Chinese Hackers Strike Again: U.S. Treasury Breached via Remote Platform Fiasco

Chinese state-sponsored threat actors breached the U.S. Treasury Department by exploiting a remote support platform. The cybercriminals, known as Salt Typhoon, accessed sensitive data using stolen API keys and zero-day vulnerabilities. The incident has prompted a cybersecurity overhaul and a potential ban on China’s telecom operations in the U.S.

Pro Dashboard

Hot Take:

Seems like the U.S. Treasury Department got a little too comfortable with BeyondTrust’s remote support platform, and now they’ve learned the hard way that Chinese state-sponsored hackers don’t take holidays. Maybe it’s time to invest in some old-fashioned vaults and carrier pigeons for secure communications?

Key Points:

  • A Chinese state-sponsored group breached the U.S. Treasury Department via a remote support platform.
  • The breach was first discovered on December 8th, after the vendor BeyondTrust notified the Treasury Department.
  • Threat actors exploited two zero-day vulnerabilities in BeyondTrust’s Remote Support SaaS.
  • The FBI and CISA have been involved in the investigation, and access has reportedly been revoked.
  • Similar hacks have targeted major U.S. telecom companies, prompting calls for encrypted communications.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?