top of page

News

Public·2 members

Jake Geier
Jake Geier

Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents



Who:

  • Suspected Chinese state-sponsored Advanced Persistent Threat (APT) actors.

  • U.S. Treasury Department.

  • BeyondTrust (third-party software service provider).

What:

  • A major cybersecurity incident where threat actors accessed U.S. Treasury systems and unclassified documents.

  • The incident involved the exploitation of a BeyondTrust API key.

  • The breach affected the Office of Foreign Assets Control (OFAC) and the Office of the Treasury Secretary.

How:

  • The threat actors gained access to a BeyondTrust API key used to secure a cloud-based service for remote technical support.

  • With the stolen key, they overrode the service's security and remotely accessed certain Treasury Departmental Offices (DO) user workstations and unclassified documents.

  • BeyondTrust's investigation revealed attackers reset passwords for local application accounts using the API key.

  • The Treasury Department, CISA, and FBI are investigating, and BeyondTrust has taken steps to mitigate the breach.


Read the full article HERE


29 Views
bottom of page