Risingbd Online Bangla News Portal

Dhaka     Saturday   04 January 2025

US Treasury says it was hacked by China in `major incident`

Desk Report || risingbd.com

Published: 14:02, 31 December 2024  
US Treasury says it was hacked by China in `major incident`

A Chinese state-sponsored hacker broke into the US Treasury Department's systems earlier this month and was able to access employee workstations and some unclassified documents, American officials said on Monday.

The Treasury Department deemed the breach a "major incident" after disclosing it via a letter notifying lawmakers to the incident, reports BBC.

The US agency said it had been working with the FBI and other agencies to investigate the impact of the hack.

A spokesman for the Chinese embassy in Washington DC told BBC News that the accusation was part of a "smear attack" and made "without any factual basis".

The Treasury Department said in its letter to lawmakers that the China-based actor was able to override security via a key used by a third-party service provider. The application offers remote technical support to its employees.

The compromised third-party service - called BeyondTrust - has since been taken offline, officials said. There was no evidence to suggest the hacker had continued to access to Treasury Department information since, the statement continued.

The department said it had been working with the Cybersecurity and Infrastructure Security Agency and third-party forensic investigators to determine the overall impact.

The department was made aware of the hack on 8 December by BeyondTrust, a spokesperson told the BBC. According to the company, the suspicious activity was first spotted on 2 December, but it took three days for the company to determine it had been hacked.

The spokesperson said the hacker was able to remotely access several Treasury user workstations and some unclassified documents that were kept by those users.

The department did not specify the nature of these files, or when and for how long the hack took place. They also did not specify the level of confidentiality of the computer systems or the seniority of the staff whose materials were accessed.

The hackers may have been able to create accounts or change passwords in the three days that they were being watched by BeyondTrust.

As espionage agents, the hackers are believed to have been seeking information, rather than attempting to steal funds.

The spokesperson said the Treasury Department "takes very seriously all threats against our systems, and the data it holds", and that it will continue to work on protecting its data from outside threats.

The department letter states that a supplemental report on the incident will be provided to lawmakers in 30 days.

Chinese embassy spokesman Liu Pengyu denied the department's report, saying in a statement that it can be difficult to trace the origin of hackers._Agencies.

Dhaka/Feroz/Nasim