logo

Chinese State-Sponsored Threat Actors Breach U.S. Treasury Department in Major Cybersecurity Incident

ID: ed58cb05-32e6-5b1f-9140-2f5653312196

STIX ID: report--ed58cb05-32e6-5b1f-9140-2f5653312196

Feed Name: SOCRadar Blog

Threat Score
92/100

Date Published: 2024-12-31

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Chinese state-sponsored APT actors exploited two zero-day vulnerabilities in a BeyondTrust Remote Support SaaS instance and a stolen API key to breach the U.S. Department of the Treasury (affecting OFAC and the Office of Financial Research); the compromised instance was shut down, the API key revoked, and CISA/FBI are coordinating the ongoing investigation and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.