TechCrunch News 2024年12月31日
US Treasury says China accessed government documents in ‘major’ cyberattack
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

美国财政部在12月遭受了一次网络攻击,该部门已将此次攻击归咎于中国政府支持的黑客。黑客通过远程访问部分财政部雇员的工作站,获取了未分类文件。事件起因是BeyondTrust公司提供的远程技术支持密钥被盗用,该公司为大型机构和政府部门提供身份访问和远程支持技术。财政部已联系美国网络安全机构CISA寻求协助,目前没有证据表明黑客持续访问财政部信息。此次攻击被认为是具有中国政府背景的高级持续性威胁组织所为,但具体组织身份尚未明确。这是近期美国政府遭受的又一次与中国相关的网络攻击。

🚨 美国财政部遭受网络攻击:黑客通过远程访问雇员工作站,获取了未分类文件,这是一起重大的网络安全事件。

🔑 技术支持密钥被盗用:BeyondTrust公司提供的远程技术支持密钥被盗用是此次攻击的入口,该公司为财政部提供技术支持。

🛡️ 美国网络安全机构介入:财政部已联系美国网络安全机构CISA寻求协助,以应对此次网络攻击,并确认目前没有证据表明黑客持续访问。

🇨🇳 中国政府背景:此次攻击被认为是具有中国政府背景的高级持续性威胁组织所为,这加剧了中美之间的网络安全紧张关系。

📱 针对美国政府机构:近期,美国政府机构已多次遭受与中国相关的网络攻击,例如针对美国电话公司和互联网巨头的攻击,这些事件突显了网络安全威胁的严峻性。

The U.S. Treasury told lawmakers in a letter Monday that it was hit by a cyberattack earlier in December, which the department has attributed to Chinese government hackers.

In the letter shared with senior U.S. House lawmakers, which TechCrunch has seen, the Treasury said the hackers gained remote access to certain Treasury employee workstations and had access to unclassified documents, in what it described as a “major cybersecurity incident.”

The Treasury said it was notified on December 8 by BeyondTrust, a company that provides identity access and remote support tech for large organizations and government departments, that hackers had “gained access to a key used by the vendor” for providing remote access technical support to Treasury employees. BeyondTrust disclosed the incident at the time, but did not say how the key was obtained. 

A spokesperson for BeyondTrust did not respond to a request for comment at press time.

The letter said the department engaged U.S. cybersecurity agency CISA for assistance and, as of December 30, it has “no evidence indicating the threat actor has continued access to Treasury information.”

The Treasury confirmed in the letter that it attributed the breach to a China state-sponsored advanced persistent threat group, indicating backing from the Chinese government. It’s not clear which group was behind the intrusion, and a spokesperson would not say.

In a brief statement, Treasury spokesperson MIchael Gwin said that the hackers were able to “remotely access several Treasury user workstations and certain unclassified documents maintained by those users.” 

“Treasury takes very seriously all threats against our systems, and the data it holds. Over the last four years, Treasury has significantly bolstered its cyber defense, and we will continue to work with both private and public sector partners to protect our financial system from threat actors,” the spokesperson said.

This is the latest cyberattack linked to China that has targeted the U.S. government in recent months. China-backed hackers dubbed Salt Tycoon were behind a wave of cyberattacks targeting U.S. phone companies and internet giants, including AT&T and Verizon, in a bid to get access the private communications of senior U.S. government officials, including presidential candidates.

A spokesperson for the Chinese Embassy in Washington, D.C., did not immediately return a request for comment.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

美国财政部 网络攻击 中国黑客 网络安全 BeyondTrust
相关文章