Chinese threat actors were able to access highly sensitive information held by the US Treasury Department after compromising a third party service used for remote IT support.
On 8 December, cybersecurity firm BeyondTrust warned users it had discovered an API key for its remote support SaaS solution had been compromised.