In early December 2024, the U.S. Department of the Treasury experienced a cybersecurity breach. Though China denies involvement, the breach is attributed to a Chinese state-sponsored Advanced Persistent Threat (APT) actor.
The attackers allegedly obtained an authentication key through BeyondTrust, a third-party service provider for the Treasury, allowing them to bypass security measures and access certain unclassified documents within the department.
While the specific content of the unclassified documents has not been publicly disclosed, the Treasury Department stated in a letter to Chairman Brown and Sen. Scott that the compromised service has been taken offline.
Currently, there is no evidence to suggest that the threat actor still has access to Treasury systems or information. However, the Treasury Department plans to release a supplemental report within 30 days to provide more detailed insights into the breach.
Newsweek has reached out to cybersecurity experts to assess the implications of this breach, highlighting its severity and potential long-term risks.