The Treasury Department has told lawmakers that a China-backed actor hacked several of its employee workstations and accessed unspecified unclassified documents after stealing a key from a third-party software service provider.
The agency disclosed the breach in a letter to leaders of the Senate Banking Committee, saying that “there is no evidence indicating the threat actor has continued access to Treasury systems or information.”
The Treasury Department has told lawmakers that a China-backed actor hacked several of its employee workstations and accessed unspecified unclassified documents after stealing a key from a third-party software service provider.
The agency disclosed the breach in a letter to leaders of the Senate Banking Committee, saying that “there is no evidence indicating the threat actor has continued access to Treasury systems or information.”
BeyondTrust notified Treasury that on Dec. 8, the threat actor “gained access to a key used by the vendor to secure a cloud-based service used to remotely provide technical support” for Treasury Department offices, and used the stolen key to remotely access an unspecified number of workstations and to access “certain unclassified documents maintained by those users,” according to a letter seen by Barron’s.