The US Treasury Department says a China state-sponsored actor was behind a cyber breach resulting in access to some of its workstations, according to a letter to Congress seen by AFP.
The incident happened this month, when the actor compromised a third-party cybersecurity service provider and was able to remotely access the Treasury workstations and some unclassified documents, a Treasury spokesperson said.
Treasury contacted the US Cybersecurity and Infrastructure Security Agency after it was alerted of the situation by its provider, BeyondTrust, and has been working with law enforcement partners to ascertain the impact.
“The compromised BeyondTrust service has been taken offline and there is no evidence indicating the threat actor has continued access to Treasury systems or information,” the department’s spokesperson said.
In its letter to the leadership of the Senate Banking Committee, the Treasury said: “Based on available indicators, the incident has been attributed to a China state-sponsored Advanced Persistent Threat (APT) actor.”