logo

Treasury workstations hacked by China-linked threat actors

ID: a3a691d2-2eb5-533e-9d55-dfdc69969507

STIX ID: report--a3a691d2-2eb5-533e-9d55-dfdc69969507

Feed Name: CyberScoop

Threat Score
88/100

Date Published: 2024-12-30

Date Updated: 2026-04-21

Author: djohnson

...
...

The U.S. Department of the Treasury disclosed that several workstations were accessed after a threat actor gained a stolen vendor key for BeyondTrust’s cloud remote-support service; the actor was able to override security, remotely access certain Treasury user workstations, and view some unclassified documents. The vendor detected anomalous activity in early December, patched identified instances by Dec. 16, and the incident—attributed to a China state-sponsored APT—is being investigated by CISA, the FBI, intelligence partners, and third-party forensics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.