Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

U.S. Treasury Sanctions Chinese Cybersecurity Firm and Hacker Linked to Network Breaches

By TheFinanceBase Team6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

On January 17, 2025, the U.S. Treasury Department sanctioned two separate China-based targets over alleged cyber activity: Shanghai-based cyber actor Yin Kecheng, whom Treasury linked to the compromise of the Departmental Offices network, and Sichuan Juxinhe Network Technology Co., Ltd., which Treasury said was directly involved in Salt Typhoon attacks on telecommunications and internet-service-provider networks.

The designations are related only because they were announced together. Treasury did not say that Yin Kecheng and Sichuan Juxinhe were responsible for the same intrusion. The action is also a sanctions measure—not a criminal conviction, arrest warrant, or technical fix for compromised networks.

The two sanctions designations at a glance

Target Location Treasury’s allegation Related incident
Yin Kecheng Shanghai Associated with the compromise of the Treasury Department’s Departmental Offices network Treasury Department network breach
Sichuan Juxinhe Network Technology Co., Ltd. Sichuan, China Direct involvement in Salt Typhoon activity, according to Treasury Telecommunications and ISP compromises

Both were added to the Office of Foreign Assets Control’s Specially Designated Nationals and Blocked Persons list. Treasury’s announcement is available from the Treasury Department, while OFAC’s designation record contains the official identifying information for both targets.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who is Yin Kecheng?

Treasury described Yin Kecheng as a Shanghai-based cyber actor who had been active for more than a decade and was affiliated with China’s Ministry of State Security. Treasury also associated him with the recent compromise of the Departmental Offices network at the U.S. Treasury Department.

OFAC’s record identifies Yin by the Chinese name 尹可成 and lists a date of birth of December 8, 1986, a place of birth in Anhui Province, and Chinese national-identification information. Those details are part of OFAC’s designation record, not an independent court finding.

The public announcement does not provide a complete forensic account of the Treasury incident. It does not specify the initial access method, the systems accessed, how long the intruder remained inside the network, what information was taken, or whether classified information was involved. It also does not establish that Yin personally conducted every activity attributed to a larger cyber operation.

What is Sichuan Juxinhe?

Sichuan Juxinhe is a cybersecurity company based in Sichuan, China. OFAC’s listing includes its Chinese name, an address in Deyang, Sichuan, an incorporation date of May 23, 2014, its business classification, and its Unified Social Credit Code.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Treasury said the company had direct involvement in Salt Typhoon’s exploitation of networks belonging to multiple major U.S. telecommunications and internet-service-provider companies. That allegation concerns the company’s role in the activity identified by Treasury; it does not mean every employee, customer, product, or ordinary business transaction involving the company was individually proven to be malicious.

The designation also should not be confused with a criminal judgment after trial. It is a U.S. government sanctions finding based on Treasury’s stated legal authority and attribution.

What is Salt Typhoon?

Salt Typhoon is a threat-actor label used for a cyber group that Treasury said had been active since at least 2019. Treasury attributed numerous compromises of U.S. communications-sector companies to the group and described the recent telecom and ISP intrusions as a major escalation in Chinese cyber operations against U.S. critical infrastructure.

Threat-actor names can vary between government agencies, cybersecurity companies, and researchers. Salt Typhoon is not the name of a legal company, and it does not by itself identify every person or organization involved in an intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Telecommunications compromises can be particularly consequential because telecom networks support connectivity for businesses, government agencies, and consumers. However, Treasury’s January 17 announcement does not establish a complete list of affected companies, the precise information accessed, or the full operational purpose of each intrusion.

What do the sanctions do?

OFAC sanctions generally block property and interests in property belonging to the designated parties when that property is in the United States or comes within the possession or control of U.S. persons. Blocked property must be reported to OFAC, and U.S. persons generally may not conduct transactions involving it unless OFAC authorizes the activity.

The restrictions can affect banks, payment processors, technology suppliers, cloud and hosting providers, telecom companies, cybersecurity vendors, and businesses considering acquisitions or joint ventures involving a designated party.

The 50 Percent Rule

Companies must also consider OFAC’s 50 Percent Rule. Entities owned directly or indirectly 50% or more, individually or in aggregate, by one or more blocked persons are generally treated as blocked even if those entities do not appear by name on the SDN list.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That makes ownership and control checks important. Screening only an English-language company name may miss Chinese names, aliases, addresses, registration details, or an indirectly owned affiliate.

Who can face exposure?

U.S. persons—including U.S. companies, financial institutions, and citizens—must comply with applicable blocking restrictions. Non-U.S. companies can also face risk if they cause, facilitate, evade, or knowingly participate in prohibited transactions, depending on the facts and the applicable sanctions rules.

OFAC can impose civil penalties on a strict-liability basis. In practical terms, a civil violation may create exposure even without proof that a company intended to break the rules. Potentially affected businesses should review the current OFAC listing, ownership information, applicable general licenses, and transaction-specific facts before proceeding.

The designation does not automatically require every non-U.S. company to terminate every relationship with every related party in every circumstance. Whether a transaction is prohibited depends on the parties, property, ownership, jurisdiction, sanctions program, and any applicable authorization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What legal authority did OFAC use?

Treasury said the designations were made under Executive Order 13694, as amended, including the executive-order authority addressing significant malicious cyber-enabled activity. These are economic and national-security sanctions, not charges brought under a criminal cybercrime statute.

That distinction matters. An OFAC designation can block property and restrict transactions without producing an indictment, trial, conviction, or arrest. The sanctions record communicates the U.S. government’s attribution and imposes financial restrictions; it does not by itself adjudicate criminal guilt.

What does the $10 million reward mean?

The State Department’s Rewards for Justice program was offering up to $10 million for information leading to the identification or location of a person who, while acting at the direction or control of a foreign government, engages in certain malicious cyber activity against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act.

That is not necessarily a bounty specifically for Yin Kecheng. “Up to $10 million” is a maximum, not a guaranteed payment. Eligibility depends on the Rewards for Justice program’s rules and on the value and usefulness of the information provided.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How this action fits the broader campaign

The January action followed several other Treasury cyber-related designations involving alleged China-linked activity:

  • March 25, 2024: Treasury designated Wuhan Xiaoruizhi Science and Technology Co. and two employees over alleged ties to APT31-related cyber activity.
  • December 10, 2024: Treasury designated Sichuan Silence Information Technology Co. and an employee over alleged firewall compromises.
  • January 3, 2025: Treasury designated Integrity Technology Group over alleged support for Flax Typhoon.
  • January 17, 2025: Treasury designated Yin Kecheng and Sichuan Juxinhe.

The sequence shows that the action was part of a continuing U.S. effort to impose financial and reputational costs on alleged PRC-linked cyber actors and facilitators, rather than an isolated response to one incident.

What sanctions can—and cannot—accomplish

What they can do

  • Block access to U.S. financial infrastructure and property.
  • Increase compliance, banking, and reputational costs.
  • Warn companies and intermediaries against dealings with designated parties.
  • Create legal risk for facilitators and businesses that attempt to evade restrictions.
  • Signal U.S. attribution and support broader diplomatic or law-enforcement measures.

What they cannot necessarily do

  • Remove an attacker from a compromised network.
  • Repair vulnerable telecom or government systems.
  • Provide a complete public account of a breach.
  • Guarantee that a designated person will be arrested or prosecuted.
  • Prevent attackers from using front companies, proxies, cryptocurrency, or non-U.S. financial channels.
  • Establish criminal guilt by themselves.

What remains unknown

The Treasury announcement leaves important questions unanswered about both incidents. Publicly available information in the announcement does not establish the Treasury breach’s initial access vector, the systems accessed, the duration of access, the precise information exfiltrated, or whether classified information was affected.

It also does not provide a complete account of Salt Typhoon’s command structure, identify every organization involved, or prove that the sanctions will prevent future attacks. Nor does it say whether a criminal prosecution or arrest will follow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those limits are important for readers and businesses. A sanctions designation is a serious government action, but it should not be expanded into claims that the public record does not support.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.