US Treasury Breached via a BeyondTrust API Key (Dec 2024)
Retrospective: this article looks back at events from December 2024, written in 2026 with the benefit of hindsight.
On December 30, 2024, the US Treasury Department told Congress that a China state-sponsored actor had accessed some Treasury workstations and unclassified documents. The attacker got in through BeyondTrust, a third-party provider of remote technical support software used by Treasury.
How it happened
According to Treasury's letter and BeyondTrust's disclosures:
- BeyondTrust detected anomalous activity in early December 2024 and found that an API key for its Remote Support SaaS service had been compromised.
- The attacker used the key to reset passwords for local application accounts and gain access to certain customers' Remote Support instances — including Treasury's.
- From there, they could remotely access Treasury user workstations.
- BeyondTrust also disclosed vulnerabilities in its Remote Support and Privileged Remote Access products discovered during the investigation, one of which (CVE-2024-12356) was added to CISA's Known Exploited Vulnerabilities catalog.
The intrusion was attributed to a Chinese state-sponsored group (reported as Silk Typhoon). Treasury said there was no evidence of continued access after the BeyondTrust service was taken offline.
Why it mattered
- Remote support tools have direct, privileged access to endpoints — a high-value target.
- A single vendor API key unlocked access to multiple customers.
- Government targets were reached through a commercial SaaS supplier.
Lessons in hindsight
- Inventory remote support and remote access tools, including SaaS ones.
- Require MFA and approval workflows for remote sessions.
- Restrict which endpoints remote support can reach.
- Ask vendors how API keys are protected and scoped.
- Monitor remote support sessions and alert on unusual use.
- How to Inventory and Rotate API Keys for Remote Support Tools How-To & Hardening
- Detecting Stolen API Key: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Remote Support Vendors and Nation-State Risk CIO Briefings