In a significant cyberattack, a Chinese state-sponsored group accessed US Treasury workstations and unclassified documents. The US Treasury Department informed Congress about this breach, which was discovered by a third-party software provider on December 8. Aditi Hardikar, assistant secretary for management at the US Treasury, confirmed the involvement of a Chinese Advanced Persistent Threat (APT) actor.
The compromised service has been taken offline, and the Treasury is working with law enforcement and the Cybersecurity and Infrastructure Security Agency (CISA) to address the issue. There is no evidence of continued access by the hackers. A classified briefing with the House Financial Services Committee is expected soon to discuss the breach.
The breach involved a stolen key used by BeyondTrust, a vendor providing cloud-based services for the Treasury's technical support. This allowed the hackers to bypass security and access certain workstations and documents. The full impact of the breach is still being assessed, with the Treasury collaborating with CISA, the FBI, US intelligence agencies, and forensic investigators.
These are people from China who use computers to break into other people's computer systems without permission. They are often very skilled at finding ways to get into secure systems.
The US Treasury is a part of the United States government that manages the country's money. It is similar to the Ministry of Finance in India.
A cyberattack is when someone uses computers to try to damage or steal information from another computer system. It's like a digital fight where one side tries to break into the other's computer.
This means that the hackers are supported or backed by a government. In this case, it suggests that the Chinese government might be helping or encouraging these hackers.
This is a company that makes software used by other companies or organizations. They are not part of the organization that uses their software, hence 'third-party'.
This is a group of people in the US government who are responsible for overseeing financial services and the economy. They are similar to a committee in the Indian Parliament that looks after financial matters.
BeyondTrust is a company that provides security software to help protect computer systems from unauthorized access. They make tools to keep computer systems safe.
This is a meeting where important and secret information is shared with only a few people who are allowed to know it. It's like a secret meeting where only certain people can attend.
Your email address will not be published. Required fields are marked *