Control (OFAC) is in possession of some important information that could be very useful to another country's government. While the hackers were only able to steal unclassified data, they could still have gotten their hands on the identities of potential sanction targets. They could also have stolen pieces of evidence that the agency had collected as part of its investigation on entities that the government is thinking of sanctioning. Overall, the attackers could have gotten enough information to give them the knowledge of how the US develops sanctions against foreign entities. 

In addition to OFAC, the Office of the Treasury Secretary and the Office of Financial Research were also affected by the breach. The attackers infiltrated the Treasury's systems by gaining access to a key used by BeyondTrust, a cloud-based service that provides the department with technical support. 

The US government has attributed numerous cyberattacks on its agencies and American companies to China state-sponsored actors over the years. Just last year, the FBI blamed "PRC-affiliated actors" for a massive hack on US telecom companies. The actors, a group known as Salt Typhoon, reportedly targeted the mobile devices of diplomats, government officials and other people linked to both presidential campaigns. According to The Post, Chinese officials called claims that their country was involved in the attack on the Treasury Department "groundless" and insisted that their government "has always opposed all forms of hacker attacks."

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/china-linked-attack-on-us-treasury-department-reportedly-targeted-its-sanctions-office-150033082.html?src=rss https://www.engadget.com/cybersecurity/china-linked-attack-on-us-treasury-department-reportedly-targeted-its-sanctions-office-150033082.html?src=rss
Created 6mo | Jan 2, 2025, 3:10:14 PM


Login to add comment

Other posts in this group

Prime Day deals include $50 off one of our favorite Ninja air fryers

For many, summer means it's time to grill outdoors. But cooking inside does at least mean you’re likely to deal with fewer bugs. It also makes it easier to try out new kitchen equipment, such as a

Jul 7, 2025, 9:30:08 AM | Engadget
Playdate Season 2 review: Taria & Como and Black Hole Havoc

We've officially made it to the end of Playdate Season Two, and what a season it's been. Despite having half the number of titles as Season One, this latest round of weekly game releases has made a

Jul 6, 2025, 9:50:18 PM | Engadget
The Stop Killing Games initiative has hit a major milestone, but the fight's just begun

A petition to preserve video game access recently achieved an

Jul 6, 2025, 7:40:16 PM | Engadget
Prime Day deals include $100 off the Apple Watch Series 10

Prime Day 2025 will be here in a few days, but you can already shop great tech deals on Amazon before the July 8-11

Jul 6, 2025, 5:20:15 PM | Engadget
Elon Musk's proposed America Party is already attracting the attention of the ultra-rich

Just a day after former White House advisor Elon Musk claimed on X that he's creating a

Jul 6, 2025, 5:20:14 PM | Engadget
The Amazon Smart Plug falls to only $13 for Prime Day

If you're looking for an ultra-affordable away to make a part of your home a little smarter, look no further than the

Jul 6, 2025, 3:10:08 PM | Engadget