China Hacks US Treasury Department: CFIUS Targeted in Cyberattack

U.S. Treasury Department Building

Chinese Hackers Breach Key U.S. Treasury Office

Chinese hackers have reportedly breached a key office within the U.S. Treasury tasked with reviewing foreign investments and transactions that could threaten U.S. national security. The office in question, the Committee on Foreign Investment in the United States, or CFIUS, plays a crucial role in national security by approving or denying deals involving sensitive U.S. information.

Details of the Cyberattack

According to U.S. officials familiar with the incident, the hackers managed to infiltrate CFIUS using a stolen key from BeyondTrust, a security vendor for the Treasury department. This breach allowed the attackers to access employee workstations and documents on the department's unclassified network.

The cyberattack also affected the department’s office for international financial sanctions, known as the Office of Foreign Assets Control, or OFAC.

U.S. Security Response and Continued Investigation

Treasury officials have confirmed they are investigating what they have described as a "major cybersecurity incident." While the Cybersecurity and Infrastructure Security Agency (CISA) noted that there was no indication of wider infiltration into other government departments, the incident has raised significant concerns.

The Hackers Behind the Breach

The group responsible for the attack, Silk Typhoon (formerly known as "Hafnium"), is associated with the Chinese government and has been linked to various large-scale hacking operations. These operations include targeting critical infrastructure and government communications.

Continued Threats and International Tension

This attack is part of a series of recent cyber incursions tied to the China-backed "Typhoon" hackers, who have also been involved in compromising U.S. government officials' communications and placing malware within U.S. critical infrastructure.

Amidst these allegations, the Chinese government has consistently denied any involvement in such cyber activities.

Read more