The US Treasury building. The department is working with the Cybersecurity and Infrastructure Security Agency and FBI following the breach. AFP
The US Treasury building. The department is working with the Cybersecurity and Infrastructure Security Agency and FBI following the breach. AFP
The US Treasury building. The department is working with the Cybersecurity and Infrastructure Security Agency and FBI following the breach. AFP
The US Treasury building. The department is working with the Cybersecurity and Infrastructure Security Agency and FBI following the breach. AFP

US Treasury reports breach by Chinese hackers in 'major incident'


  • English
  • Arabic

The US Treasury Department was breached by Chinese state-sponsored hackers, who gained access to unclassified documents, in what the organisation called a “major cyber security incident”, according to a letter sent to the Congress on Monday.

The Treasury said a third-party software provider, BeyondTrust, had notified it of the breach.

The hackers “gained access to a key used by the vendor to secure a cloud-based service used to remotely provide technical support for Treasury Departmental Offices (DO) end users”, the letter seen by Bloomberg and Reuters, said.

“With access to the stolen key, the threat actor was able to override the service’s security, remotely access certain Treasury DO user workstations, and access certain unclassified documents maintained by those users.”

The Treasury department said it was working with the US Cybersecurity and Infrastructure Security Agency, the FBI and third-party forensic investigators.

BeyondTrust said it has been supporting the investigative efforts.

The Chinese Embassy in Washington dismissed the allegations and said the “US needs to stop using cyber security to smear and slander China, and stop spreading all kinds of disinformation about the so-called Chinese hacking threat”.

“The compromised BeyondTrust service has been taken offline, and there is no evidence indicating the threat actor has continued access to Treasury systems or information,” a Treasury representative told Bloomberg.

Cyber security issues globally have been rising sharply, led by an increasing number of ransomware attacks targeting government services and other critical sectors in many countries, the 2024 Global Cybersecurity Index released by the UN's International Telecommunication Union in September.

The global average cost of a data breach was estimated at $4.45 million last year, it said.

The US is already carrying out an investigation into what has become known as the Salt Typhoon cyber breach, flagged by officials in early December. The US has accused China of sponsoring the attack that infiltrated US communications companies and potentially left American consumers vulnerable.

Initially, officials said eight US companies had been affected, but that number has since risen to nine.

US companies need to enact critical infrastructure changes and update basic cyber security practices, Anne Neuberger, deputy national security adviser for cyber and emerging technology, told media on Friday.

“What we've learnt from the investigation is that there's several categories of things that are needed in this space: better management of configuration, better vulnerability management of networks, better work across the telecom sector to share information when incidents occur,” she said.

Voluntary commitments by companies were inadequate, she said, and explained that the administration would be seeking bipartisan support from the Federal Communications Commission (FCC) to ensure compliance from telecoms companies.

With inputs from Bloomberg and Reuters

Company profile

Date started: 2015

Founder: John Tsioris and Ioanna Angelidaki

Based: Dubai

Sector: Online grocery delivery

Staff: 200

Funding: Undisclosed, but investors include the Jabbar Internet Group and Venture Friends

Desert Warrior

Starring: Anthony Mackie, Aiysha Hart, Ben Kingsley

Director: Rupert Wyatt

Rating: 3/5

Jetour T1 specs

Engine: 2-litre turbocharged

Power: 254hp

Torque: 390Nm

Price: From Dh126,000

Available: Now

Classification of skills

A worker is categorised as skilled by the MOHRE based on nine levels given in the International Standard Classification of Occupations (ISCO) issued by the International Labour Organisation. 

A skilled worker would be someone at a professional level (levels 1 – 5) which includes managers, professionals, technicians and associate professionals, clerical support workers, and service and sales workers.

The worker must also have an attested educational certificate higher than secondary or an equivalent certification, and earn a monthly salary of at least Dh4,000. 

GAC GS8 Specs

Engine: 2.0-litre 4cyl turbo

Power: 248hp at 5,200rpm

Torque: 400Nm at 1,750-4,000rpm

Transmission: 8-speed auto

Fuel consumption: 9.1L/100km

On sale: Now

Price: From Dh149,900

Meghan%20podcast
%3Cp%3EMeghan%20Markle%2C%20the%20wife%20of%20Prince%20Harry%2C%20launched%20her%20long-awaited%20podcast%20Tuesday%2C%20with%20tennis%20megastar%20Serena%20Williams%20as%20the%20first%20guest.%3C%2Fp%3E%0A%3Cp%3EThe%20Duchess%20of%20Sussex%20said%20the%2012-part%20series%2C%20called%20%22Archetypes%2C%22%20--%20a%20play%20on%20the%20name%20of%20the%20couple's%20oldest%20child%2C%20Archie%20--%20would%20explore%20the%20female%20experience.%3C%2Fp%3E%0A%3Cp%3ELast%20year%20the%20couple%20told%20Oprah%20Winfrey%20that%20life%20inside%20%22The%20Firm%22%20had%20been%20miserable%2C%20and%20that%20they%20had%20experienced%20racism.%26nbsp%3B%3C%2Fp%3E%0A%3Cp%3E%22I%20don't%20ever%20remember%20personally%20feeling%20the%20negative%20connotation%20behind%20the%20word%20ambitious%2C%20until%20I%20started%20dating%20my%20now-husband%2C%22%20she%20told%20the%20tennis%20champion.%26nbsp%3B%3C%2Fp%3E%0A%3Cp%3E%3C%2Fp%3E%0A
Updated: January 02, 2025, 8:00 PM