Multi-CloudIncident TeardownsRetrospectives

US Treasury Breached via a BeyondTrust API Key (Dec 2024)

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2024, written in 2026 with the benefit of hindsight.

On December 30, 2024, the US Treasury Department told Congress that a China state-sponsored actor had accessed some Treasury workstations and unclassified documents. The attacker got in through BeyondTrust, a third-party provider of remote technical support software used by Treasury.

How it happened

According to Treasury's letter and BeyondTrust's disclosures:

  • BeyondTrust detected anomalous activity in early December 2024 and found that an API key for its Remote Support SaaS service had been compromised.
  • The attacker used the key to reset passwords for local application accounts and gain access to certain customers' Remote Support instances — including Treasury's.
  • From there, they could remotely access Treasury user workstations.
  • BeyondTrust also disclosed vulnerabilities in its Remote Support and Privileged Remote Access products discovered during the investigation, one of which (CVE-2024-12356) was added to CISA's Known Exploited Vulnerabilities catalog.

The intrusion was attributed to a Chinese state-sponsored group (reported as Silk Typhoon). Treasury said there was no evidence of continued access after the BeyondTrust service was taken offline.

Why it mattered

  • Remote support tools have direct, privileged access to endpoints — a high-value target.
  • A single vendor API key unlocked access to multiple customers.
  • Government targets were reached through a commercial SaaS supplier.

Lessons in hindsight

  • Inventory remote support and remote access tools, including SaaS ones.
  • Require MFA and approval workflows for remote sessions.
  • Restrict which endpoints remote support can reach.
  • Ask vendors how API keys are protected and scoped.
  • Monitor remote support sessions and alert on unusual use.
us treasury breach beyondtrustUS Treasury / BeyondTrust2024

More on this story