U.S. Department of the Treasury BeyondTrust Breach December 2024
A China state-sponsored APT (later attributed to Silk Typhoon) compromised a stolen BeyondTrust Remote Support SaaS API key, using it to reset local application account passwords and remotely access U.S. Treasury Department workstations and unclassified documents. The intrusion, detected by BeyondTrust on December 2, 2024 and disclosed to Congress on December 30, 2024 as a major cybersecurity incident, reached the Office of Foreign Assets Control, the Committee on Foreign Investment in the United States, the Office of Financial Research, and reportedly the Office of the Treasury Secretary. The attack exploited a critical unauthenticated command/argument-injection flaw (CVE-2024-12356, CVSS 9.8) and a second lower-severity flaw (CVE-2024-12686); OFAC later sanctioned contractor Yin Kecheng for his role in the compromise.