Chinese state hackers breached US Treasury workstations through BeyondTrust
- Organization
- U.S. Department of the Treasury
- Exploit
- Supply Chain Attack
- Industry
- Government
On December 30, 2024, the U.S. Department of the Treasury notified Congress that it had suffered what it classified as a major cybersecurity incident, attributing the intrusion to a Chinese state-sponsored advanced persistent threat actor.
Treasury said BeyondTrust, which supplied a cloud-based remote technical support service used by the department, informed it on December 8 that attackers had obtained a key used to secure that service. With the key the intruders were able to override the service's security controls, remotely access certain Treasury departmental office user workstations and read unclassified documents held by those users. Two flaws in BeyondTrust products, CVE-2024-12356 and CVE-2024-12686, were tied to the campaign, and CISA added the first to its Known Exploited Vulnerabilities catalog.
The compromised BeyondTrust instance was taken offline and the stolen key revoked. Treasury said it found no evidence that the attackers retained access after that, and worked with CISA, the FBI, the intelligence community and third-party forensic investigators.
Reporting after the initial disclosure indicated that the Office of Foreign Assets Control, the Office of the Treasury Secretary and the Office of Financial Research were among the units affected. Treasury officials told lawmakers on January 15, 2025 that the attackers accessed 419 Treasury computers and at least 3,029 files between September 30 and November 18, 2024. Files belonging to Secretary Janet Yellen, Deputy Secretary Wally Adeyemo and Acting Under Secretary Brad Smith were among those accessed. In March 2025 the Justice Department linked the intrusion to APT27, also tracked as Silk Typhoon. China denied involvement.