In December 2024, an attacker used a compromised security key associated with BeyondTrust’s remote-support service to reach several U.S. Treasury Department workstations. Treasury said unclassified documents were accessed and attributed the incident, based on available indicators, to a China state-sponsored advanced persistent threat actor. Public accounts do not establish how many workstations or documents were involved.
How did the attackers get into Treasury computers?
The access path ran through BeyondTrust, a vendor whose cloud-based remote-support service supported Treasury Departmental Office end users. Treasury said BeyondTrust notified the department on December 8, 2024, that a threat actor had gained access to a key used to secure that service. The compromised key gave the attacker a route to Treasury workstations.
The public accounts identify the compromised key and remote-support service as the path into the department. They do not describe how the key was obtained, whether the attacker exploited another weakness, or the precise technical steps used to reach each workstation. The incident is an example of third-party access risk: a security failure involving a service provider can expose systems belonging to its customer.
What did the Treasury hackers access?
Treasury reported that the attacker accessed several employee workstations and unclassified documents. The public record does not identify the documents or establish whether they were viewed, copied, or otherwise removed. It also does not report a dollar-loss figure. The available statements do not support claims that classified information was stolen.
How many workstations were breached?
Treasury has not published a reliable workstation count or a document count. “Several” is the supported description; a more precise number would go beyond the public information cited in the department’s notice and subsequent account.
#1 Best Overall
Who was blamed, and what happened to the named attacker?
In its December 30, 2024, notice to congressional committee leadership, Treasury said: “Based on available indicators, the incident has been attributed to a China state-sponsored Advanced Persistent Threat (APT) actor.” Treasury classified the event as a “major incident” under federal incident-reporting criteria.
On January 17, 2025, the Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned Yin Kecheng, a Shanghai-based cyber actor, for involvement in the recent Treasury network compromise. The OFAC release described him as affiliated with China’s Ministry of State Security. This named-person action adds detail to the public attribution, but it does not establish every operational detail of the intrusion.
The same OFAC release separately sanctioned Sichuan Juxinhe for direct involvement in Salt Typhoon. That separate designation is not evidence that Yin Kecheng or the Treasury intruders conducted every other China-linked intrusion.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Did the attackers still have access?
After BeyondTrust alerted the department, the compromised service was taken offline. Treasury said it was working with CISA, the FBI, the intelligence community, and third-party forensic investigators to assess the incident. CISA also said it was coordinating with Treasury and BeyondTrust to understand and mitigate impacts.
Treasury reported no evidence at that time that the actor retained continued access to Treasury information after the service was taken offline. That is a statement about the evidence available then; it does not show that no information was viewed or copied before containment.
Rank #3
What this incident does—and does not—mean for personal finances
This was a compromise of Treasury Department workstations through a vendor remote-support service. The public accounts summarized here describe access to unclassified government documents; they do not report that consumer bank accounts, payment cards, or personal financial accounts were breached. They also do not establish that such accounts were affected indirectly. The documented lesson is narrower: organizations that rely on outside providers for remote access need to treat vendor-held authentication credentials as part of their own security perimeter.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




