logo

Treasury hackers also breached US foreign investments review office

ID: 9cf62103-0f6a-598e-a951-27b053fe58e4

STIX ID: report--9cf62103-0f6a-598e-a951-27b053fe58e4

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-01-10

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

Silk Typhoon (aka Hafnium), a Chinese state-backed APT, reportedly used a stolen BeyondTrust Remote Support API key to breach Treasury Department systems including CFIUS and OFAC, likely accessing unclassified documents related to potential sanctions; the campaign fits a pattern of nation-state cyberespionage leveraging stolen credentials and zero-day exploits. Investigators say the breach appears limited to Treasury and there is no confirmed persistent access after the compromised BeyondTrust instance was disabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.