China-linked attack on US Treasury Department reportedly targeted its sanctions office

Share

The US Treasury Department told lawmakers in a letter back in December that its documents and workstations were accessed by an external party in a security breach. It described the attack as “a major cybersecurity incident” and attributed it to a “China state-sponsored Advanced Persistent Threat actor.” Now, The Washington Post has reported that the bad actors infiltrated a “highly sensitive office” within the Treasury in charge of deliberating and administering US government sanctions.

As The Post explains, the Office of Foreign Assets Control (OFAC) is in possession of some important information that could be very useful to another country’s government. While the hackers were only able to steal unclassified data, they could still have gotten their hands on the identities of potential sanction targets. They could also have stolen pieces of evidence that the agency had collected as part of its investigation on entities that the government is thinking of sanctioning. Overall, the attackers could have gotten enough information to give them the knowledge of how the US develops sanctions against foreign entities.

In addition to OFAC, the Office of the Treasury Secretary and the Office of Financial Research were also affected by the breach. The attackers infiltrated the Treasury’s systems by gaining access to a key used by BeyondTrust, a cloud-based service that provides the department with technical support.

The US government has attributed numerous cyberattacks on its agencies and American companies to China state-sponsored actors over the years. Just last year, the FBI blamed “PRC-affiliated actors” for a massive hack on US telecom companies. The actors, a group known as Salt Typhoon, reportedly targeted the mobile devices of diplomats, government officials and other people linked to both presidential campaigns. According to The Post, Chinese officials called claims that their country was involved in the attack on the Treasury Department “groundless” and insisted that their government “has always opposed all forms of hacker attacks.”