The US Treasury Department reported a significant cybersecurity breach attributed to Chinese state-sponsored hackers, according to a letter to Congress.
The attack exploited a vulnerability in BeyondTrust, a third-party software provider used for remote technical support. Hackers accessed Treasury workstations and unclassified documents, though the compromised service has since been taken offline.
The Treasury is working with the FBI, intelligence agencies, and forensic investigators. BeyondTrust confirmed the incident affected a limited number of customers and is cooperating with law enforcement.
The Chinese embassy denied the allegations, accusing the U.S. of spreading disinformation.
The breach coincides with escalating concerns over Chinese cyber-espionage, including a separate campaign targeting US telecommunications firms, further straining relations between Washington and Beijing.